Team Ai
Datasetpublic

codekingpro/portable-devtools

sourceHugging Faceupdated 5mo agoView on Hugging Face
1likes14kdownloads
build.js101 linesDownload Raw Back to dist
1"use strict";
2Object.defineProperty(exports, "__esModule", { value: true });
3exports.toMessageSignatureBundle = toMessageSignatureBundle;
4exports.toDSSEBundle = toDSSEBundle;
5/*
6Copyright 2023 The Sigstore Authors.
7
8Licensed under the Apache License, Version 2.0 (the "License");
9you may not use this file except in compliance with the License.
10You may obtain a copy of the License at
11
12    http://www.apache.org/licenses/LICENSE-2.0
13
14Unless required by applicable law or agreed to in writing, software
15distributed under the License is distributed on an "AS IS" BASIS,
16WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
17See the License for the specific language governing permissions and
18limitations under the License.
19*/
20const protobuf_specs_1 = require("@sigstore/protobuf-specs");
21const bundle_1 = require("./bundle");
22// Message signature bundle - $case: 'messageSignature'
23function toMessageSignatureBundle(options) {
24    return {
25        mediaType: options.certificateChain
26            ? bundle_1.BUNDLE_V02_MEDIA_TYPE
27            : bundle_1.BUNDLE_V03_MEDIA_TYPE,
28        content: {
29            $case: 'messageSignature',
30            messageSignature: {
31                messageDigest: {
32                    algorithm: protobuf_specs_1.HashAlgorithm.SHA2_256,
33                    digest: options.digest,
34                },
35                signature: options.signature,
36            },
37        },
38        verificationMaterial: toVerificationMaterial(options),
39    };
40}
41// DSSE envelope bundle - $case: 'dsseEnvelope'
42function toDSSEBundle(options) {
43    return {
44        mediaType: options.certificateChain
45            ? bundle_1.BUNDLE_V02_MEDIA_TYPE
46            : bundle_1.BUNDLE_V03_MEDIA_TYPE,
47        content: {
48            $case: 'dsseEnvelope',
49            dsseEnvelope: toEnvelope(options),
50        },
51        verificationMaterial: toVerificationMaterial(options),
52    };
53}
54function toEnvelope(options) {
55    return {
56        payloadType: options.artifactType,
57        payload: options.artifact,
58        signatures: [toSignature(options)],
59    };
60}
61function toSignature(options) {
62    return {
63        keyid: options.keyHint || '',
64        sig: options.signature,
65    };
66}
67// Verification material
68function toVerificationMaterial(options) {
69    return {
70        content: toKeyContent(options),
71        tlogEntries: [],
72        timestampVerificationData: { rfc3161Timestamps: [] },
73    };
74}
75function toKeyContent(options) {
76    if (options.certificate) {
77        if (options.certificateChain) {
78            return {
79                $case: 'x509CertificateChain',
80                x509CertificateChain: {
81                    certificates: [{ rawBytes: options.certificate }],
82                },
83            };
84        }
85        else {
86            return {
87                $case: 'certificate',
88                certificate: { rawBytes: options.certificate },
89            };
90        }
91    }
92    else {
93        return {
94            $case: 'publicKey',
95            publicKey: {
96                hint: options.keyHint || '',
97            },
98        };
99    }
100}
101 
codekingpro/portable-devtools · Team Ai