{"_id":"@absolutejs/attest","_rev":"4-7525d22ac067ceb838da565269edb7b7","name":"@absolutejs/attest","dist-tags":{"latest":"0.1.3"},"versions":{"0.1.0":{"name":"@absolutejs/attest","version":"0.1.0","license":"MIT","_id":"@absolutejs/attest@0.1.0","maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"homepage":"https://github.com/absolutejs/attest","bugs":{"url":"https://github.com/absolutejs/attest/issues"},"bin":{"absolute-attest":"dist/cli.js"},"dist":{"shasum":"8c91e412a80e664c1ea5f57a44325c1ea6a0a716","tarball":"https://registry.npmjs.org/@absolutejs/attest/-/attest-0.1.0.tgz","fileCount":10,"integrity":"sha512-KTdDMmjfDYlouHQc/Ai/T+SuzrkQu4SgMX0MnngY8VH39nkr5+aV5vMpRyiM4UHDL5Yros70FkCzYXeak4Glsg==","signatures":[{"sig":"MEUCIHDtpQ7Nx9VLvDoXp6/br9jsA+8aGwKjbGTI5IQNUnVEAiEA8DJTqxweKpgAIhNcqqWhvnaSZd/FZk4pLYA1fHEoXgc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":33059},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","shasum":"8c91e412a80e664c1ea5f57a44325c1ea6a0a716","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./manifest":{"types":"./dist/manifest.d.ts","import":"./dist/manifest.js"},"./manifest.json":"./dist/manifest.json"},"scripts":{"lint":"eslint . --max-warnings 0","test":"bun test","build":"rm -rf dist && bun build src/index.ts src/cli.ts src/manifest.ts --outdir dist --target=bun --external @absolutejs/manifest --external @sinclair/typebox && tsc -p tsconfig.build.json && absolute-manifest emit","format":"prettier --write \"./**/*.{ts,json,md,mjs}\"","release":"bun run format && bun run check:package && bun publish","typecheck":"tsc --noEmit","verify-pack":"npm pack --dry-run","check:package":"bun run typecheck && bun run lint && bun run verify-package && bun run build && bun run verify-package --artifacts && bun run test && bun run verify-pack","verify-package":"absolute-manifest verify-package"},"_npmUser":{"name":"alexkahndev","email":"alexkahn2019@gmail.com"},"_integrity":"sha512-KTdDMmjfDYlouHQc/Ai/T+SuzrkQu4SgMX0MnngY8VH39nkr5+aV5vMpRyiM4UHDL5Yros70FkCzYXeak4Glsg==","absolutejs":{"manifestContract":2},"repository":{"url":"https://github.com/absolutejs/attest.git","type":"git"},"_npmVersion":"10.8.3","description":"Keyless Sigstore attestation policy, provenance, signing, and verification for private CI pipelines.","directories":{},"_nodeVersion":"24.3.0","dependencies":{"@sinclair/typebox":"^0.34.0","@absolutejs/manifest":"^0.8.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.7.0","globals":"^17.7.0","prettier":"^3.8.3","@eslint/js":"^10.0.1","@types/bun":"^1.3.14","typescript":"^5.9.0","typescript-eslint":"^8.63.0","eslint-plugin-promise":"^7.3.0","eslint-plugin-absolute":"^0.11.9","eslint-plugin-security":"^4.0.1","@stylistic/eslint-plugin":"^5.10.0","@typescript-eslint/parser":"^8.63.0"},"_npmOperationalInternal":{"tmp":"tmp/attest_0.1.0_1785461794770_0.895006102504295","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@absolutejs/attest","version":"0.1.1","license":"MIT","_id":"@absolutejs/attest@0.1.1","maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"homepage":"https://github.com/absolutejs/attest","bugs":{"url":"https://github.com/absolutejs/attest/issues"},"bin":{"absolute-attest":"dist/cli.js"},"dist":{"shasum":"3d8a85c1172befffd5b8e53f0e1f84d02f2ad82e","tarball":"https://registry.npmjs.org/@absolutejs/attest/-/attest-0.1.1.tgz","fileCount":10,"integrity":"sha512-6YNyv8NE15ikkLm9/Xp4Hybl5mwjeaIJ4CK3zAsklbgFV64qpf5YV4ETCd+NSf2kD7EvRoBNr1Kg9YfMWa259A==","signatures":[{"sig":"MEYCIQD0E9z8shG6JdfcJypLfimZMPqIUk6THOF9iw0g2rOtGgIhANVAKLSwEM0OK1KOKr0HrlUon7C7m2klXHOrOtcNb910","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":34913},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","shasum":"3d8a85c1172befffd5b8e53f0e1f84d02f2ad82e","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./manifest":{"types":"./dist/manifest.d.ts","import":"./dist/manifest.js"},"./manifest.json":"./dist/manifest.json"},"scripts":{"lint":"eslint . --max-warnings 0","test":"bun test","build":"rm -rf dist && bun build src/index.ts src/cli.ts src/manifest.ts --outdir dist --target=bun --external @absolutejs/manifest --external @sinclair/typebox && tsc -p tsconfig.build.json && absolute-manifest emit","format":"prettier --write \"./**/*.