Skip to content

feat(push): implement push command with signing support - #8

Merged
jmgilman merged 2 commits into
masterfrom
feat/push-command
Jan 22, 2026
Merged

jmgilman merged 2 commits into
masterfrom
feat/push-command

Conversation

@jmgilman

Copy link
Copy Markdown
Contributor

Summary

  • Implement the push command to upload directories to OCI registries as blob archives
  • Add zstd compression (default) with option for no compression
  • Support Sigstore keyless signing via --sign flag
  • Add annotation support (--annotation key=value)
  • Fix error display in main.go (errors were silenced but not printed)

Test plan

  • Unit tests added for push command (cmd/push_test.go)
  • Functional test: successfully pushed test files to docker.io/meigma/blob-test:v1
  • Run just ci to verify lint/test/build pass

🤖 Generated with Claude Code

Implement the push command to upload directories to OCI registries as
blob archives. Features include:

- Zstd compression (default) or no compression
- Skip compression for already-compressed files
- Optional Sigstore keyless signing
- Annotation support (key=value format)
- Text and JSON output formats

Also fixes error display in main.go - errors were silenced but not
printed to stderr.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@kusari-inspector

kusari-inspector Bot commented Jan 22, 2026 •

Copy link
Copy Markdown

Kusari Inspector

Kusari Analysis Results:

Do not proceed without addressing issues

Caution

Flagged Issues Detected
These changes contain flagged issues that may introduce security risks.

Critical conflict detected between analyses that must be resolved before merge. The dependency analysis identifies 13 active heap-buffer-overflow vulnerabilities in github.com/google/flatbuffers@v25.12.19+incompatible (via sigstore dependency chain) with specific CVE identifiers and no available fix. These memory corruption vulnerabilities can enable arbitrary code execution. However, the code analysis reports zero vulnerabilities and suggests the issue has been resolved. This discrepancy requires immediate investigation to determine: (1) which scan reflects the actual post-merge dependency state, (2) whether the flatbuffers dependency was truly removed/replaced, or (3) if there is a gap in one of the scanning tools. Additionally, the CC-BY-SA-4.0 license compatibility concern needs verification. Given the critical severity of heap-buffer-overflow vulnerabilities and concrete evidence in the dependency analysis, the secure approach is to block until the conflict is definitively resolved. Action required: Re-run both scans, manually verify go.mod/go.sum for flatbuffers presence, and confirm vulnerability status before proceeding.

Note

View full detailed analysis result for more information on the output and the checks that were run.

Required Dependency Mitigations

  • CRITICAL SECURITY BLOCKER: github.com/google/flatbuffers@v25.12.19+incompatible has 13 unresolved heap-buffer-overflow vulnerabilities (OSV-2021-347, OSV-2021-349, OSV-2021-520, OSV-2021-1229, OSV-2021-1249, OSV-2021-333, OSV-2021-541, OSV-2021-581, OSV-2021-1314, OSV-2021-1678, OSV-2021-1695, OSV-2021-281, OSV-2021-308). Dependency path: github.com/meigma/blob/policy/sigstore → github.com/google/flatbuffers. No fix is available for the current version. Required actions: (1) Contact the maintainers of github.com/meigma/blob/policy/sigstore to request removal or replacement of the flatbuffers dependency, (2) Evaluate if the sigstore policy package is essential for your use case, (3) If required, investigate alternative packages that provide similar functionality without the flatbuffers dependency, or (4) Consider implementing custom verification logic to avoid this dependency chain. The +incompatible version suffix indicates Go module compatibility issues which compounds the security concern.
  • LICENSE INCOMPATIBILITY: github.com/opencontainers/go-digest@v1.0.0 includes CC-BY-SA-4.0 license (marked as non-OSS with share-alike provisions). Dependency path: github.com/meigma/blob/policy/sigstore → github.com/opencontainers/go-digest. This license may impose obligations on your codebase requiring derivative works to be shared under the same license terms. Verify this is compatible with your organization's licensing policy before proceeding. If incompatible, you will need to avoid or replace dependencies that bring in this package.

@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: 45371a3, performed at: 2026-01-22T16:54:55Z

Found this helpful? Give it a 👍 or 👎 reaction!

The replace directive pointing to ../blob only works locally and
breaks CI builds. Use the published module instead.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@kusari-inspector

Copy link
Copy Markdown

Kusari PR Analysis rerun based on - 45371a3 performed at: 2026-01-22T16:56:04Z - link to updated analysis

@jmgilman
jmgilman merged commit 8d269cf into master Jan 22, 2026
4 of 5 checks passed
@jmgilman
jmgilman deleted the feat/push-command branch January 22, 2026 17:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant