Build Signature Response
Message encapsulating the signature of the verified build.
Constructors
Types
Properties
Public key of the builder which can be used to verify that the related findings are valid and unchanged. If key_type
is empty, this defaults to PEM encoded public keys. This field may be empty if key_id
references an external key. For Cloud Build based signatures, this is a PEM encoded public key. To verify the Cloud Build signature, place the contents of this field into a file (public.pem). The signature field is base64-decoded into its binary representation in signature.bin, and the provenance bytes from BuildDetails
are base64-decoded into a binary representation in signed.bin. OpenSSL can then verify the signature: openssl sha256 -verify public.pem -signature signature.bin signed.bin