Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -14,5 +14,5 @@ fakes: ## Rebuild the implementation fakes
go generate ./...

.PHONY: proto
proto: ## Rebuild the policies and provenance predicate from protocol buffer definitions
proto: ## Rebuild the policy types from the protocol buffer definitions
buf generate
1 change: 1 addition & 0 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ require (
github.com/maxbrunsfeld/counterfeiter/v6 v6.13.0
github.com/migueleliasweb/go-github-mock v1.5.0
github.com/sigstore/sigstore-go v1.3.0
github.com/slsa-framework/protos v0.0.0-20260905230943-612c99695f3b
github.com/spf13/cobra v1.10.2
github.com/stretchr/testify v1.12.1
golang.org/x/mod v0.41.0
Expand Down
2 changes: 2 additions & 0 deletions go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -529,6 +529,8 @@ github.com/sirupsen/logrus v1.10.2 h1:G2SED73/qrAu6YwbdxOD6peLkCBI3z7L+ykJFTXJBB
github.com/sirupsen/logrus v1.10.2/go.mod h1:SLEg8TqYulVKKfIGHldVp2K2aYz2DKSVBq4g/H5bR7Q=
github.com/skeema/knownhosts v1.3.2 h1:EDL9mgf4NzwMXCTfaxSD/o/a5fxDw/xL9nkU28JjdBg=
github.com/skeema/knownhosts v1.3.2/go.mod h1:bEg3iQAuw+jyiw+484wwFJoKSLwcfd7fqRy+N0QTiow=
github.com/slsa-framework/protos v0.0.0-20260905230943-612c99695f3b h1:6IjAVZhOCYCgkcYc8gDYI8nr7pnHlQ8FaL1l7Y2OPfg=
github.com/slsa-framework/protos v0.0.0-20260905230943-612c99695f3b/go.mod h1:qIbxqThHVEmY1OTDwTg+iXPd/CU9AXyab7BBvk1V2gk=
github.com/spdx/tools-golang v0.5.7 h1:+sWcKGnhwp3vLdMqPcLdA6QK679vd86cK9hQWH3AwCg=
github.com/spdx/tools-golang v0.5.7/go.mod h1:jg7w0LOpoNAw6OxKEzCoqPC2GCTj45LyTlVmXubDsYw=
github.com/spf13/cobra v1.10.2 h1:DMTTonx5m65Ic0GOoRY2c16WCbHxOOw6xxezuLaBpcU=
Expand Down
24 changes: 23 additions & 1 deletion internal/cmd/audit.go
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ import (
"github.com/spf13/cobra"

"github.com/slsa-framework/source-tool/pkg/audit"
"github.com/slsa-framework/source-tool/pkg/provenance"
"github.com/slsa-framework/source-tool/pkg/sourcetool"
)

Expand Down Expand Up @@ -83,6 +84,27 @@ type AuditCommitResultJSON struct {
Error string `json:"error,omitempty"`
}

// ControlJSON is the JSON rendering of a provenance control. The predicate
// types are protobuf messages meant for protojson, so their timestamps are
// formatted here before the result goes through encoding/json.
type ControlJSON struct {
Name string `json:"name"`
Since string `json:"since"`
}

// provControlsToJSON converts provenance controls to their JSON rendering.
func provControlsToJSON(controls []*provenance.Control) []ControlJSON {
ret := make([]ControlJSON, 0, len(controls))
for _, c := range controls {
var since string
if c.GetSince() != nil {
since = c.GetSince().AsTime().Format("2006-01-02T15:04:05.000Z")
}
ret = append(ret, ControlJSON{Name: c.GetName(), Since: since})
}
return ret
}

// AuditResultJSON represents the full audit result in JSON format
type AuditResultJSON struct {
Owner string `json:"owner"`
Expand Down Expand Up @@ -314,7 +336,7 @@ func convertAuditResultToJSON(owner, repo string, ar *audit.AuditCommitResult, m
}

