From cdee30a9d9021a1e73f61b4a6e6be41c9a0e03c6 Mon Sep 17 00:00:00 2001 From: "Adolfo Garcia Veytia (puerco)" Date: Mon, 28 Sep 2026 16:20:31 +0100 Subject: [PATCH] Use the shared slsa-framework/protos source provenance definitions This commit updates sourcetool to use the hared proto definitions from slsa/protos which all tools now share. The older definitios are sitill in the repo Signed-off-by: Adolfo Garcia Veytia (puerco) --- Makefile | 2 +- go.mod | 1 + go.sum | 2 + internal/cmd/audit.go | 24 +- internal/cmd/audit_test.go | 4 +- pkg/attest/attester.go | 4 +- pkg/attest/provenance.go | 2 +- pkg/provenance/predicate.go | 62 +-- pkg/provenance/provenance.pb.go | 409 ------------------- pkg/sourcetool/backends/vcs/github/github.go | 5 +- proto/v1/provenance.proto | 50 --- 11 files changed, 57 insertions(+), 508 deletions(-) delete mode 100644 pkg/provenance/provenance.pb.go delete mode 100644 proto/v1/provenance.proto diff --git a/Makefile b/Makefile index d3801a33..2ae66b78 100644 --- a/Makefile +++ b/Makefile @@ -14,5 +14,5 @@ fakes: ## Rebuild the implementation fakes go generate ./... .PHONY: proto -proto: ## Rebuild the policies and provenance predicate from protocol buffer definitions +proto: ## Rebuild the policy types from the protocol buffer definitions buf generate diff --git a/go.mod b/go.mod index b4b5e590..d853eb4f 100644 --- a/go.mod +++ b/go.mod @@ -17,6 +17,7 @@ require ( github.com/maxbrunsfeld/counterfeiter/v6 v6.13.0 github.com/migueleliasweb/go-github-mock v1.5.0 github.com/sigstore/sigstore-go v1.3.0 + github.com/slsa-framework/protos v0.0.0-20260905230943-612c99695f3b github.com/spf13/cobra v1.10.2 github.com/stretchr/testify v1.12.1 golang.org/x/mod v0.41.0 diff --git a/go.sum b/go.sum index fc8c95bc..8d6c93da 100644 --- a/go.sum +++ b/go.sum @@ -529,6 +529,8 @@ github.com/sirupsen/logrus v1.10.2 h1:G2SED73/qrAu6YwbdxOD6peLkCBI3z7L+ykJFTXJBB github.com/sirupsen/logrus v1.10.2/go.mod h1:SLEg8TqYulVKKfIGHldVp2K2aYz2DKSVBq4g/H5bR7Q= github.com/skeema/knownhosts v1.3.2 h1:EDL9mgf4NzwMXCTfaxSD/o/a5fxDw/xL9nkU28JjdBg= github.com/skeema/knownhosts v1.3.2/go.mod h1:bEg3iQAuw+jyiw+484wwFJoKSLwcfd7fqRy+N0QTiow= +github.com/slsa-framework/protos v0.0.0-20260905230943-612c99695f3b h1:6IjAVZhOCYCgkcYc8gDYI8nr7pnHlQ8FaL1l7Y2OPfg= +github.com/slsa-framework/protos v0.0.0-20260905230943-612c99695f3b/go.mod h1:qIbxqThHVEmY1OTDwTg+iXPd/CU9AXyab7BBvk1V2gk= github.com/spdx/tools-golang v0.5.7 h1:+sWcKGnhwp3vLdMqPcLdA6QK679vd86cK9hQWH3AwCg= github.com/spdx/tools-golang v0.5.7/go.mod h1:jg7w0LOpoNAw6OxKEzCoqPC2GCTj45LyTlVmXubDsYw= github.com/spf13/cobra v1.10.2 h1:DMTTonx5m65Ic0GOoRY2c16WCbHxOOw6xxezuLaBpcU= diff --git a/internal/cmd/audit.go b/internal/cmd/audit.go index 8c5533d1..5c7c51ae 100644 --- a/internal/cmd/audit.go +++ b/internal/cmd/audit.go @@ -10,6 +10,7 @@ import ( "github.com/spf13/cobra" "github.com/slsa-framework/source-tool/pkg/audit" + "github.com/slsa-framework/source-tool/pkg/provenance" "github.com/slsa-framework/source-tool/pkg/sourcetool" ) @@ -83,6 +84,27 @@ type AuditCommitResultJSON struct { Error string `json:"error,omitempty"` } +// ControlJSON is the JSON rendering of a provenance control. The predicate +// types are protobuf messages meant for protojson, so their timestamps are +// formatted here before the result goes through encoding/json. +type ControlJSON struct { + Name string `json:"name"` + Since string `json:"since"` +} + +// provControlsToJSON converts provenance controls to their JSON rendering. +func provControlsToJSON(controls []*provenance.Control) []ControlJSON { + ret := make([]ControlJSON, 0, len(controls)) + for _, c := range controls { + var