Skip to main content

Verify your software using trusted supply chains.

Project description

Python Rekor Monitor

Verify your software using trusted supply chains.

Description

This repository uses Rekor API, a tool that helps improve security in software supply chains by providing immutable records of software build metadata. This repository includes code that interacts with Rekor's API and verifies the consistency using transparency logs.

Installation

  1. Clone the repository:
git clone https://github.com/JacksonQu/Software-Supply-Chain-Security-Assignment1.git
cd Software-Supply-Chain-Security-Assignment1/
  1. (Optional) Create a virtual environment:
python -m venv venv
source venv/bin/activate
  1. Install dependencies:
pip install cryptography requests

Usage

  • Fetch a checkpoint of Rekor transparency log.
python main.py -c
  • Verify the artifact signature.
python main.py --inclusion {logIndex} --artifact {filepath}
  • Verify merkle tree consistency.
python main.py --consistency --tree-id {treeID} --tree-size {treeSize} --root-hash {hash}

Reference

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

rekor_monitor_jacksonqu-4.0.1.tar.gz (18.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

rekor_monitor_jacksonqu-4.0.1-py3-none-any.whl (19.8 kB view details)

Uploaded Python 3

File details

Details for the file rekor_monitor_jacksonqu-4.0.1.tar.gz.

File metadata

  • Download URL: rekor_monitor_jacksonqu-4.0.1.tar.gz
  • Upload date:
  • Size: 18.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/1.8.4 CPython/3.10.9 Linux/5.15.0-124-generic

File hashes

Hashes for rekor_monitor_jacksonqu-4.0.1.tar.gz
Algorithm Hash digest
SHA256 e4bb908c4923ef35bc3805cb2db6c82e96b52eed9cd8a4d22c1e4ff3e978b284
MD5 116e5d8367c3518f4f6a90405f9c5a52
BLAKE2b-256 8c3ed4138fc59ee895d59e7f1f6cc4a5881597cf14520a2e835fa1a383d66600

See more details on using hashes here.

File details

Details for the file rekor_monitor_jacksonqu-4.0.1-py3-none-any.whl.

File metadata

File hashes

Hashes for rekor_monitor_jacksonqu-4.0.1-py3-none-any.whl
Algorithm Hash digest
SHA256 1df1c1cca519e4ccbac790d5fe7d448222c8edd7c61da744fd12e492a0ae6631
MD5 0962dc52054dbebfc0b38072370069fe
BLAKE2b-256 57c55a58243b33b7357dde708b381d9cbb0c2ab6459b5790bd53f8c764fb3ecb

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page