Skip to content
ocx
install

PackageCommands (13 of 16)

PackageCommandsclassdataclass#

Re-exported from ocx_sdk._clientView source

attestmethod#

def attest(ref: PackageLike, *, predicate: str | Path, predicate_type: str, tags: Iterable[str] | None = None, tags_file: str | Path | None = None, platform: str | None = None, signature_format: SignatureFormat | None = None, key: str | None = None, rekor_upload: bool | None = None, fulcio_url: str | None = None, rekor_url: str | None = None, identity_token_file: str | Path | None = None, identity_token_stdin: bool = False, no_tty: bool = False, no_cache: bool = False, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> AttestationReport | SweepReport

Attach an in-toto attestation to a package reference (C-013).

Same three call shapes as sign (D2): tags/tags_file sweeps and returns a SweepReport; neither attests ref alone and returns an AttestationReport. mutating=True (D5), retries off by default (D6).

Carries the identical --key conflict set sign has — this is enumerated per command rather than delegated to a shared note, because it is attest’s own guard, declared independently in package_attest.rs alongside package_sign.rs’s: four flags refuse key outright (fulcio_url, identity_token_file, identity_token_stdin, no_tty); rekor_upload=False (--no-rekor-upload) requires key, the opposite direction; and independently of key, identity_token_file conflicts with identity_token_stdin.

Parameters

NameTypeDefaultDescription
refPackageLikerequiredThe package reference to attest.
predicatestr | PathrequiredThe predicate document to attest.
predicate_typestrrequiredThe predicate type URI or its short alias — ocx’s --type. The returned report’s predicate_type is the resolved URI, which may differ from what was passed here.
tagsIterable[str] | NoneNoneSweep these tags instead of attesting ref directly. Unions with tags_file when both are given — sweeping is triggered by either, not a choice between them. An empty sequence is refused: tags=None is how you act on ref itself.
tags_filestr | Path | NoneNoneSweep the tags listed in this file. Unions with tags — see above.
platformstr | NoneNoneAttest one platform’s manifest. Refused alongside tags or tags_file.
signature_formatSignatureFormat | NoneNoneWhich signature format(s) to produce.
keystr | NoneNoneA key reference. None signs keyless, against Fulcio. Conflicts with fulcio_url, identity_token_file, identity_token_stdin, and no_tty.
rekor_uploadbool | NoneNoneUpload to the transparency log. False (--no-rekor-upload) is valid only alongside key.
fulcio_urlstr | NoneNoneA non-default Fulcio instance. Conflicts with key.
rekor_urlstr | NoneNoneA non-default Rekor instance.
identity_token_filestr | Path | NoneNoneRead the OIDC identity token from this file. Conflicts with key and with identity_token_stdin.
identity_token_stdinboolFalseRead the OIDC identity token from stdin. Conflicts with key and with identity_token_file.
no_ttyboolFalseSuppress the interactive TTY prompt. Conflicts with key.
no_cacheboolFalseSkip ocx’s signing cache.
timeoutMaybeTimeoutUNSETSeconds per attempt. Omitted takes the config’s.
retryMaybeRetryUNSETRetry policy. Defaults to no retries.

Returns

AttestationReport | SweepReport
An AttestationReport for a single attestation, or a
AttestationReport | SweepReport
SweepReport when tags/tags_file swept multiple.

Raises

ValueError
tags was empty; platform was given alongside tags/tags_file; key was given alongside fulcio_url, identity_token_file, identity_token_stdin, or no_tty; identity_token_file and identity_token_stdin were both given; or rekor_upload=False was given without key.
OcxProcessError
A non-zero exit. Recover a partial report with partial_report(err) and AttestationReport.from_json (D10).