{ts,json,md,mjs}\"","release":"bun run format && bun run check:package && bun publish","typecheck":"tsc --noEmit","verify-pack":"npm pack --dry-run","check:package":"bun run typecheck && bun run lint && bun run verify-package && bun run build && bun run verify-package --artifacts && bun run test && bun run verify-pack","verify-package":"absolute-manifest verify-package"},"_npmUser":{"name":"alexkahndev","email":"alexkahn2019@gmail.com"},"_integrity":"sha512-6YNyv8NE15ikkLm9/Xp4Hybl5mwjeaIJ4CK3zAsklbgFV64qpf5YV4ETCd+NSf2kD7EvRoBNr1Kg9YfMWa259A==","absolutejs":{"manifestContract":2},"repository":{"url":"https://github.com/absolutejs/attest.git","type":"git"},"_npmVersion":"10.8.3","description":"Keyless Sigstore attestation policy, provenance, signing, and verification for private CI pipelines.","directories":{},"_nodeVersion":"24.3.0","dependencies":{"@sinclair/typebox":"^0.34.0","@absolutejs/manifest":"^0.8.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.7.0","globals":"^17.7.0","prettier":"^3.8.3","@eslint/js":"^10.0.1","@types/bun":"^1.3.14","typescript":"^5.9.0","typescript-eslint":"^8.63.0","eslint-plugin-promise":"^7.3.0","eslint-plugin-absolute":"^0.11.9","eslint-plugin-security":"^4.0.1","@stylistic/eslint-plugin":"^5.10.0","@typescript-eslint/parser":"^8.63.0"},"_npmOperationalInternal":{"tmp":"tmp/attest_0.1.1_1785462418079_0.299487314902281","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@absolutejs/attest","version":"0.1.2","license":"MIT","_id":"@absolutejs/attest@0.1.2","maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"homepage":"https://github.com/absolutejs/attest","bugs":{"url":"https://github.com/absolutejs/attest/issues"},"bin":{"absolute-attest":"dist/cli.js"},"dist":{"shasum":"fb48cd1c1b5fbb4840ef591b3152a04bf1a5200a","tarball":"https://registry.npmjs.org/@absolutejs/attest/-/attest-0.1.2.tgz","fileCount":10,"integrity":"sha512-3daMVyt4F8XKqBMOEwxZcEzPEecrf4dh2CWADOoBxdqWrKWcxo6O3SCZD9j08eLL/g5Hynx+Vcx3e6HR4ObumA==","signatures":[{"sig":"MEYCIQDdhtNGeYgVwtNBNnbFOX1kMVP52s6dO3akVy3zrAJCxwIhAOMJTByny91vOSEHRNcSZCRfpVPEgaIeVBiBDBmUNMf0","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":34913},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","shasum":"fb48cd1c1b5fbb4840ef591b3152a04bf1a5200a","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./manifest":{"types":"./dist/manifest.d.ts","import":"./dist/manifest.js"},"./manifest.json":"./dist/manifest.json"},"scripts":{"lint":"eslint . --max-warnings 0","test":"bun test","build":"rm -rf dist && bun build src/index.ts src/cli.ts src/manifest.ts --outdir dist --target=bun --external @absolutejs/manifest --external @sinclair/typebox && tsc -p tsconfig.build.json && absolute-manifest emit","format":"prettier --write \"./**/*.{ts,json,md,mjs}\"","release":"bun run format && bun run check:package && bun publish","typecheck":"tsc --noEmit","verify-pack":"npm pack --dry-run","check:package":"bun run typecheck && bun run lint && bun run verify-package && bun run build && bun run verify-package --artifacts && bun run test && bun run verify-pack","verify-package":"absolute-manifest verify-package"},"_npmUser":{"name":"alexkahndev","email":"alexkahn2019@gmail.com"},"_integrity":"sha512-3daMVyt4F8XKqBMOEwxZcEzPEecrf4dh2CWADOoBxdqWrKWcxo6O3SCZD9j08eLL/g5Hynx+Vcx3e6HR4ObumA==","absolutejs":{"manifestContract":2},"repository":{"url":"https://github.com/absolutejs/attest.git","type":"git"},"_npmVersion":"10.8.3","description":"Keyless Sigstore attestation policy, provenance, signing, and verification for private CI pipelines.","directories":{},"_nodeVersion":"24.3.0","dependencies":{"@sinclair/typebox":"^0.34.0","@absolutejs/manifest":"^0.8.