Mirrored from attesto-v1 ops/get-host/homebrew/ (commit f21339ce); hashes from the KMS-signed channel manifests on get.attesto.eu. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
69 lines
2.6 KiB
Ruby
69 lines
2.6 KiB
Ruby
# Attesto CLI — offline verifier for Attesto evidence.
|
|
#
|
|
# PROVENANCE OF THE sha256 VALUES: every hash below is copied verbatim from
|
|
# the SIGNED channel manifest https://get.attesto.eu/0.5.0/SHA256SUMS after
|
|
# verifying its cosign signature:
|
|
#
|
|
# curl -fsSLO https://get.attesto.eu/cosign.pub
|
|
# curl -fsSLO https://get.attesto.eu/0.5.0/SHA256SUMS
|
|
# curl -fsSLO https://get.attesto.eu/0.5.0/SHA256SUMS.sig
|
|
# cosign verify-blob --key cosign.pub --insecure-ignore-tlog \
|
|
# --signature SHA256SUMS.sig SHA256SUMS
|
|
#
|
|
# (--insecure-ignore-tlog: the release key is a KMS key and signatures are
|
|
# not uploaded to Rekor; this matches the project's documented verification
|
|
# flow.) Do not replace these hashes with locally computed ones.
|
|
class Attesto < Formula
|
|
desc "Offline verifier CLI for Attesto evidence (receipts, bundles, anchors)"
|
|
homepage "https://attesto.eu"
|
|
version "0.5.0"
|
|
license "Apache-2.0"
|
|
|
|
# KNOWN AUDIT WAIVER: `brew audit --strict` reports "Use `url :stable`" for
|
|
# the livecheck url below. That is a false positive in the
|
|
# FormulaAudit/LivecheckUrlSymbol cop: with every stable `url` inside
|
|
# on_macos/on_linux blocks, the cop takes the FIRST `url` call in the class
|
|
# body as the stable URL — which is this livecheck url itself, so it always
|
|
# self-matches, whatever string it holds. Following the suggestion would be
|
|
# wrong (livecheck would scan a binary download instead of the version
|
|
# feed), and moving `livecheck` after the on_* blocks trips ComponentsOrder
|
|
# instead. Canonical order is kept; the finding is waived.
|
|
livecheck do
|
|
url "https://get.attesto.eu/latest-version.txt"
|
|
regex(/^v?(\d+(?:\.\d+)+)$/i)
|
|
end
|
|
|
|
on_macos do
|
|
on_arm do
|
|
url "https://get.attesto.eu/0.5.0/attesto_0.5.0_darwin_arm64"
|
|
sha256 "8fd7a0044d5d042cd63f7972d80c78a099f5880050933a718bcdae9429e76815"
|
|
end
|
|
on_intel do
|
|
url "https://get.attesto.eu/0.5.0/attesto_0.5.0_darwin_amd64"
|
|
sha256 "ddc4d82ac9ecf8c85abee0f6300e305288d590f5b76723445ca76137a6d17dbf"
|
|
end
|
|
end
|
|
|
|
on_linux do
|
|
on_arm do
|
|
url "https://get.attesto.eu/0.5.0/attesto_0.5.0_linux_arm64"
|
|
sha256 "bce90fd4714e61fc2b95813b6935cceadf8b5346764c5ab4c3c968aab511d5c6"
|
|
end
|
|
on_intel do
|
|
url "https://get.attesto.eu/0.5.0/attesto_0.5.0_linux_amd64"
|
|
sha256 "65ec45c16096556eea86604ba61a15f5934874e5f92dc24de194657609e45bc8"
|
|
end
|
|
end
|
|
|
|
def install
|
|
os = OS.mac? ? "darwin" : "linux"
|
|
arch = Hardware::CPU.arm? ? "arm64" : "amd64"
|
|
bin.install "attesto_#{version}_#{os}_#{arch}" => "attesto"
|
|
chmod 0755, bin/"attesto"
|
|
end
|
|
|
|
test do
|
|
assert_match version.to_s, shell_output("#{bin}/attesto version")
|
|
end
|
|
end
|