- integrations
- Python
- ocx_sdk
PackageCommands (13 of 16)
PackageCommandsclassdataclass#
ocx_sdk._clientView sourceattestmethod#
def attest(ref: PackageLike, *, predicate: str | Path, predicate_type: str, tags: Iterable[str] | None = None, tags_file: str | Path | None = None, platform: str | None = None, signature_format: SignatureFormat | None = None, key: str | None = None, rekor_upload: bool | None = None, fulcio_url: str | None = None, rekor_url: str | None = None, identity_token_file: str | Path | None = None, identity_token_stdin: bool = False, no_tty: bool = False, no_cache: bool = False, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> AttestationReport | SweepReportAttach an in-toto attestation to a package reference (C-013).
Same three call shapes as sign (D2): tags/tags_file sweeps and
returns a SweepReport; neither attests ref alone and returns an
AttestationReport. mutating=True (D5), retries off by default
(D6).
Carries the identical --key conflict set sign has — this is
enumerated per command rather than delegated to a shared note,
because it is attest’s own guard, declared independently in
package_attest.rs alongside package_sign.rs’s: four flags
refuse key outright (fulcio_url, identity_token_file,
identity_token_stdin, no_tty); rekor_upload=False
(--no-rekor-upload) requires key, the opposite direction; and
independently of key, identity_token_file conflicts with
identity_token_stdin.
Parameters
| Name | Type | Default | Description |
|---|---|---|---|
ref | PackageLike | required | The package reference to attest. |
predicate | str | Path | required | The predicate document to attest. |
predicate_type | str | required | The predicate type URI or its short alias —
ocx’s --type. The returned report’s predicate_type is
the resolved URI, which may differ from what was passed
here. |
tags | Iterable[str] | None | None | Sweep these tags instead of attesting ref directly.
Unions with tags_file when both are given — sweeping is
triggered by either, not a choice between them.
An empty sequence is refused: tags=None is how you act
on ref itself. |
tags_file | str | Path | None | None | Sweep the tags listed in this file. Unions with
tags — see above. |
platform | str | None | None | Attest one platform’s manifest. Refused alongside
tags or tags_file. |
signature_format | SignatureFormat | None | None | Which signature format(s) to produce. |
key | str | None | None | A key reference. None signs keyless, against Fulcio.
Conflicts with fulcio_url, identity_token_file,
identity_token_stdin, and no_tty. |
rekor_upload | bool | None | None | Upload to the transparency log. False
(--no-rekor-upload) is valid only alongside key. |
fulcio_url | str | None | None | A non-default Fulcio instance. Conflicts with key. |
rekor_url | str | None | None | A non-default Rekor instance. |
identity_token_file | str | Path | None | None | Read the OIDC identity token from this
file. Conflicts with key and with identity_token_stdin. |
identity_token_stdin | bool | False | Read the OIDC identity token from stdin.
Conflicts with key and with identity_token_file. |
no_tty | bool | False | Suppress the interactive TTY prompt. Conflicts with
key. |
no_cache | bool | False | Skip ocx’s signing cache. |
timeout | MaybeTimeout | UNSET | Seconds per attempt. Omitted takes the config’s. |
retry | MaybeRetry | UNSET | Retry policy. Defaults to no retries. |
Returns
AttestationReport | SweepReport- An
AttestationReportfor a single attestation, or a AttestationReport | SweepReportSweepReportwhentags/tags_fileswept multiple.
Raises
ValueErrortagswas empty;platformwas given alongsidetags/tags_file;keywas given alongsidefulcio_url,identity_token_file,identity_token_stdin, orno_tty;identity_token_fileandidentity_token_stdinwere both given; orrekor_upload=Falsewas given withoutkey.OcxProcessError- A non-zero exit. Recover a partial report with
partial_report(err)andAttestationReport.from_json(D10).