Download the PHP package k2gl/sigstore-bundle without Composer
On this page you can find all versions of the php package k2gl/sigstore-bundle. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download k2gl/sigstore-bundle
More information about k2gl/sigstore-bundle
Files in k2gl/sigstore-bundle
Package sigstore-bundle
Short Description Build Sigstore bundles (.sigstore.json) in PHP — the counterpart to verification, emitting DSSE and message-signature bundles.
License MIT
Homepage https://github.com/k2gl/sigstore-bundle
Informations about the package sigstore-bundle
Build Sigstore bundles in PHP
Assemble a Sigstore bundle — the .sigstore.json that cosign, gitsign and npm/PyPI
provenance emit — from PHP. This is the counterpart to verification: hand it the
pieces you already have (a signature or DSSE envelope, the Fulcio certificate, the
Rekor entry) and it lays them out as the canonical v0.3 JSON that verifiers accept.
It does no signing and no network I/O — it is the format layer. The signature, the certificate and the transparency-log entry come from elsewhere (your signer, Fulcio, Rekor); this package places them in a well-formed bundle.
Requirements
- PHP 8.1+
k2gl/dsse(for the DSSE envelope content)
Installation
Usage
A DSSE-attestation bundle
An artifact-signature bundle
Signing identity
Pick one, matching how the artifact was signed:
->withCertificate($der)— a single Fulcio leaf certificate (the keyless default).->withCertificateChain([$leaf, $intermediate, $root])— a full X.509 chain.->withPublicKey($hint)— a key-based identity; the bundle only names the key by hint.
Compatibility
The output is byte-for-byte the same structure the reference tooling emits: the test
suite rebuilds real cosign/GitHub v0.3 bundles (DSSE, message signature, and with an
RFC 3161 timestamp) from their components and checks the result is identical. Bundles
built here verify with k2gl/sigstore-verify
and with cosign.