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.7.0","globals":"^17.7.0","prettier":"^3.8.3","@eslint/js":"^10.0.1","@types/bun":"^1.3.14","typescript":"^5.9.0","typescript-eslint":"^8.63.0","eslint-plugin-promise":"^7.3.0","eslint-plugin-absolute":"^0.11.9","eslint-plugin-security":"^4.0.1","@stylistic/eslint-plugin":"^5.10.0","@typescript-eslint/parser":"^8.63.0"},"_npmOperationalInternal":{"tmp":"tmp/attest_0.1.2_1785462832984_0.44205909474645555","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@absolutejs/attest","version":"0.1.3","description":"Keyless Sigstore attestation policy, provenance, signing, and verification for private CI pipelines.","type":"module","license":"MIT","repository":{"type":"git","url":"https://github.com/absolutejs/attest.git"},"homepage":"https://github.com/absolutejs/attest","bugs":{"url":"https://github.com/absolutejs/attest/issues"},"publishConfig":{"access":"public"},"main":"./dist/index.js","types":"./dist/index.d.ts","bin":{"absolute-attest":"dist/cli.js"},"absolutejs":{"manifestContract":2},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./manifest":{"types":"./dist/manifest.d.ts","import":"./dist/manifest.js"},"./manifest.json":"./dist/manifest.json"},"scripts":{"format":"prettier --write \"./**/*.{ts,json,md,mjs}\"","typecheck":"tsc --noEmit","lint":"eslint . --max-warnings 0","test":"bun test","build":"rm -rf dist && bun build src/index.ts src/cli.ts src/manifest.ts --outdir dist --target=bun --external @absolutejs/manifest --external @sinclair/typebox && tsc -p tsconfig.build.json && absolute-manifest emit","verify-package":"absolute-manifest verify-package","verify-pack":"npm pack --dry-run","check:package":"bun run typecheck && bun run lint && bun run verify-package && bun run build && bun run verify-package --artifacts && bun run test && bun run verify-pack","release":"bun run format && bun run check:package && bun publish"},"dependencies":{"@absolutejs/manifest":"^0.8.0","@sinclair/typebox":"^0.34.0"},"devDependencies":{"@eslint/js":"^10.0.1","@stylistic/eslint-plugin":"^5.10.0","@types/bun":"^1.3.14","@typescript-eslint/parser":"^8.63.0","eslint":"^10.7.0","eslint-plugin-absolute":"^0.11.9","eslint-plugin-promise":"^7.3.0","eslint-plugin-security":"^4.0.1","globals":"^17.7.0","prettier":"^3.8.3","typescript":"^5.9.0","typescript-eslint":"^8.63.0"},"_id":"@absolutejs/attest@0.1.3","_integrity":"sha512-1UKr30s2IkUKSmTEwAle3O2/RLJ71h8n84cXtMjXLKE/NlWKECRjJTWcofnWx+8mQZXPEFeRjZFf/PO9HBDnCw==","_nodeVersion":"24.3.0","_npmVersion":"10.8.3","shasum":"dffb394f258fa9c2d285372903f52473c1fe1e4a","dist":{"integrity":"sha512-1UKr30s2IkUKSmTEwAle3O2/RLJ71h8n84cXtMjXLKE/NlWKECRjJTWcofnWx+8mQZXPEFeRjZFf/PO9HBDnCw==","shasum":"dffb394f258fa9c2d285372903f52473c1fe1e4a","tarball":"https://registry.npmjs.org/@absolutejs/attest/-/attest-0.1.3.tgz","fileCount":10,"unpackedSize":34633,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIAcSrhJhN3tApqlVnFqM3s3UAhSpX+GQiyHQxfocpZpYAiBigKiTK1H5NqME5YAsiLs3lvraCirPHhy4CSbVi2mqTw=="}]},"_npmUser":{"name":"alexkahndev","email":"alexkahn2019@gmail.com"},"directories":{},"maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/attest_0.1.3_1785462975028_0.6412355141531494"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-31T01:36:34.582Z","modified":"2026-07-31T01:56:15.350Z","0.1.0":"2026-07-31T01:36:34.919Z","0.1.1":"2026-07-31T01:46:58.246Z","0.1.2":"2026-07-31T01:53:53.121Z","0.1.3":"2026-07-31T01:56:15.177Z"},"bugs":{"url":"https://github.com/absolutejs/attest/issues"},"license":"MIT","homepage":"https://github.com/absolutejs/attest","repository":{"type":"git","url":"https://github.com/absolutejs/attest.git"},"description":"Keyless Sigstore attestation policy, provenance, signing, and verification for private CI pipelines.","maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"readme":"# @absolutejs/attest\n\nKeyless software-supply-chain attestation for private CI pipelines.