Search by

thephpf / attestation

asgrimpronskiy

A PHP library to aid in verifying artifact attestations

Package info

github.com/ThePHPF/attestation

pkg:composer/thephpf/attestation

Fund package maintenance!

ThePHPF

Open Collective

Statistics

Installs: 32 893

Dependents: 0

Suggesters: 0

Stars: 7

Open Issues: 5

0.0.8 2026-09-13 19:02 UTC

This package is auto-updated.

Last update: 2026-09-13 19:27:17 UTC


README

A PHP library to aid in verifying artifact attestations. This tool will carry out some basic verifications that the given file is genuine. At this time, the library does not support signing artifacts.

Library usage

Fetching a bundle from GitHub's Artifact Attestations API and verifying it:

<?php

use ThePhpFoundation\Attestation\AttestationException;
use ThePhpFoundation\Attestation\BundleSource\DownloadGitHubBundle;
use ThePhpFoundation\Attestation\FilenameWithChecksum;
use ThePhpFoundation\Attestation\FulcioSigstoreOidExtensions;
use ThePhpFoundation\Attestation\Verification\VerifyBundleWithOpenSsl;

try {
    $file = FilenameWithChecksum::fromFilename($fileYouWantToVerify);

    $bundles = DownloadGitHubBundle::factory('your-org') // the org/user in your GH URL, e.g. https://github.com/your-org
        ->getBundles($file);

    VerifyBundleWithOpenSsl::factory(
        [
            FulcioSigstoreOidExtensions::SOURCE_REPOSITORY_URI => 'https://github.com/your-org/your-repo',
            FulcioSigstoreOidExtensions::SOURCE_REPOSITORY_OWNER_URI => 'https://github.com/your-org',
        ],
        // the workflow that's expected to have produced the signing certificate
        'https://github.com/your-org/your-repo/.github/workflows/build.yml@refs/heads/main',
        // the expected issuer of the signing certificate
        'https://token.actions.githubusercontent.com',
    )
        ->verify($bundles, $file);
} catch (AttestationException $issue) {
    // Handle a failure to fetch or verify the attestation in the way you see fit...
}

CLI usage

A verify-bundle command is provided, implementing a subset of the Sigstore conformance CLI protocol, to verify a local Sigstore bundle file against a local artifact:

php bin/cli.php verify-bundle \
  --bundle=path/to/bundle.json \
  --certificate-identity=https://github.com/your-org/your-repo/.github/workflows/build.yml@refs/heads/main \
  --certificate-oidc-issuer=https://token.actions.githubusercontent.com \
  path/to/artifact

Pass --trusted-root=path/to/trusted-root.jsonl to verify against a custom trusted root instead of the one bundled with this library.