feat(pull): implement pull command with policy verification - #11
Conversation
Add the pull command to download and extract blob archives from OCI registries with optional policy-based verification. Features: - Pull archives from OCI registries with alias resolution - Policy verification: Sigstore keyless signatures, SLSA provenance - Policy sources: config file, YAML files (--policy), OPA Rego (--policy-rego) - Output formats: text and JSON (--output json) - Quiet mode support - Directory handling: creates destination if needed, skips existing files New files: - internal/policy/loader.go: YAML policy file parsing - internal/policy/builder.go: Convert config policies to registry policies - internal/policy/policy_test.go: Policy package tests - cmd/pull_test.go: Pull command tests Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Kusari Analysis Results:Caution Flagged Issues Detected While the code analysis shows no security issues across all 7 scanned files, the dependency analysis reveals a critical anomaly that blocks this PR. Two direct dependencies (github.com/meigma/blob/policy/opa and github.com/meigma/blob/policy/slsa) have version timestamps dated in the future (January 2026), which is highly irregular and could indicate compromised packages, system misconfiguration, or test dependencies incorrectly included in production code. This anomaly must be investigated and resolved before merging. Additionally, a transitive dependency uses a non-OSS license (BSD-2-Clause-Views) that requires compliance review. Action items: (1) Verify the source and authenticity of the future-dated packages, (2) Replace pseudo-versions with properly versioned releases, (3) Review license compatibility for the transitive dependency. Note View full detailed analysis result for more information on the output and the checks that were run. Required Dependency Mitigations
Found this helpful? Give it a 👍 or 👎 reaction! |
Summary
pullcommand to download and extract blob archives from OCI registries--policy), OPA Rego (--policy-rego)Features
--output json)--quietis setTest plan
prepareDestinationfunctionpullTextandpullJSONoutput formattersLoadFile)ConvertConfigPolicy)BuildPolicies)docker.io/meigma/blob-test:v1🤖 Generated with Claude Code