Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions app/cli/documentation/cli-reference.mdx
Original file line numberDiff line numberDiff line change
Expand Up@@ -268,7 +268,7 @@ Options
--append reserved for a future release: will control whether --policy-input and --policy-input-from-file append to (rather than replace) the contract-declared value; has no effect yet
--attestation-id string Unique identifier of the in-progress attestation
-h, --help help for add
--kind string kind of the material to be recorded: ["ARTIFACT" "ASYNCAPI_SPEC" "ATTESTATION" "BLACKDUCK_SCA_JSON" "CERTCC_DRANZER" "CHAINLOOP_AI_AGENT_CONFIG" "CHAINLOOP_AI_CODING_SESSION" "CHAINLOOP_PR_INFO" "CHAINLOOP_RUNNER_CONTEXT" "CHECKMARX_JSON" "COBERTURA_XML" "CONTAINER_IMAGE" "CSAF_INFORMATIONAL_ADVISORY" "CSAF_SECURITY_ADVISORY" "CSAF_SECURITY_INCIDENT_RESPONSE" "CSAF_VEX" "EVIDENCE" "GHAS_CODE_SCAN" "GHAS_DEPENDENCY_SCAN" "GHAS_SECRET_SCAN" "GITLAB_SECURITY_REPORT" "GITLEAKS_JSON" "GRAPHQL_SPEC" "HELM_CHART" "JACOCO_XML" "JUNIT_XML" "OPENAPI_SPEC" "OPENVEX" "OSSF_SCORECARD_JSON" "RADAMSA_CRASHES" "RADAMSA_REPORT" "SARIF" "SBOM_CYCLONEDX_JSON" "SBOM_SPDX_JSON" "SLSA_PROVENANCE" "STRING" "SYSINTERNALS_ACCESSCHK" "SYSINTERNALS_SIGCHECK" "TRUFFLEHOG_JSON" "TWISTCLI_SCAN_JSON" "YELP_DETECT_SECRETS_BASELINE" "ZAP_DAST_ZIP"]
--kind string kind of the material to be recorded: ["ARTIFACT" "ASYNCAPI_SPEC" "ATTESTATION" "BLACKDUCK_SCA_JSON" "CERTCC_DRANZER" "CHAINLOOP_AI_AGENT_CONFIG" "CHAINLOOP_AI_CODING_SESSION" "CHAINLOOP_PR_INFO" "CHAINLOOP_RUNNER_CONTEXT" "CHECKMARX_JSON" "COBERTURA_XML" "CONTAINER_IMAGE" "CSAF_INFORMATIONAL_ADVISORY" "CSAF_SECURITY_ADVISORY" "CSAF_SECURITY_INCIDENT_RESPONSE" "CSAF_VEX" "EVIDENCE" "GHAS_CODE_SCAN" "GHAS_DEPENDENCY_SCAN" "GHAS_SECRET_SCAN" "GITLAB_SECURITY_REPORT" "GITLEAKS_JSON" "GRAPHQL_SPEC" "HELM_CHART" "JACOCO_XML" "JUNIT_XML" "OPENAPI_SPEC" "OPENVEX" "OSSF_SCORECARD_JSON" "OVERSECURED_JSON" "RADAMSA_CRASHES" "RADAMSA_REPORT" "SARIF" "SBOM_CYCLONEDX_JSON" "SBOM_SPDX_JSON" "SLSA_PROVENANCE" "STRING" "SYSINTERNALS_ACCESSCHK" "SYSINTERNALS_SIGCHECK" "TRUFFLEHOG_JSON" "TWISTCLI_SCAN_JSON" "YELP_DETECT_SECRETS_BASELINE" "ZAP_DAST_ZIP"]
--max-extract-entries int max number of files to extract when --value is an archive (default 10000)
--max-extract-size string max total uncompressed size to extract when --value is an archive (default "1GiB")
--name string name of the material as shown in the contract
Expand DownExpand Up@@ -3045,7 +3045,7 @@ Options
--annotation strings Key-value pairs of material annotations (key=value)
-h, --help help for eval
--input stringArray Key-value pairs of policy inputs (key=value)