since string + if c.GetSince() != nil { + since = c.GetSince().AsTime().Format("2006-01-02T15:04:05.000Z") + } + ret = append(ret, ControlJSON{Name: c.GetName(), Since: since}) + } + return ret +} + // AuditResultJSON represents the full audit result in JSON format type AuditResultJSON struct { Owner string `json:"owner"` @@ -314,7 +336,7 @@ func convertAuditResultToJSON(owner, repo string, ar *audit.AuditCommitResult, m } if ar.ProvPred != nil { - result.ProvControls = ar.ProvPred.GetControls() + result.ProvControls = provControlsToJSON(ar.ProvPred.GetControls()) result.PrevCommit = ar.ProvPred.GetPrevCommit() result.PriorCommit = ar.PriorCommit matches := ar.ProvPred.GetPrevCommit() == ar.PriorCommit diff --git a/internal/cmd/audit_test.go b/internal/cmd/audit_test.go index e6c1633a..21daa82a 100644 --- a/internal/cmd/audit_test.go +++ b/internal/cmd/audit_test.go @@ -186,7 +186,7 @@ func TestConvertAuditResultToJSON(t *testing.T) { Status: "passed", VerifiedLevels: []string{"SLSA_SOURCE_LEVEL_3"}, PrevCommitMatches: &matches, - ProvControls: []*provenance.Control{{Name: "test_control"}}, + ProvControls: []ControlJSON{{Name: "test_control"}}, Controls: slsa.ControlSet{}, PrevCommit: "def456", PriorCommit: "def456", @@ -230,7 +230,7 @@ func TestConvertAuditResultToJSON(t *testing.T) { Status: "failed", VerifiedLevels: []string{"SLSA_SOURCE_LEVEL_3"}, PrevCommitMatches: &matches, - ProvControls: []*provenance.Control{{Name: "test_control"}}, + ProvControls: []ControlJSON{{Name: "test_control"}}, PrevCommit: "wrong123", PriorCommit: "def456", Link: "https://github.com/test-owner/test-repo/commit/def456", diff --git a/pkg/attest/attester.go b/pkg/attest/attester.go index 07a26aaa..475938cb 100644 --- a/pkg/attest/attester.go +++ b/pkg/attest/attester.go @@ -184,8 +184,8 @@ func (a *Attester) createCurrentProvenance(ctx context.Context, branch *models.B // ... indeed, but don't set the `since`` date because doing so breaks // checking against policies. // See https://github.com/slsa-framework/source-tool/issues/272 - if curProvPred.GetControl(slsa.SLSA_SOURCE_SCS_PROVENANCE.String()) == nil { - curProvPred.AddControl( + if provenance.GetControl(&curProvPred, slsa.SLSA_SOURCE_SCS_PROVENANCE.String()) == nil { + provenance.AddControl(&curProvPred, &provenance.Control{ Name: slsa.SLSA_SOURCE_SCS_PROVENANCE.String(), }, diff --git a/pkg/attest/provenance.go b/pkg/attest/provenance.go index e0bc891b..3eb61f70 100644 --- a/pkg/attest/provenance.go +++ b/pkg/attest/provenance.go @@ -329,7 +329,7 @@ func (a *Attester) CreateSourceProvenance(ctx context.Context, branch *models.Br // There was prior provenance, so update the Since field for each property // to the oldest encountered. for i, curControl := range curProvPred.GetControls() { - prevControl := prevProvPred.GetControl(curControl.GetName()) + prevControl := provenance.GetControl(prevProvPred, curControl.GetName()) // No prior version of this control if prevControl == nil { continue diff --git a/pkg/provenance/predicate.go b/pkg/provenance/predicate.go index c4b2abb5..9d604db7 100644 --- a/pkg/provenance/predicate.go +++ b/pkg/provenance/predicate.go @@ -1,17 +1,35 @@ // SPDX-FileCopyrightText: Copyright 2025 The SLSA Authors // SPDX-License-Identifier: Apache-2.0 +// Package provenance exposes the SLSA source provenance predicate types. +// +// The message definitions live in the shared slsa-framework/protos module; +// this package aliases them so callers keep a descriptive import name and +// adds the predicate type URIs and a few helpers around the generated code. package provenance -import "encoding/json" +import ( + sourcetoolv1 "github.com/slsa-framework/protos/sourcetool/v1" +) const ( SourceProvPredicateType = "https://github.com/slsa-framework/slsa-source-poc/source-provenance/v1-draft" TagProvPredicateType = "https://github.com/slsa-framework/slsa-source-poc/tag-provenance/v1-draft" ) +type ( + // SourceProvenancePred is the source provenance predicate. + SourceProvenancePred = sourcetoolv1.SourceProvenancePred + // Control records a control enforced on the source and since when. + Control = sourcetoolv1.Control + // TagProvenancePred is the tag provenance predicate. + TagProvenancePred = sourcetoolv1.TagProvenancePred + // VsaSummary summarizes a VSA referenced from tag provenance. + VsaSummary = sourcetoolv1.VsaSummary +) + // GetControl looks for a control by name in the predicate. -func (pred *SourceProvenancePred) GetControl(name string) *Control { +func GetControl(pred *SourceProvenancePred, name string) *Control { for _, control := range pred.GetControls() { if control.GetName() == name { return control @@ -20,8 +38,8 @@ func (pred *SourceProvenancePred) GetControl(name string) *Control { return nil } -// AddControl adds a new control to the predicate. -func (pred *SourceProvenancePred) AddControl(newControls ...*Control) { +// AddControl adds new controls to the predicate, skipping nil entries. +func AddControl(pred *SourceProvenancePred, newControls ...*Control) { for _, c := range newControls { if c == nil { continue @@ -29,39 +47,3 @@ func (pred *SourceProvenancePred) AddControl(newControls ...*Control) { pred.Controls = append(pred.Controls, c) } } - -func (pred *SourceProvenancePred) MarshalJSON() ([]byte, error) { - type Alias SourceProvenancePred - var con string - if pred.GetCreatedOn() != nil { - con = pred.GetCreatedOn().AsTime().Format("2006-01-02T15:04:05.000Z") - } - - return json.Marshal( - &struct { - CreatedOn string `json:"created_on"` - *Alias - }{ - CreatedOn: con, - Alias: (*Alias)(pred), - }, - ) -} - -func (ctl *Control) MarshalJSON() ([]byte, error) { - type Alias Control - var since string - if ctl.GetSince() != nil { - since = ctl.GetSince().AsTime().Format("2006-01-02T15:04:05.000Z") - } - - return json.Marshal( - &struct { - CreatedOn string `json:"since"` - *Alias - }{ - CreatedOn: since, - Alias: (*Alias)(ctl), - }, - ) -} diff --git a/pkg/provenance/provenance.pb.go b/pkg/provenance/provenance.pb.go deleted file mode 100644 index f3ea55e2..00000000 --- a/pkg/provenance/provenance.pb.go +++ /dev/null @@ -1,409 +0,0 @@ -// SPDX-FileCopyrightText: Copyright 2025 The SLSA Authors -// SPDX-License-Identifier: Apache-2.0 - -// Code generated by protoc-gen-go. DO NOT EDIT. -// versions: -// protoc-gen-go v1.36.12 -// protoc (unknown) -// source: provenance.proto - -package provenance - -import ( - protoreflect "google.golang.org/protobuf/reflect/protoreflect" - protoimpl "google.golang.org/protobuf/runtime/protoimpl" - timestamppb "google.golang.org/protobuf/types/known/timestamppb" - reflect "reflect" - sync "sync" - unsafe "unsafe" -) - -const ( - // Verify that this generated code is sufficiently up-to-date. - _ = protoimpl.EnforceVersion(20 - protoimpl.MinVersion) - // Verify that runtime/protoimpl is sufficiently up-to-date. - _ = protoimpl.EnforceVersion(protoimpl.MaxVersion - 20) -) - -// The predicate that encodes source provenance data. -// The git commit this corresponds to is encoded in the surrounding statement. -type SourceProvenancePred struct { - state protoimpl.MessageState `protogen:"open.v1"` - // The commit preceding 'Commit' in the current context. - PrevCommit string `protobuf:"bytes,1,opt,name=prev_commit,json=prevCommit,proto3" json:"prev_commit,omitempty"` - RepoUri string `protobuf:"bytes,2,opt,name=repo_uri,json=repoUri,proto3" json:"repo_uri,omitempty"` - ActivityType string `protobuf:"bytes,3,opt,name=activity_type,json=activityType,proto3" json:"activity_type,omitempty"` - Actor string `protobuf:"bytes,4,opt,name=actor,proto3" json:"actor,omitempty"` - Branch string `protobuf:"bytes,5,opt,name=branch,proto3" json:"branch,omitempty"` - CreatedOn *timestamppb.Timestamp `protobuf:"bytes,6,opt,name=created_on,json=createdOn,proto3,oneof" json:"created_on,omitempty"` // TODO: get the author of the PR (if this was from a PR). - // The controls enabled at the time this commit was pushed. - Controls []*Control `protobuf:"bytes,7,rep,name=controls,proto3" json:"controls,omitempty"` - unknownFields protoimpl.UnknownFields - sizeCache protoimpl.SizeCache -} - -func (x *SourceProvenancePred) Reset() { - *x = SourceProvenancePred{} - mi := &file_provenance_proto_msgTypes[0] - ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) - ms.StoreMessageInfo(mi) -} - -func (x *SourceProvenancePred) String() string { - return protoimpl.X.MessageStringOf(x) -} - -func (*SourceProvenancePred) ProtoMessage() {} - -func (x *SourceProvenancePred) ProtoReflect() protoreflect.Message { - mi := &file_provenance_proto_msgTypes[0] - if x != nil { - ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) - if ms.LoadMessageInfo() == nil { - ms.StoreMessageInfo(mi) - } - return ms - } - return mi.MessageOf(x) -} - -// Deprecated: Use SourceProvenancePred.ProtoReflect.Descriptor instead. -func (*SourceProvenancePred) Descriptor() ([]byte, []int) { - return file_provenance_proto_rawDescGZIP(), []int{0} -} - -func (x *SourceProvenancePred) GetPrevCommit() string { - if x != nil { - return x.PrevCommit - } - return "" -} - -func (x *SourceProvenancePred) GetRepoUri() string { - if x != nil { - return x.RepoUri - } - return "" -} - -func (x *SourceProvenancePred) GetActivityType() string { - if x != nil { - return x.ActivityType - } - return "" -} - -func (x *SourceProvenancePred) GetActor() string { - if x != nil { - return x.Actor - } - return "" -} - -func (x *SourceProvenancePred) GetBranch() string { - if x != nil { - return x.Branch - } - return "" -} - -func (x *SourceProvenancePred) GetCreatedOn() *timestamppb.Timestamp { - if x != nil { - return x.CreatedOn - } - return nil -} - -func (x *SourceProvenancePred) GetControls() []*Control { - if x != nil { - return x.Controls - } - return nil -} - -type Control struct { - state protoimpl.MessageState `protogen:"open.v1"` - // The name of the control - Name string `protobuf:"bytes,1,opt,name=name,proto3" json:"name,omitempty"` - // The time from which this control has been continuously enforced/observed. - Since *timestamppb.Timestamp `protobuf:"bytes,2,opt,name=since,proto3" json:"since,omitempty"` - unknownFields protoimpl.UnknownFields - sizeCache protoimpl.SizeCache -} - -func (x *Control) Reset() { - *x = Control{} - mi := &file_provenance_proto_msgTypes[1] - ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) - ms.StoreMessageInfo(mi) -} - -func (x *Control) String() string { - return protoimpl.X.MessageStringOf(x) -} - -func (*Control) ProtoMessage() {} - -func (x *Control) ProtoReflect() protoreflect.Message { - mi := &file_provenance_proto_msgTypes[1] - if x != nil { - ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) - if ms.LoadMessageInfo() == nil { - ms.StoreMessageInfo(mi) - } - return ms - } - return mi.MessageOf(x) -} - -// Deprecated: Use Control.ProtoReflect.Descriptor instead. -func (*Control) Descriptor() ([]byte, []int) { - return file_provenance_proto_rawDescGZIP(), []int{1} -} - -func (x *Control) GetName() string { - if x != nil { - return x.Name - } - return "" -} - -func (x *Control) GetSince() *timestamppb.Timestamp { - if x != nil { - return x.Since - } - return nil -} - -type TagProvenancePred struct { - state protoimpl.MessageState `protogen:"open.v1"` - RepoUri string `protobuf:"bytes,1,opt,name=repo_uri,json=repoUri,proto3" json:"repo_uri,omitempty"` - Actor string `protobuf:"bytes,2,opt,name=actor,proto3" json:"actor,omitempty"` - Tag string `protobuf:"bytes,3,opt,name=tag,proto3" json:"tag,omitempty"` - CreatedOn *timestamppb.Timestamp `protobuf:"bytes,4,opt,name=created_on,json=createdOn,proto3,oneof" json:"created_on,omitempty"` - // The tag related controls enabled at the time this tag was created/updated. - Controls []*Control `protobuf:"bytes,7,rep,name=controls,proto3" json:"controls,omitempty"` - VsaSummaries []*VsaSummary `protobuf:"bytes,8,rep,name=vsa_summaries,json=vsaSummaries,proto3" json:"vsa_summaries,omitempty"` - unknownFields protoimpl.UnknownFields - sizeCache protoimpl.SizeCache -} - -func (x *TagProvenancePred) Reset() { - *x = TagProvenancePred{} - mi := &file_provenance_proto_msgTypes[2] - ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) - ms.StoreMessageInfo(mi) -} - -func (x *TagProvenancePred) String() string { - return protoimpl.X.MessageStringOf(x) -} - -func (*TagProvenancePred) ProtoMessage() {} - -func (x *TagProvenancePred) ProtoReflect() protoreflect.Message { - mi := &file_provenance_proto_msgTypes[2] - if x != nil { - ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) - if ms.LoadMessageInfo() == nil { - ms.StoreMessageInfo(mi) - } - return ms - } - return mi.MessageOf(x) -} - -// Deprecated: Use TagProvenancePred.ProtoReflect.Descriptor instead. -func (*TagProvenancePred) Descriptor() ([]byte, []int) { - return file_provenance_proto_rawDescGZIP(), []int{2} -} - -func (x *TagProvenancePred) GetRepoUri() string { - if x != nil { - return x.RepoUri - } - return "" -} - -func (x *TagProvenancePred) GetActor() string { - if x != nil { - return x.Actor - } - return "" -} - -func (x *TagProvenancePred) GetTag() string { - if x != nil { - return x.Tag - } - return "" -} - -func (x *TagProvenancePred) GetCreatedOn() *timestamppb.Timestamp { - if x != nil { - return x.CreatedOn - } - return nil -} - -func (x *TagProvenancePred) GetControls() []*Control { - if x != nil { - return x.Controls - } - return nil -} - -func (x *TagProvenancePred) GetVsaSummaries() []*VsaSummary { - if x != nil { - return x.VsaSummaries - } - return nil -} - -// Summary of a summary -type VsaSummary struct { - state protoimpl.MessageState `protogen:"open.v1"` - SourceRefs []string `protobuf:"bytes,1,rep,name=source_refs,json=sourceRefs,proto3" json:"source_refs,omitempty"` - VerifiedLevels []string `protobuf:"bytes,2,rep,name=verified_levels,json=verifiedLevels,proto3" json:"verified_levels,omitempty"` - unknownFields protoimpl.UnknownFields - sizeCache protoimpl.SizeCache -} - -func (x *VsaSummary) Reset() { - *x = VsaSummary{} - mi := &file_provenance_proto_msgTypes[3] - ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) - ms.StoreMessageInfo(mi) -} - -func (x *VsaSummary) String() string { - return protoimpl.X.MessageStringOf(x) -} - -func (*VsaSummary) ProtoMessage() {} - -func (x *VsaSummary) ProtoReflect() protoreflect.Message { - mi := &file_provenance_proto_msgTypes[3] - if x != nil { - ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) - if ms.LoadMessageInfo() == nil { - ms.StoreMessageInfo(mi) - } - return ms - } - return mi.MessageOf(x) -} - -// Deprecated: Use VsaSummary.ProtoReflect.Descriptor instead. -func (*VsaSummary) Descriptor() ([]byte, []int) { - return