package ops import ( "github.com/versenilvis/iris/spec" ) func init() { spec.Register(&spec.Spec{ Name: "cosign", Description: "Provides utilities for attaching artifacts to other artifacts in a registry", Subcommands: []spec.Subcommand{ {Name: "attach", Description: "Provides utilities for attaching artifacts to other artifacts in a registry"}, {Name: "attestation", Description: "Attach attestation to the supplied container image"}, {Name: "sbom", Description: "Attach sbom to the supplied container image"}, {Name: "signature", Description: "Attach signatures to the supplied container image"}, {Name: "attest", Description: "Attest the supplied container image"}, {Name: "clean", Description: "Remove all signatures from an image"}, {Name: "completion", Description: "Generate completion script"}, {Name: "copy", Description: "Copy the supplied container image and signatures"}, {Name: "verify", Description: "Verify a signature on the base image specified in the Dockerfile"}, {Name: "generate", Description: "Generates (unsigned) signature payloads from the supplied container image"}, {Name: "generate-key-pair", Description: "Generates a key-pair"}, {Name: "import-key-pair", Description: "Imports a PEM-encoded RSA or EC private key"}, {Name: "load", Description: "Load a signed image on disk to a remote registry"}, {Name: "login", Description: "Log in to a registry"}, {Name: "piv-tool", Description: "This cosign was not built with piv-tool support!"}, {Name: "pkcs11-tool", Description: "This cosign was not built with pkcs11-tool support!"}, {Name: "policy", Description: "Subcommand to manage a keyless policy"}, {Name: "init", Description: "Generate a new keyless policy"}, {Name: "sign", Description: "Sign a keyless policy"}, {Name: "public-key", Description: "Gets a public key from the key-pair"}, {Name: "sign-blob", Description: "Sign the supplied blob, outputting the base64-encoded signature to stdout"}, {Name: "upload", Description: "Provides utilities for uploading artifacts to a registry"}, {Name: "blob", Description: "Upload one or more blobs to the supplied container image address"}, {Name: "wasm", Description: "Upload a wasm module to the supplied container image reference"}, {Name: "verify-attestation", Description: "Verify an attestation on the supplied container image"}, {Name: "verify-blob", Description: "Verify a signature on the supplied blob"}, {Name: "version", Description: "Prints the version"}, {Name: "help", Description: "Help about any command"}, }, Options: []spec.Option{ {Name: "--output-file", Description: "Log output to a file"}, {Name: "--timeout", Description: "Timeout for commands"}, {Name: "--verbose", Description: "Log debug output"}, {Name: "--allow-insecure-registry", Description: "Path to the attestation envelope"}, {Name: "--k8s-keychain", Description: "Help for attestation"}, {Name: "--type", Description: "Type of sbom (spdx|cyclonedx|syft)"}, {Name: "--help", Description: "Help for sbom"}, {Name: "--signature", Description: "The signature, path to the signature, or {-} for stdin"}, {Name: "--force", Description: "Skip warnings and confirmations"}, {Name: "--fulcio-url", Description: "[EXPERIMENTAL] address of sigstore PKI server"}, {Name: "--identity-token", Description: "[EXPERIMENTAL] identity token to use for certificate from fulcio"}, {Name: "--insecure-skip-verify", Description: "Path to the private key file, KMS URI or Kubernetes Secret"}, {Name: "--no-upload", Description: "Do not upload the generated attestation"}, {Name: "--oidc-client-id", Description: "[EXPERIMENTAL] OIDC client ID for application"}, {Name: "--oidc-client-secret", Description: "[EXPERIMENTAL] OIDC client secret for application"}, {Name: "--oidc-issuer", Description: "[EXPERIMENTAL] OIDC provider to be used to issue ID token"}, {Name: "--predicate", Description: "Path to the predicate file"}, {Name: "--recursive", Description: "If a multi-arch image is specified, additionally sign each discrete image"}, {Name: "--rekor-url", Description: "[EXPERIMENTAL] address of rekor STL server"}, {Name: "--replace", Description: "Whether to use a hardware security key"}, {Name: "--slot", Description: "Specify a predicate type (slsaprovenance|link|spdx|vuln|custom) or an URI"}, {Name: "--attachment", Description: "Related image attachment to sign (sbom), default none"}, {Name: "--attachment-tag-prefix", Description: "Only verify the base image (the last FROM image in the Dockerfile)"}, {Name: "--cert", Description: "Path to the public certificate"}, {Name: "--cert-email", Description: "The email expected in a valid Fulcio certificate"}, {Name: "--cert-oidc-issuer", Description: "Whether to check the claims found"}, {Name: "--local-image", Description: "Output format for the signing image information (json|text)"}, {Name: "--signature-digest-algorithm", Description: "Whether to use a hardware security key"}, {Name: "--kms", Description: "Create key pair in KMS service to use for signing"}, {Name: "--key", Description: "Import key pair to use for signing"}, {Name: "--mirror", Description: "GCS bucket to a SigStore TUF repository or HTTP(S) base URL"}, {Name: "--root", Description: "Path to trusted initial root. defaults to embedded root"}, {Name: "--dir", Description: "Path to directory where the signed image is stored on disk"}, {Name: "--password", Description: "Password"}, {Name: "--password-stdin", Description: "Take the password from stdin"}, {Name: "--username", Description: "Username"}, {Name: "--issuer", Description: "Trusted issuer to use for identity tokens, e.g. https://accounts.google.com"}, {Name: "--namespace", Description: "Registry namespace that the root policy belongs to"}, {Name: "--out", Description: "Output policy locally"}, {Name: "--threshold", Description: "Threshold for root policy signers"}, }, }) }