if ar.ProvPred != nil {
result.ProvControls = ar.ProvPred.GetControls()
result.ProvControls = provControlsToJSON(ar.ProvPred.GetControls())
result.PrevCommit = ar.ProvPred.GetPrevCommit()
result.PriorCommit = ar.PriorCommit
matches := ar.ProvPred.GetPrevCommit() == ar.PriorCommit
Expand Down
4 changes: 2 additions & 2 deletions internal/cmd/audit_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -186,7 +186,7 @@ func TestConvertAuditResultToJSON(t *testing.T) {
Status: "passed",
VerifiedLevels: []string{"SLSA_SOURCE_LEVEL_3"},
PrevCommitMatches: &matches,
ProvControls: []*provenance.Control{{Name: "test_control"}},
ProvControls: []ControlJSON{{Name: "test_control"}},
Controls: slsa.ControlSet{},
PrevCommit: "def456",
PriorCommit: "def456",
Expand Down Expand Up @@ -230,7 +230,7 @@ func TestConvertAuditResultToJSON(t *testing.T) {
Status: "failed",
VerifiedLevels: []string{"SLSA_SOURCE_LEVEL_3"},
PrevCommitMatches: &matches,
ProvControls: []*provenance.Control{{Name: "test_control"}},
ProvControls: []ControlJSON{{Name: "test_control"}},
PrevCommit: "wrong123",
PriorCommit: "def456",
Link: "https://github.com/test-owner/test-repo/commit/def456",
Expand Down
4 changes: 2 additions & 2 deletions pkg/attest/attester.go
Original file line number Diff line number Diff line change
Expand Up @@ -184,8 +184,8 @@ func (a *Attester) createCurrentProvenance(ctx context.Context, branch *models.B
// ... indeed, but don't set the `since`` date because doing so breaks
// checking against policies.
// See https://github.com/slsa-framework/source-tool/issues/272
if curProvPred.GetControl(slsa.SLSA_SOURCE_SCS_PROVENANCE.String()) == nil {
curProvPred.AddControl(
if provenance.GetControl(&curProvPred, slsa.SLSA_SOURCE_SCS_PROVENANCE.String()) == nil {
provenance.AddControl(&curProvPred,
&provenance.Control{
Name: slsa.SLSA_SOURCE_SCS_PROVENANCE.String(),
},
Expand Down
2 changes: 1 addition & 1 deletion pkg/attest/provenance.go
Original file line number Diff line number Diff line change
Expand Up @@ -329,7 +329,7 @@ func (a *Attester) CreateSourceProvenance(ctx context.Context, branch *models.Br
// There was prior provenance, so update the Since field for each property
// to the oldest encountered.
for i, curControl := range curProvPred.GetControls() {
prevControl := prevProvPred.GetControl(curControl.GetName())
prevControl := provenance.GetControl(prevProvPred, curControl.GetName())
// No prior version of this control
if prevControl == nil {
continue
Expand Down
62 changes: 22 additions & 40 deletions pkg/provenance/predicate.go
Original file line number Diff line number Diff line change
@@ -1,17 +1,35 @@
// SPDX-FileCopyrightText: Copyright 2025 The SLSA Authors
// SPDX-License-Identifier: Apache-2.0

// Package provenance exposes the SLSA source provenance predicate types.
//
// The message definitions live in the shared slsa-framework/protos module;
// this package aliases them so callers keep a descriptive import name and
// adds the predicate type URIs and a few helpers around the generated code.
package provenance

import "encoding/json"
import (
sourcetoolv1 "github.com/slsa-framework/protos/sourcetool/v1"
)

const (
SourceProvPredicateType = "https://github.com/slsa-framework/slsa-source-poc/source-provenance/v1-draft"
TagProvPredicateType = "https://github.com/slsa-framework/slsa-source-poc/tag-provenance/v1-draft"
)

type (
// SourceProvenancePred is the source provenance predicate.
SourceProvenancePred = sourcetoolv1.SourceProvenancePred
// Control records a control enforced on the source and since when.
Control = sourcetoolv1.Control
// TagProvenancePred is the tag provenance predicate.
TagProvenancePred = sourcetoolv1.TagProvenancePred
// VsaSummary summarizes a VSA referenced from tag provenance.
VsaSummary = sourcetoolv1.VsaSummary
)

// GetControl looks for a control by name in the predicate.
func (pred *SourceProvenancePred) GetControl(name string) *Control {
func GetControl(pred *SourceProvenancePred, name string) *Control {
for _, control := range pred.GetControls() {
if control.GetName() == name {
return control
Expand All @@ -20,48 +38,12 @@ func (pred *SourceProvenancePred) GetControl(name string) *Control {
return nil
}

// AddControl adds a new control to the predicate.
func (pred *SourceProvenancePred) AddControl(newControls ...*Control) {
// AddControl adds new controls to the predicate, skipping nil entries.
func AddControl(pred *SourceProvenancePred, newControls ...*Control) {
for _, c := range newControls {
if c == nil {
continue
}
pred.Controls = append(pred.Controls, c)
}
}

func (pred *SourceProvenancePred) MarshalJSON() ([]byte, error) {
type Alias SourceProvenancePred
var con string
if pred.GetCreatedOn() != nil {
con = pred.GetCreatedOn().AsTime().Format("2006-01-02T15:04:05.000Z")
}

return json.Marshal(
&struct {
CreatedOn string `json:"created_on"`
*Alias
}{
CreatedOn: con,
Alias: (*Alias)(pred),
},
)
}

func (ctl *Control) MarshalJSON() ([]byte, error) {
type Alias Control
var since string
if ctl.GetSince() != nil {
since = ctl.GetSince().AsTime().Format("2006-01-02T15:04:05.000Z")
}

return json.Marshal(
&struct {
CreatedOn string `json:"since"`
*Alias
}{
CreatedOn: since,
Alias: (*Alias)(ctl),
},
)
}
Loading
Loading