file_provenance_proto_rawDescGZIP(), []int{3} -} - -func (x *VsaSummary) GetSourceRefs() []string { - if x != nil { - return x.SourceRefs - } - return nil -} - -func (x *VsaSummary) GetVerifiedLevels() []string { - if x != nil { - return x.VerifiedLevels - } - return nil -} - -var File_provenance_proto protoreflect.FileDescriptor - -const file_provenance_proto_rawDesc = "" + - "\n" + - "\x10provenance.proto\x123in_toto_attestation.predicates.source_provenance.v1\x1a\x1fgoogle/protobuf/timestamp.proto\"\xce\x02\n" + - "\x14SourceProvenancePred\x12\x1f\n" + - "\vprev_commit\x18\x01 \x01(\tR\n" + - "prevCommit\x12\x19\n" + - "\brepo_uri\x18\x02 \x01(\tR\arepoUri\x12#\n" + - "\ractivity_type\x18\x03 \x01(\tR\factivityType\x12\x14\n" + - "\x05actor\x18\x04 \x01(\tR\x05actor\x12\x16\n" + - "\x06branch\x18\x05 \x01(\tR\x06branch\x12>\n" + - "\n" + - "created_on\x18\x06 \x01(\v2\x1a.google.protobuf.TimestampH\x00R\tcreatedOn\x88\x01\x01\x12X\n" + - "\bcontrols\x18\a \x03(\v2<.in_toto_attestation.predicates.source_provenance.v1.ControlR\bcontrolsB\r\n" + - "\v_created_on\"O\n" + - "\aControl\x12\x12\n" + - "\x04name\x18\x01 \x01(\tR\x04name\x120\n" + - "\x05since\x18\x02 \x01(\v2\x1a.google.protobuf.TimestampR\x05since\"\xe5\x02\n" + - "\x11TagProvenancePred\x12\x19\n" + - "\brepo_uri\x18\x01 \x01(\tR\arepoUri\x12\x14\n" + - "\x05actor\x18\x02 \x01(\tR\x05actor\x12\x10\n" + - "\x03tag\x18\x03 \x01(\tR\x03tag\x12>\n" + - "\n" + - "created_on\x18\x04 \x01(\v2\x1a.google.protobuf.TimestampH\x00R\tcreatedOn\x88\x01\x01\x12X\n" + - "\bcontrols\x18\a \x03(\v2<.in_toto_attestation.predicates.source_provenance.v1.ControlR\bcontrols\x12d\n" + - "\rvsa_summaries\x18\b \x03(\v2?.in_toto_attestation.predicates.source_provenance.v1.VsaSummaryR\fvsaSummariesB\r\n" + - "\v_created_on\"V\n" + - "\n" + - "VsaSummary\x12\x1f\n" + - "\vsource_refs\x18\x01 \x03(\tR\n" + - "sourceRefs\x12'\n" + - "\x0fverified_levels\x18\x02 \x03(\tR\x0everifiedLevelsB\xe3\x02\n" + - "7com.in_toto_attestation.predicates.source_provenance.v1B\x0fProvenanceProtoP\x01Z4github.com/slsa-framework/source-tool/pkg/provenance\xa2\x02\x03IPS\xaa\x020InTotoAttestation.Predicates.SourceProvenance.V1\xca\x020InTotoAttestation\\Predicates\\SourceProvenance\\V1\xe2\x02 google.protobuf.Timestamp - 1, // 1: in_toto_attestation.predicates.source_provenance.v1.SourceProvenancePred.controls:type_name -> in_toto_attestation.predicates.source_provenance.v1.Control - 4, // 2: in_toto_attestation.predicates.source_provenance.v1.Control.since:type_name -> google.protobuf.Timestamp - 4, // 3: in_toto_attestation.predicates.source_provenance.v1.TagProvenancePred.created_on:type_name -> google.protobuf.Timestamp - 1, // 4: in_toto_attestation.predicates.source_provenance.v1.TagProvenancePred.controls:type_name -> in_toto_attestation.predicates.source_provenance.v1.Control - 3, // 5: in_toto_attestation.predicates.source_provenance.v1.TagProvenancePred.vsa_summaries:type_name -> in_toto_attestation.predicates.source_provenance.v1.VsaSummary - 6, // [6:6] is the sub-list for method output_type - 6, // [6:6] is the sub-list for method input_type - 6, // [6:6] is the sub-list for extension type_name - 6, // [6:6] is the sub-list for extension extendee - 0, // [0:6] is the sub-list for field type_name -} - -func init() { file_provenance_proto_init() } -func file_provenance_proto_init() { - if File_provenance_proto != nil { - return - } - file_provenance_proto_msgTypes[0].OneofWrappers = []any{} - file_provenance_proto_msgTypes[2].OneofWrappers = []any{} - type x struct{} - out := protoimpl.TypeBuilder{ - File: protoimpl.DescBuilder{ - GoPackagePath: