sbx kit provenance
| 内容説明 | Show the SLSA provenance attached to a kit |
|---|---|
| 利用方法 | sbx kit provenance REFERENCE [flags] |
試験的
This command is experimental.
Experimental features are intended for testing and feedback as their functionality or design may change between releases without warning or can be removed entirely in a future release.
Description
Print the SLSA provenance attestation attached to an OCI kit.
Provenance is attached by sbx kit push as an OCI referrer of the kit
manifest. It records the kit's content digests, the sandbox image its spec
declares, and the source git commit the kit was pushed from.
Provenance pushed without --sign is unsigned: it is printed but marked UNSIGNED, because anyone with push access to the repository could have written it. To verify a signed attestation, pass --key for a key-based signature, or --certificate-identity (or --certificate-identity-regexp) together with --certificate-oidc-issuer (or its regexp form) for a keyless one; only attestations that verify and whose subject matches the kit's own digest are reported as VERIFIED.
Options
| オプション | デフォルト | 内容説明 |
|---|---|---|
--certificate-identity | Exact keyless signer identity (certificate SAN) | |
--certificate-identity-regexp | Keyless signer identity regexp (certificate SAN) | |
--certificate-oidc-issuer | Exact keyless OIDC issuer | |
--certificate-oidc-issuer-regexp | Keyless OIDC issuer regexp | |
--insecure-ignore-tlog | Do not require a Rekor transparency-log entry (for private keyless signatures) | |
--key | Public key for key-based verification (PEM) |
Global options
| オプション | デフォルト | 内容説明 |
|---|---|---|
-D, --debug | Enable debug logging |
Examples
# Show provenance (unsigned attestations are printed as-is)
sbx kit provenance ghcr.io/org/my-kit:1.0
# Verify a signed attestation before printing it
sbx kit provenance \
--certificate-identity user@example.com \
--certificate-oidc-issuer https://accounts.google.com \
ghcr.io/org/my-kit:1.0