--kind string Kind of the material: ["ARTIFACT" "ASYNCAPI_SPEC" "ATTESTATION" "BLACKDUCK_SCA_JSON" "CERTCC_DRANZER" "CHAINLOOP_AI_AGENT_CONFIG" "CHAINLOOP_AI_CODING_SESSION" "CHAINLOOP_PR_INFO" "CHAINLOOP_RUNNER_CONTEXT" "CHECKMARX_JSON" "COBERTURA_XML" "CONTAINER_IMAGE" "CSAF_INFORMATIONAL_ADVISORY" "CSAF_SECURITY_ADVISORY" "CSAF_SECURITY_INCIDENT_RESPONSE" "CSAF_VEX" "EVIDENCE" "GHAS_CODE_SCAN" "GHAS_DEPENDENCY_SCAN" "GHAS_SECRET_SCAN" "GITLAB_SECURITY_REPORT" "GITLEAKS_JSON" "GRAPHQL_SPEC" "HELM_CHART" "JACOCO_XML" "JUNIT_XML" "OPENAPI_SPEC" "OPENVEX" "OSSF_SCORECARD_JSON" "RADAMSA_CRASHES" "RADAMSA_REPORT" "SARIF" "SBOM_CYCLONEDX_JSON" "SBOM_SPDX_JSON" "SLSA_PROVENANCE" "STRING" "SYSINTERNALS_ACCESSCHK" "SYSINTERNALS_SIGCHECK" "TRUFFLEHOG_JSON" "TWISTCLI_SCAN_JSON" "YELP_DETECT_SECRETS_BASELINE" "ZAP_DAST_ZIP"]
--kind string Kind of the material: ["ARTIFACT" "ASYNCAPI_SPEC" "ATTESTATION" "BLACKDUCK_SCA_JSON" "CERTCC_DRANZER" "CHAINLOOP_AI_AGENT_CONFIG" "CHAINLOOP_AI_CODING_SESSION" "CHAINLOOP_PR_INFO" "CHAINLOOP_RUNNER_CONTEXT" "CHECKMARX_JSON" "COBERTURA_XML" "CONTAINER_IMAGE" "CSAF_INFORMATIONAL_ADVISORY" "CSAF_SECURITY_ADVISORY" "CSAF_SECURITY_INCIDENT_RESPONSE" "CSAF_VEX" "EVIDENCE" "GHAS_CODE_SCAN" "GHAS_DEPENDENCY_SCAN" "GHAS_SECRET_SCAN" "GITLAB_SECURITY_REPORT" "GITLEAKS_JSON" "GRAPHQL_SPEC" "HELM_CHART" "JACOCO_XML" "JUNIT_XML" "OPENAPI_SPEC" "OPENVEX" "OSSF_SCORECARD_JSON" "OVERSECURED_JSON" "RADAMSA_CRASHES" "RADAMSA_REPORT" "SARIF" "SBOM_CYCLONEDX_JSON" "SBOM_SPDX_JSON" "SLSA_PROVENANCE" "STRING" "SYSINTERNALS_ACCESSCHK" "SYSINTERNALS_SIGCHECK" "TRUFFLEHOG_JSON" "TWISTCLI_SCAN_JSON" "YELP_DETECT_SECRETS_BASELINE" "ZAP_DAST_ZIP"]
--material string Path to material or attestation file
-p, --policy string Policy reference (./my-policy.yaml, https://my-domain.com/my-policy.yaml, chainloop://my-stored-policy) (default "policy.yaml")
--project string Project name to use as engine context for chainloop.* built-ins
Expand Down

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

14 changes: 10 additions & 4 deletions app/controlplane/api/workflowcontract/v1/crafting_schema.pb.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Original file line numberDiff line numberDiff line change
Expand Up@@ -199,6 +199,9 @@ message CraftingSchema {
// Checkmarx One native JSON report (ScanResultsCollection)
// https://github.com/Checkmarx/ast-cli/blob/main/internal/wrappers/results-json.go
CHECKMARX_JSON = 42;
// Oversecured mobile (Android/iOS) scan report, whole-scan JSON export
// https://docs.oversecured.com/docs/guide-exporting-reports
OVERSECURED_JSON = 43;
}
}
}
Expand Down
35 changes: 35 additions & 0 deletions app/controlplane/api/workflowcontract/v1/crafting_schema_test.go
Original file line numberDiff line numberDiff line change
Expand Up@@ -307,3 +307,38 @@ func TestValidateRefs(t *testing.T) {
})
}
}

// Kinds deliberately kept out of CraftingMaterialInValidationOrder, the list
// walked to guess a kind when `chainloop attestation add` is given no --kind.
