github.com/yogeshkumararora/slsa-github-generator@v1.10.1-0.20240520161934-11278bd5afb4/.github/actions/sign-attestations/testdata/attestations/attestation1.intoto (about)

     1  {
     2    "_type": "https://in-toto.io/Statement/v0.1",
     3    "predicateType": "https://slsa.dev/provenance/v0.2",
     4    "subject": [
     5      {
     6        "name": "slsa-verifier-linux-amd64",
     7        "digest": {
     8          "sha256": "ad4b408c43504d439827998c27ab4be1c44ff467ccb39b78da01568f8542b10e"
     9        }
    10      }
    11    ],
    12    "predicate": {
    13      "builder": {
    14        "id": "https://github.com/yogeshkumararora/slsa-github-generator/.github/workflows/builder_go_slsa3.yml@refs/tags/v1.2.2"
    15      },
    16      "buildType": "https://github.com/yogeshkumararora/slsa-github-generator/go@v1",
    17      "invocation": {
    18        "configSource": {
    19          "uri": "git+https://github.com/slsa-framework/slsa-verifier@refs/tags/v2.0.1",
    20          "digest": {
    21            "sha1": "a43888265e1f6aae98c924538298944f2721dcf0"
    22          },
    23          "entryPoint": ".github/workflows/release.yml"
    24        },
    25        "parameters": {},
    26        "environment": {
    27          "arch": "X64",
    28          "github_actor": "asraa",
    29          "github_actor_id": "5194569",
    30          "github_base_ref": "",
    31          "github_event_name": "push",
    32          "github_event_payload": {
    33            "after": "a43888265e1f6aae98c924538298944f2721dcf0",
    34            "base_ref": "refs/heads/main",
    35            "before": "0000000000000000000000000000000000000000",
    36            "commits": [],
    37            "compare": "https://github.com/slsa-framework/slsa-verifier/compare/v2.0.1",
    38            "created": true,
    39            "deleted": false,
    40            "forced": false,
    41            "head_commit": {
    42              "author": {
    43                "email": "64505099+laurentsimon@users.noreply.github.com",
    44                "name": "laurentsimon",
    45                "username": "laurentsimon"
    46              },
    47              "committer": {
    48                "email": "noreply@github.com",
    49                "name": "GitHub",
    50                "username": "web-flow"
    51              },
    52              "distinct": true,
    53              "id": "a43888265e1f6aae98c924538298944f2721dcf0",
    54              "message": "fix: command in installer Action (#396)\n\n* update\r\n\r\nSigned-off-by: laurentsimon <laurentsimon@google.com>",
    55              "timestamp": "2022-12-08T22:32:57Z",
    56              "tree_id": "d5a2c622e262f0a53446d60488f7c1a89294d4f5",
    57              "url": "https://github.com/slsa-framework/slsa-verifier/commit/a43888265e1f6aae98c924538298944f2721dcf0"
    58            },
    59            "organization": {
    60              "avatar_url": "https://avatars.githubusercontent.com/u/80431187?v=4",
    61              "description": "Supply-chain Levels for Software Artifacts",
    62              "events_url": "https://api.github.com/orgs/slsa-framework/events",
    63              "hooks_url": "https://api.github.com/orgs/slsa-framework/hooks",
    64              "id": 80431187,
    65              "issues_url": "https://api.github.com/orgs/slsa-framework/issues",
    66              "login": "slsa-framework",
    67              "members_url": "https://api.github.com/orgs/slsa-framework/members{/member}",
    68              "node_id": "MDEyOk9yZ2FuaXphdGlvbjgwNDMxMTg3",
    69              "public_members_url": "https://api.github.com/orgs/slsa-framework/public_members{/member}",
    70              "repos_url": "https://api.github.com/orgs/slsa-framework/repos",
    71              "url": "https://api.github.com/orgs/slsa-framework"
    72            },
    73            "pusher": {
    74              "email": "asraa@google.com",
    75              "name": "asraa"
    76            },
    77            "ref": "refs/tags/v2.0.1",
    78            "repository": {
    79              "allow_forking": true,
    80              "archive_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/{archive_format}{/ref}",
    81              "archived": false,
    82              "assignees_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/assignees{/user}",
    83              "blobs_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/git/blobs{/sha}",
    84              "branches_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/branches{/branch}",
    85              "clone_url": "https://github.com/slsa-framework/slsa-verifier.git",
    86              "collaborators_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/collaborators{/collaborator}",
    87              "comments_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/comments{/number}",
    88              "commits_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/commits{/sha}",
    89              "compare_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/compare/{base}...{head}",
    90              "contents_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/contents/{+path}",
    91              "contributors_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/contributors",
    92              "created_at": 1648242107,
    93              "default_branch": "main",
    94              "deployments_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/deployments",
    95              "description": "Verify provenance from SLSA compliant builders",
    96              "disabled": false,
    97              "downloads_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/downloads",
    98              "events_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/events",
    99              "fork": false,
   100              "forks": 20,
   101              "forks_count": 20,
   102              "forks_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/forks",
   103              "full_name": "slsa-framework/slsa-verifier",
   104              "git_commits_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/git/commits{/sha}",
   105              "git_refs_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/git/refs{/sha}",
   106              "git_tags_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/git/tags{/sha}",
   107              "git_url": "git://github.com/slsa-framework/slsa-verifier.git",
   108              "has_discussions": false,
   109              "has_downloads": true,
   110              "has_issues": true,
   111              "has_pages": false,
   112              "has_projects": true,
   113              "has_wiki": true,
   114              "homepage": "",
   115              "hooks_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/hooks",
   116              "html_url": "https://github.com/slsa-framework/slsa-verifier",
   117              "id": 474162642,
   118              "is_template": false,
   119              "issue_comment_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/issues/comments{/number}",
   120              "issue_events_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/issues/events{/number}",
   121              "issues_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/issues{/number}",
   122              "keys_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/keys{/key_id}",
   123              "labels_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/labels{/name}",
   124              "language": "Go",
   125              "languages_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/languages",
   126              "license": {
   127                "key": "apache-2.0",
   128                "name": "Apache License 2.0",
   129                "node_id": "MDc6TGljZW5zZTI=",
   130                "spdx_id": "Apache-2.0",
   131                "url": "https://api.github.com/licenses/apache-2.0"
   132              },
   133              "master_branch": "main",
   134              "merges_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/merges",
   135              "milestones_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/milestones{/number}",
   136              "mirror_url": null,
   137              "name": "slsa-verifier",
   138              "node_id": "R_kgDOHEMl0g",
   139              "notifications_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/notifications{?since,all,participating}",
   140              "open_issues": 73,
   141              "open_issues_count": 73,
   142              "organization": "slsa-framework",
   143              "owner": {
   144                "avatar_url": "https://avatars.githubusercontent.com/u/80431187?v=4",
   145                "email": null,
   146                "events_url": "https://api.github.com/users/slsa-framework/events{/privacy}",
   147                "followers_url": "https://api.github.com/users/slsa-framework/followers",
   148                "following_url": "https://api.github.com/users/slsa-framework/following{/other_user}",
   149                "gists_url": "https://api.github.com/users/slsa-framework/gists{/gist_id}",
   150                "gravatar_id": "",
   151                "html_url": "https://github.com/slsa-framework",
   152                "id": 80431187,
   153                "login": "slsa-framework",
   154                "name": "slsa-framework",
   155                "node_id": "MDEyOk9yZ2FuaXphdGlvbjgwNDMxMTg3",
   156                "organizations_url": "https://api.github.com/users/slsa-framework/orgs",
   157                "received_events_url": "https://api.github.com/users/slsa-framework/received_events",
   158                "repos_url": "https://api.github.com/users/slsa-framework/repos",
   159                "site_admin": false,
   160                "starred_url": "https://api.github.com/users/slsa-framework/starred{/owner}{/repo}",
   161                "subscriptions_url": "https://api.github.com/users/slsa-framework/subscriptions",
   162                "type": "Organization",
   163                "url": "https://api.github.com/users/slsa-framework"
   164              },
   165              "private": false,
   166              "pulls_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/pulls{/number}",
   167              "pushed_at": 1670975177,
   168              "releases_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/releases{/id}",
