Skip to content

feat(sign,verify): implement sign and verify commands - #16

Merged
jmgilman merged 1 commit into
masterfrom
feat/sign-verify-commands
Jan 23, 2026
Merged

jmgilman merged 1 commit into
masterfrom
feat/sign-verify-commands

Conversation

@jmgilman

Copy link
Copy Markdown
Contributor

Summary

  • Implement sign command with keyless and key-based signing support
  • Implement verify command with policy-based verification
  • Add --output-signature flag for signing to stdout
  • Add --no-default-policy flag to skip config file policies
  • Add ExitError type for exit code 5 on policy violations
  • Add tests for new behaviors

Test plan

  • just lint passes (0 issues)
  • go build succeeds
  • New tests pass (TestExtractReference, TestSignToStdout_InvalidReference, TestExitError, TestVerifyJSON_StatusFieldClarity)
  • Manual test: blob verify docker.io/meigma/blob-test:v1 shows warning and digest
  • Manual test: blob verify --output json docker.io/meigma/blob-test:v1 includes status field
  • Manual test: blob sign --help shows expected flags

🤖 Generated with Claude Code

Implement the sign and verify commands per DESIGN.md:

Sign command:
- Keyless signing (default) using Fulcio/Rekor with ambient credentials
- Key-based signing with --key flag (PEM file, BLOB_KEY_PASSWORD env)
- --output-signature flag to print signature bundle to stdout

Verify command:
- --policy flag (repeatable) for YAML policy files
- --policy-rego flag for OPA Rego policies
- --no-default-policy flag to skip config file policies
- Clear status field in JSON output ("verified" vs "no_policies")
- Exit code 5 for policy violations per DESIGN.md

Also adds:
- ExitError type for specific exit codes
- Tests for new behaviors including reference parsing and output formats

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@jmgilman
jmgilman merged commit 61a4519 into master Jan 23, 2026
5 checks passed
@jmgilman
jmgilman deleted the feat/sign-verify-commands branch January 23, 2026 18:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant