- integrations
- Python
- ocx_sdk
SignatureReport (1 of 2)
SignatureReportclassdataclass#
Re-exported from
ocx_sdk._resultsView sourceclass SignatureReport(identifier: str, subject_digest: str, legs: tuple[SignatureLegReport, ...], platform: str, signer: str, certificate_identity: str, certificate_oidc_issuer: str, key_backend: str, transparency_log_index: int | None, public_key_hint: str | None = None)ocx package sign on a single reference — no tag sweep (C-011).
Payload is enveloped (D11): from_json unwraps data via
_envelope before parsing. A --signature-format both run where one leg
lands and one fails exits non-zero carrying a full report — recover it
with partial_report(err) and this same from_json (D10); legs names
which leg died through its error field.
Per D7’s field-order rule, public_key_hint moves to the end even
though upstream orders it before transparency_log_index — transcribing
that order verbatim would put a defaulted field before a required one.
Attributes
| Name | Type | Description |
|---|---|---|
identifier | str | The identifier that was signed. |
subject_digest | str | The manifest digest the signature covers. |
legs | tuple[SignatureLegReport, ...] | One row per signature format requested. |
platform | str | The signed platform. |
signer | str | The signing mode label — never an identity and never a key
reference. "keyless-fulcio" under keyless signing
(signature.rs:159-162), else key_backend’s own backend
label (awskms, file, …). Deliberately spelled differently
from key_backend, which reads the plain "keyless" in that
same case (signature.rs:155-157): upstream’s own comment
notes that reusing "keyless" here too would leave no field
that actually names the mechanism. |
certificate_identity | str | The Fulcio certificate’s identity. Plain
String upstream (signature.rs:59) — always emitted, on both
the keyless and key-based paths. |
certificate_oidc_issuer | str | The Fulcio certificate’s OIDC issuer.
Always emitted (signature.rs:61), same as above. |
key_backend | str | Which key backend produced the signature, carried as
raw str (D8; irregular KMS spellings live here unmodified).
Always emitted (signature.rs:68); under keyless signing the
value is literally "keyless", not absent. |
transparency_log_index | int | None | The Rekor entry index. Always present in the
JSON, but None when nothing was logged. |
public_key_hint | str | None | A hint identifying the verifying key, when ocx supplied one. |
certificate_identityattributeinstance attribute#
certificate_identity: strcertificate_oidc_issuerattributeinstance attribute#
certificate_oidc_issuer: stridentifierattributeinstance attribute#
identifier: strkey_backendattributeinstance attribute#
key_backend: strlegsattributeinstance attribute#
legs: tuple[SignatureLegReport, ...]platformattributeinstance attribute#
platform: str