Skip to main content

Tools to make using Rekor eaiser

Project description

A tool for verifying artifacts logged to Rekor

You can find out more about this tool and the motivation behind it at https://github.com/wp732/ssc_assignment_1

usage: wp732_rekor_tool [-h] [-d] [-c] [--inclusion INCLUSION] [--artifact ARTIFACT] [--consistency]
[--tree-id TREE_ID] [--tree-size TREE_SIZE] [--root-hash ROOT_HASH] [-e ENTRY]

Rekor Verifier

options:
-h, --help show this help message and exit
-d, --debug Debug mode
-c, --checkpoint Obtain latest checkpoint from Rekor Server public instance. When used with -d
also saves the checkpoint to ~/checkpoint.json
--inclusion INCLUSION
Verify inclusion of an entry in the Rekor Transparency Log using log index and
artifact filename. Usage: --inclusion 126574567
--artifact ARTIFACT Artifact filepath for verifying signature
--consistency Verify consistency of a given checkpoint with the latest checkpoint.
--tree-id TREE_ID Tree ID for consistency proof
--tree-size TREE_SIZE
Tree size for consistency proof
--root-hash ROOT_HASH
Root hash for consistency proof
-e ENTRY, --entry ENTRY
Get Rekor log entry by log index Usage: --entry 126574567

Examples

wp732_rekor_tool \
--checkpoint

wp732_rekor_tool \
--inclusion <log index from .rekorBundle.Payload.logIndex of artifact bundle json> \
--artifact

wp732_rekor_tool \
--consistency \
--tree-id <rekor tree id from .treeID of artifact bundle json> \
--tree-size <rekor tree size from .treeSize of artifact bundle json> \
--root-hash <rekor root hash from .rootHash of artifact bundle json>

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

wp732_rekor_tools-4.0.0.tar.gz (10.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

wp732_rekor_tools-4.0.0-py3-none-any.whl (13.6 kB view details)

Uploaded Python 3

File details

Details for the file wp732_rekor_tools-4.0.0.tar.gz.

File metadata

  • Download URL: wp732_rekor_tools-4.0.0.tar.gz
  • Upload date:
  • Size: 10.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/2.2.1 CPython/3.11.2 Linux/6.12.34+rpt-rpi-v8

File hashes

Hashes for wp732_rekor_tools-4.0.0.tar.gz
Algorithm Hash digest
SHA256 00d62d0def751013d21e4f3602522c6d9bf24bf0007dc0c51805847a7922bfc1
MD5 c2c47504e215149d8ed1243bc6e050b5
BLAKE2b-256 32afd86b3ea37d1e9d9bfe670be157dd3a0077e360049f802e1a6401cf3c44ba

See more details on using hashes here.

File details

Details for the file wp732_rekor_tools-4.0.0-py3-none-any.whl.

File metadata

  • Download URL: wp732_rekor_tools-4.0.0-py3-none-any.whl
  • Upload date:
  • Size: 13.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/2.2.1 CPython/3.11.2 Linux/6.12.34+rpt-rpi-v8

File hashes

Hashes for wp732_rekor_tools-4.0.0-py3-none-any.whl
Algorithm Hash digest
SHA256 4a8b9c7637265522e831381e75c05e68cc799fa2b94d67b611789b72dd04c21c
MD5 1d2e00d0e4d2085aa95199e71cc5c989
BLAKE2b-256 93cdc1893bb475ce48aa664a5fba51ec128cc2cc1c9a0911b4471fa2fa18d29b

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page