// Each is excluded for a documented reason (see the NOTEs beside the list), so
// pin them here: adding one back would silently start probing every
// contract-free material against it.
func TestMaterialKindsExcludedFromAutoDetection(t *testing.T) {
testCases := []struct {
name string
kind v1.CraftingSchema_Material_MaterialType
}{
{
name: "checkmarx report is generic JSON",
kind: v1.CraftingSchema_Material_CHECKMARX_JSON,
},
{
name: "oversecured export envelope is not published by the vendor",
kind: v1.CraftingSchema_Material_OVERSECURED_JSON,
},
{
name: "radamsa report",
kind: v1.CraftingSchema_Material_RADAMSA_REPORT,
},
{
name: "radamsa crashes accept almost any non-empty file",
kind: v1.CraftingSchema_Material_RADAMSA_CRASHES,
},
}

for _, tc := range testCases {
t.Run(tc.name, func(t *testing.T) {
assert.NotContains(t, v1.CraftingMaterialInValidationOrder, tc.kind)
})
}
}
Original file line numberDiff line numberDiff line change
Expand Up@@ -30,6 +30,20 @@ import (
// CraftingMaterialInValidationOrder all type of CraftingMaterial that are available for automatic
// detection. The order of the list is important as it defines the order of the
// detection process. Normally from most common one to the least common one and weaker validation method.
//
// Kinds deliberately left out, each because auto-detecting it would misfire on
// other kinds' files. They all work when referenced with an explicit --kind or
// from a workflow contract:
// - RADAMSA_CRASHES: single-file mode accepts almost any non-empty file, so it
// would eagerly shadow every other type. RADAMSA_REPORT goes with it.
// - CHECKMARX_JSON: generic JSON that risks shadowing (or being shadowed by)
// other JSON kinds. Revisit once the fingerprint is proven strong.
// - OVERSECURED_JSON: a stronger fingerprint (a header carrying a scan id and
// an app platform), but the export envelope is not published by the vendor,
// so pinning it here would bet every other JSON kind on a shape inferred
// from a sample.
//
// TestMaterialKindsExcludedFromAutoDetection pins these exclusions.
var CraftingMaterialInValidationOrder = []CraftingSchema_Material_MaterialType{
CraftingSchema_Material_OPENVEX,
CraftingSchema_Material_SBOM_CYCLONEDX_JSON,
Expand All@@ -49,14 +63,6 @@ var CraftingMaterialInValidationOrder = []CraftingSchema_Material_MaterialType{
CraftingSchema_Material_JUNIT_XML,
CraftingSchema_Material_JACOCO_XML,
CraftingSchema_Material_COBERTURA_XML,
// NOTE: RADAMSA_REPORT and RADAMSA_CRASHES are intentionally omitted from
// auto-detection. RADAMSA_CRASHES single-file mode accepts almost any
// non-empty file and would eagerly shadow other types; both work fine when
// referenced with an explicit kind in a workflow contract.
// NOTE: CHECKMARX_JSON is intentionally omitted from auto-detection. The
// Checkmarx native report is generic JSON that risks shadowing (or being
// shadowed by) other JSON kinds; it must be referenced with an explicit
// --kind CHECKMARX_JSON. Revisit once the fingerprint is proven strong.
CraftingSchema_Material_HELM_CHART,
CraftingSchema_Material_SARIF,
CraftingSchema_Material_BLACKDUCK_SCA_JSON,
Expand Down
2 changes: 2 additions & 0 deletions pkg/attestation/crafter/materials/materials.go
Original file line numberDiff line numberDiff line change
Expand Up@@ -424,6 +424,8 @@ func Craft(ctx context.Context, materialSchema *schemaapi.CraftingSchema_Materia
crafter, err = NewTrufflehogCrafter(materialSchema, casBackend, logger)
case schemaapi.CraftingSchema_Material_CHECKMARX_JSON:
crafter, err = NewCheckmarxCrafter(materialSchema, casBackend, logger)
case schemaapi.CraftingSchema_Material_OVERSECURED_JSON:
crafter, err = NewOversecuredCrafter(materialSchema, casBackend, logger)
default:
return nil, fmt.Errorf("material of type %q not supported yet", materialSchema.Type)
}
Expand Down
Loading
Loading