# Attesto CLI — offline verifier for Attesto evidence. # # PROVENANCE OF THE sha256 VALUES: every hash below is copied verbatim from # the SIGNED channel manifest https://get.attesto.eu/0.5.0/SHA256SUMS after # verifying its cosign signature: # # curl -fsSLO https://get.attesto.eu/cosign.pub # curl -fsSLO https://get.attesto.eu/0.5.0/SHA256SUMS # curl -fsSLO https://get.attesto.eu/0.5.0/SHA256SUMS.sig # cosign verify-blob --key cosign.pub --insecure-ignore-tlog \ # --signature SHA256SUMS.sig SHA256SUMS # # (--insecure-ignore-tlog: the release key is a KMS key and signatures are # not uploaded to Rekor; this matches the project's documented verification # flow.) Do not replace these hashes with locally computed ones. class Attesto < Formula desc "Offline verifier CLI for Attesto evidence (receipts, bundles, anchors)" homepage "https://attesto.eu" version "0.5.0" license "Apache-2.0" # KNOWN AUDIT WAIVER: `brew audit --strict` reports "Use `url :stable`" for # the livecheck url below. That is a false positive in the # FormulaAudit/LivecheckUrlSymbol cop: with every stable `url` inside # on_macos/on_linux blocks, the cop takes the FIRST `url` call in the class # body as the stable URL — which is this livecheck url itself, so it always # self-matches, whatever string it holds. Following the suggestion would be # wrong (livecheck would scan a binary download instead of the version # feed), and moving `livecheck` after the on_* blocks trips ComponentsOrder # instead. Canonical order is kept; the finding is waived. livecheck do url "https://get.attesto.eu/latest-version.txt" regex(/^v?(\d+(?:\.\d+)+)$/i) end on_macos do on_arm do url "https://get.attesto.eu/0.5.0/attesto_0.5.0_darwin_arm64" sha256 "8fd7a0044d5d042cd63f7972d80c78a099f5880050933a718bcdae9429e76815" end on_intel do url "https://get.attesto.eu/0.5.0/attesto_0.5.0_darwin_amd64" sha256 "ddc4d82ac9ecf8c85abee0f6300e305288d590f5b76723445ca76137a6d17dbf" end end on_linux do on_arm do url "https://get.attesto.eu/0.5.0/attesto_0.5.0_linux_arm64" sha256 "bce90fd4714e61fc2b95813b6935cceadf8b5346764c5ab4c3c968aab511d5c6" end on_intel do url "https://get.attesto.eu/0.5.0/attesto_0.5.0_linux_amd64" sha256 "65ec45c16096556eea86604ba61a15f5934874e5f92dc24de194657609e45bc8" end end def install os = OS.mac? ? "darwin" : "linux" arch = Hardware::CPU.arm? ? "arm64" : "amd64" bin.install "attesto_#{version}_#{os}_#{arch}" => "attesto" chmod 0755, bin/"attesto" end test do assert_match version.to_s, shell_output("#{bin}/attesto version") end end