   169              "size": 47453,
   170              "ssh_url": "git@github.com:slsa-framework/slsa-verifier.git",
   171              "stargazers": 54,
   172              "stargazers_count": 54,
   173              "stargazers_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/stargazers",
   174              "statuses_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/statuses/{sha}",
   175              "subscribers_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/subscribers",
   176              "subscription_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/subscription",
   177              "svn_url": "https://github.com/slsa-framework/slsa-verifier",
   178              "tags_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/tags",
   179              "teams_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/teams",
   180              "topics": [],
   181              "trees_url": "https://api.github.com/repos/slsa-framework/slsa-verifier/git/trees{/sha}",
   182              "updated_at": "2022-12-13T19:00:37Z",
   183              "url": "https://github.com/slsa-framework/slsa-verifier",
   184              "visibility": "public",
   185              "watchers": 54,
   186              "watchers_count": 54,
   187              "web_commit_signoff_required": true
   188            },
   189            "sender": {
   190              "avatar_url": "https://avatars.githubusercontent.com/u/5194569?v=4",
   191              "events_url": "https://api.github.com/users/asraa/events{/privacy}",
   192              "followers_url": "https://api.github.com/users/asraa/followers",
   193              "following_url": "https://api.github.com/users/asraa/following{/other_user}",
   194              "gists_url": "https://api.github.com/users/asraa/gists{/gist_id}",
   195              "gravatar_id": "",
   196              "html_url": "https://github.com/asraa",
   197              "id": 5194569,
   198              "login": "asraa",
   199              "node_id": "MDQ6VXNlcjUxOTQ1Njk=",
   200              "organizations_url": "https://api.github.com/users/asraa/orgs",
   201              "received_events_url": "https://api.github.com/users/asraa/received_events",
   202              "repos_url": "https://api.github.com/users/asraa/repos",
   203              "site_admin": false,
   204              "starred_url": "https://api.github.com/users/asraa/starred{/owner}{/repo}",
   205              "subscriptions_url": "https://api.github.com/users/asraa/subscriptions",
   206              "type": "User",
   207              "url": "https://api.github.com/users/asraa"
   208            }
   209          },
   210          "github_head_ref": "",
   211          "github_ref": "refs/tags/v2.0.1",
   212          "github_ref_type": "tag",
   213          "github_repository_id": "474162642",
   214          "github_repository_owner": "slsa-framework",
   215          "github_repository_owner_id": "80431187",
   216          "github_run_attempt": "1",
   217          "github_run_id": "3690336455",
   218          "github_run_number": "164",
   219          "github_sha1": "a43888265e1f6aae98c924538298944f2721dcf0",
   220          "os": "ubuntu22"
   221        }
   222      },
   223      "buildConfig": {
   224        "version": 1,
   225        "steps": [
   226          {
   227            "command": [
   228              "/opt/hostedtoolcache/go/1.18.8/x64/bin/go",
   229              "mod",
   230              "vendor"
   231            ],
   232            "env": null,
   233            "workingDir": "/home/runner/work/slsa-verifier/slsa-verifier/__PROJECT_CHECKOUT_DIR__/cli/slsa-verifier"
   234          },
   235          {
   236            "command": [
   237              "/opt/hostedtoolcache/go/1.18.8/x64/bin/go",
   238              "build",
   239              "-mod=vendor",
   240              "-trimpath",
   241              "-tags=netgo",
   242              "-ldflags=-X sigs.k8s.io/release-utils/version.gitVersion=2.0.1",
   243              "-o",
   244              "slsa-verifier-linux-amd64"
   245            ],
   246            "env": [
   247              "GOOS=linux",
   248              "GOARCH=amd64",
   249              "GO111MODULE=on",
   250              "CGO_ENABLED=0"
   251            ],
   252            "workingDir": "/home/runner/work/slsa-verifier/slsa-verifier/__PROJECT_CHECKOUT_DIR__/cli/slsa-verifier"
   253          }
   254        ]
   255      },
   256      "metadata": {
   257        "buildInvocationID": "3690336455-1",
   258        "completeness": {
   259          "parameters": true,
   260          "environment": false,
   261          "materials": false
   262        },
   263        "reproducible": false
   264      },
   265      "materials": [
   266        {
   267          "uri": "git+https://github.com/slsa-framework/slsa-verifier@refs/tags/v2.0.1",
   268          "digest": {
   269            "sha1": "a43888265e1f6aae98c924538298944f2721dcf0"
   270          }
   271        },
   272        {
   273          "uri": "https://github.com/actions/virtual-environments/releases/tag/ubuntu22/20221204.2"
   274        }
   275      ]
   276    }
   277  }