\n\n`@absolutejs/attest` binds an immutable container digest or release file to an\nexact GitHub Actions repository, workflow, ref, and commit. It creates SLSA v1\nprovenance predicates, builds fail-closed Cosign command plans, stores image\nprovenance and SPDX SBOM attestations beside the image in its OCI registry, and\ncreates portable Sigstore bundles for ordinary release files.\n\nThe package does not implement cryptography, operate a certificate authority,\nor replace Sigstore. The official Cosign client performs signing and\nverification against Fulcio, Rekor, and the Sigstore trust root. This package\nowns the reusable policy that tells Cosign exactly which workflow identity and\nartifact digest are acceptable.\n\n## Why this is not part of `@absolutejs/deploy`\n\nAttestation happens before deployment and remains useful without a deployer.\nBuild systems produce evidence, registries retain it, admission controls verify\nit, and offline release reviewers inspect it. `@absolutejs/deploy` may require\nvalid evidence before activation, but it should not own the trust model.\n\n## GitHub Actions identity\n\n```ts\nimport {\n  createImagePublicationCommands,\n  githubWorkflowIdentityFromEnvironment,\n} from \"@absolutejs/attest\";\n\nconst identity = githubWorkflowIdentityFromEnvironment(process.env);\nconst commands = createImagePublicationCommands({\n  identity,\n  imageReference:\n    \"ghcr.io/acme/api@sha256:0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef\",\n  provenancePath: \"evidence/provenance.json\",\n  sbomPath: \"evidence/sbom.spdx.json\",\n});\n```\n\nEvery verification command requires:\n\n- the exact Fulcio OIDC issuer;\n- the exact GitHub repository;\n- the exact workflow file;\n- the exact branch or tag ref;\n- the exact source commit;\n- a digest-pinned OCI image reference.\n\nTags such as `latest`, abbreviated commits, unqualified workflow names, and\nnon-GitHub invocation URLs are rejected.\n\n## CLI\n\nThe package exports `absolute-attest` for CI jobs:\n\n```sh\nabsolute-attest provenance evidence/provenance.json\nabsolute-attest publish-image \\\n  \"$IMAGE_NAME@$IMAGE_DIGEST\" \\\n  evidence/provenance.json \\\n  evidence/sbom.spdx.json \\\n  evidence/attestations.json\nabsolute-attest sign-blobs \\\n  release/release.json \\\n  release/images.env \\\n  release/sha256sums.txt\nabsolute-attest verify-blobs \\\n  release/release.json \\\n  release/images.env \\\n  release/sha256sums.txt\nabsolute-attest verify-image \\\n  \"$IMAGE_NAME@$IMAGE_DIGEST\"\n```\n\nThe CLI reads GitHub's standard `GITHUB_REPOSITORY`, `GITHUB_WORKFLOW_REF`,\n`GITHUB_REF`, `GITHUB_SHA`, `GITHUB_SERVER_URL`, and `GITHUB_RUN_ID`\nvariables. None are credentials. Cosign obtains the job's short-lived OIDC\nidentity directly from GitHub Actions.\n\n## Security properties\n\n- No long-lived signing key.\n- No custom cryptography.\n- Immediate verification after every signing or attestation operation.\n- Exact certificate identity and GitHub workflow claims.\n- SHA-256 digest-pinned images only.\n- SLSA v1 provenance bound to the source commit and workflow invocation.\n- SPDX JSON SBOM attestations stored with the OCI image.\n- Portable Sigstore bundles for non-container release files.\n- Sequential execution that stops at the first violated boundary.\n\nMIT licensed.\n","readmeFilename":"README.md"}