Source: golang-github-in-toto-go-witness Section: golang Maintainer: Debian Go Packaging Team Uploaders: Simon Josefsson , Build-Depends: debhelper-compat (= 13), dh-sequence-golang, golang-any, golang-github-cyclonedx-cyclonedx-go-dev, golang-github-digitorus-pkcs7-dev, golang-github-digitorus-timestamp-dev, golang-github-edwarnicke-gitoid-dev, golang-github-gabriel-vasile-mimetype-dev, golang-github-gitleaks-gitleaks-dev, golang-github-go-git-go-git-dev, golang-github-go-jose-go-jose-dev, golang-github-gobwas-glob-dev, golang-github-in-toto-attestation-dev, golang-github-invopop-jsonschema-dev, golang-github-jellydator-ttlcache-dev, golang-github-mattn-go-isatty-dev, golang-github-mitchellh-go-homedir-dev, golang-github-open-policy-agent-opa-dev, golang-github-openvex-go-vex-dev, golang-github-owenrumney-go-sarif-dev, golang-github-sigstore-cosign-dev, golang-github-sigstore-fulcio-dev, golang-github-sigstore-sigstore-dev, golang-github-smallstep-crypto-dev, golang-github-spdx-tools-golang-dev, golang-github-spiffe-go-spiffe-dev, golang-golang-x-sys-dev, golang-google-cloud-dev (>> 0.115.0~), golang-google-grpc-dev, golang-gopkg-square-go-jose.v2-dev (>> 2.6.3-4~), golang-k8s-sigs-structured-merge-diff-dev, Testsuite: autopkgtest-pkg-go Standards-Version: 4.7.3 Vcs-Browser: https://salsa.debian.org/go-team/packages/golang-github-in-toto-go-witness Vcs-Git: https://salsa.debian.org/go-team/packages/golang-github-in-toto-go-witness.git Homepage: https://github.com/in-toto/go-witness XS-Go-Import-Path: github.com/in-toto/go-witness Package: golang-github-in-toto-go-witness-dev Architecture: all Multi-Arch: foreign Depends: golang-github-cyclonedx-cyclonedx-go-dev, golang-github-digitorus-pkcs7-dev, golang-github-digitorus-timestamp-dev, golang-github-edwarnicke-gitoid-dev, golang-github-gabriel-vasile-mimetype-dev, golang-github-gitleaks-gitleaks-dev, golang-github-go-git-go-git-dev, golang-github-go-jose-go-jose-dev, golang-github-gobwas-glob-dev, golang-github-in-toto-attestation-dev, golang-github-invopop-jsonschema-dev, golang-github-jellydator-ttlcache-dev, golang-github-mattn-go-isatty-dev, golang-github-mitchellh-go-homedir-dev, golang-github-open-policy-agent-opa-dev, golang-github-openvex-go-vex-dev, golang-github-owenrumney-go-sarif-dev, golang-github-sigstore-cosign-dev, golang-github-sigstore-fulcio-dev, golang-github-sigstore-sigstore-dev, golang-github-smallstep-crypto-dev, golang-github-spdx-tools-golang-dev, golang-github-spiffe-go-spiffe-dev, golang-golang-x-sys-dev, golang-google-cloud-dev (>> 0.115.0~), golang-google-grpc-dev, golang-gopkg-square-go-jose.v2-dev (>> 2.6.3-4~), golang-k8s-sigs-structured-merge-diff-dev, ${misc:Depends}, Description: in-toto Go library for transparency log witness A client library for in-toto Witness written in Go. . Features: - Creation and signing of in-toto attestations - Verification of in-toto attestations and associated signatures with: - Witness policy engine - OPA Rego policy language - A growing list of attestor types defined under a common interface - A selection of attestation sources to search for attestation collections - Resilient Fulcio signer with automatic retry logic and improved error handling for GitHub Actions environments . For more detail regarding the library itself, see: https://pkg.go.dev/github.com/in-toto/go-witness . This package contains the Go development library.