Skip to content
ocx
install

SignatureReport (1 of 2)

SignatureReportclassdataclass#

Re-exported from ocx_sdk._resultsView source
class SignatureReport(identifier: str, subject_digest: str, legs: tuple[SignatureLegReport, ...], platform: str, signer: str, certificate_identity: str, certificate_oidc_issuer: str, key_backend: str, transparency_log_index: int | None, public_key_hint: str | None = None)

ocx package sign on a single reference — no tag sweep (C-011).

Payload is enveloped (D11): from_json unwraps data via _envelope before parsing. A --signature-format both run where one leg lands and one fails exits non-zero carrying a full report — recover it with partial_report(err) and this same from_json (D10); legs names which leg died through its error field.

Per D7’s field-order rule, public_key_hint moves to the end even though upstream orders it before transparency_log_index — transcribing that order verbatim would put a defaulted field before a required one.

Attributes

NameTypeDescription
identifierstrThe identifier that was signed.
subject_digeststrThe manifest digest the signature covers.
legstuple[SignatureLegReport, ...]One row per signature format requested.
platformstrThe signed platform.
signerstrThe signing mode label — never an identity and never a key reference. "keyless-fulcio" under keyless signing (signature.rs:159-162), else key_backend’s own backend label (awskms, file, …). Deliberately spelled differently from key_backend, which reads the plain "keyless" in that same case (signature.rs:155-157): upstream’s own comment notes that reusing "keyless" here too would leave no field that actually names the mechanism.
certificate_identitystrThe Fulcio certificate’s identity. Plain String upstream (signature.rs:59) — always emitted, on both the keyless and key-based paths.
certificate_oidc_issuerstrThe Fulcio certificate’s OIDC issuer. Always emitted (signature.rs:61), same as above.
key_backendstrWhich key backend produced the signature, carried as raw str (D8; irregular KMS spellings live here unmodified). Always emitted (signature.rs:68); under keyless signing the value is literally "keyless", not absent.
transparency_log_indexint | NoneThe Rekor entry index. Always present in the JSON, but None when nothing was logged.
public_key_hintstr | NoneA hint identifying the verifying key, when ocx supplied one.

certificate_identityattributeinstance attribute#

certificate_identity: str

certificate_oidc_issuerattributeinstance attribute#

certificate_oidc_issuer: str

identifierattributeinstance attribute#

identifier: str

key_backendattributeinstance attribute#

key_backend: str

legsattributeinstance attribute#

legs: tuple[SignatureLegReport, ...]

platformattributeinstance attribute#

platform: str