reflect.TypeOf(x{}).PkgPath(), - RawDescriptor: unsafe.Slice(unsafe.StringData(file_provenance_proto_rawDesc), len(file_provenance_proto_rawDesc)), - NumEnums: 0, - NumMessages: 4, - NumExtensions: 0, - NumServices: 0, - }, - GoTypes: file_provenance_proto_goTypes, - DependencyIndexes: file_provenance_proto_depIdxs, - MessageInfos: file_provenance_proto_msgTypes, - }.Build() - File_provenance_proto = out.File - file_provenance_proto_goTypes = nil - file_provenance_proto_depIdxs = nil -} diff --git a/pkg/sourcetool/backends/vcs/github/github.go b/pkg/sourcetool/backends/vcs/github/github.go index 1a04a9e7..c7d2361b 100644 --- a/pkg/sourcetool/backends/vcs/github/github.go +++ b/pkg/sourcetool/backends/vcs/github/github.go @@ -13,6 +13,7 @@ import ( "github.com/slsa-framework/source-tool/pkg/attest" "github.com/slsa-framework/source-tool/pkg/auth" "github.com/slsa-framework/source-tool/pkg/ghcontrol" + "github.com/slsa-framework/source-tool/pkg/provenance" "github.com/slsa-framework/source-tool/pkg/slsa" "github.com/slsa-framework/source-tool/pkg/sourcetool/models" ) @@ -186,12 +187,12 @@ func (b *Backend) GetBranchControlsAtCommit(ctx context.Context, branch *models. // We carry over the since date from the previous attestation, only if // it > 0 (unix origin) var t *time.Time - if ctrl := attestation.GetControl(slsa.SLSA_SOURCE_SCS_PROVENANCE.String()); ctrl != nil { + if ctrl := provenance.GetControl(attestation, slsa.SLSA_SOURCE_SCS_PROVENANCE.String()); ctrl != nil { if ctrl.GetSince() != nil && ctrl.GetSince().AsTime().Unix() != 0 { rt := ctrl.GetSince().AsTime() t = &rt } - } else if ctrl := attestation.GetControl(slsa.DEPRECATED_ProvenanceAvailable.String()); ctrl != nil { + } else if ctrl := provenance.GetControl(attestation, slsa.DEPRECATED_ProvenanceAvailable.String()); ctrl != nil { if ctrl.GetSince() != nil && ctrl.GetSince().AsTime().Unix() != 0 { rt := ctrl.GetSince().AsTime() t = &rt diff --git a/proto/v1/provenance.proto b/proto/v1/provenance.proto deleted file mode 100644 index 15fd5298..00000000 --- a/proto/v1/provenance.proto +++ /dev/null @@ -1,50 +0,0 @@ -// SPDX-FileCopyrightText: Copyright 2025 The SLSA Authors -// SPDX-License-Identifier: Apache-2.0 - -syntax = "proto3"; -package in_toto_attestation.predicates.source_provenance.v1; - -import "google/protobuf/timestamp.proto"; - -// buf:lint:ignore PACKAGE_SAME_GO_PACKAGE -option go_package = "github.com/slsa-framework/source-tool/pkg/provenance"; - -// The predicate that encodes source provenance data. -// The git commit this corresponds to is encoded in the surrounding statement. -message SourceProvenancePred { - // The commit preceding 'Commit' in the current context. - string prev_commit = 1; - string repo_uri = 2; - string activity_type = 3; - string actor = 4; - string branch = 5; - optional google.protobuf.Timestamp created_on = 6; - // TODO: get the author of the PR (if this was from a PR). - - // The controls enabled at the time this commit was pushed. - repeated Control controls = 7; -} - -message Control { - // The name of the control - string name = 1; - // The time from which this control has been continuously enforced/observed. - google.protobuf.Timestamp since = 2; -} - -message TagProvenancePred { - string repo_uri = 1; - string actor = 2; - string tag = 3; - optional google.protobuf.Timestamp created_on = 4; - - // The tag related controls enabled at the time this tag was created/updated. - repeated Control controls = 7; - repeated VsaSummary vsa_summaries = 8; -} - -// Summary of a summary -message VsaSummary { - repeated string source_refs = 1; - repeated string verified_levels = 2 [json_name = "verifiedLevels"]; -}