{"id":25797203,"url":"https://github.com/carabiner-dev/bnd","last_synced_at":"2025-02-27T14:58:24.686Z","repository":{"id":276892522,"uuid":"925016673","full_name":"carabiner-dev/bnd","owner":"carabiner-dev","description":"Sign and package attestations in sigstore bundles","archived":false,"fork":false,"pushed_at":"2025-02-19T22:03:16.000Z","size":209,"stargazers_count":4,"open_issues_count":1,"forks_count":2,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-02-19T23:20:23.204Z","etag":null,"topics":["attestation","attestations","intoto","signature-verification","signatures","sigstore","slsa","slsa-provenance"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/carabiner-dev.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY-INSIGHTS.yml","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2025-01-31T04:07:01.000Z","updated_at":"2025-02-19T22:03:20.000Z","dependencies_parsed_at":"2025-02-11T02:37:11.662Z","dependency_job_id":null,"html_url":"https://github.com/carabiner-dev/bnd","commit_stats":null,"previous_names":["carabiner-dev/bnd"],"tags_count":1,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/carabiner-dev%2Fbnd","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/carabiner-dev%2Fbnd/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/carabiner-dev%2Fbnd/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/carabiner-dev%2Fbnd/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/carabiner-dev","download_url":"https://codeload.github.com/carabiner-dev/bnd/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":241027043,"owners_count":19896721,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["attestation","attestations","intoto","signature-verification","signatures","sigstore","slsa","slsa-provenance"],"created_at":"2025-02-27T14:58:24.002Z","updated_at":"2025-02-27T14:58:24.678Z","avatar_url":"https://github.com/carabiner-dev.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# 🥨 bnd\n\n### A Utility to work with sigstore bundles and attestations\n\t\nbnd is a utility that makes it easy to work with attestations and sigstore bundles.\nIt can create new bundles by \"binding\" an attestation and signing it. It can verify\nexisting bundles, extract data from them inspect their contents.\n\n```\n🥨 bnd: a utility to work with attestations and sigstore bundles.\n\t\nbnd (pronounced bind) is a utility that makes it easy to work with attestations\nand sigstore bundles. It can create new bundles by \"binding\" a sattement, signing\nit and wrappring it in a bundle. It can verify existing bundles, extract data\nfrom them and inspect their contents.\n\nUsage:\n  bnd [command]\n\nExamples:\n\nCreate a new bundle by signing and bundling an attestation and its verification\nmaterial:\n\n  bnd statement --out=bundle.json statement.intoto.json\n\nInspect the resulting bundle:\n\n  bnd inspect bundle.json\n\nExtract the in-toto attestation from the bundle:\n\n  bnd extract attestation bundle.json\n\nExtract the predicate data from the bundle:\n\n  bnd extract predicate bundle.json\n\nAvailable Commands:\n  commit      attest git commits\n  completion  Generate the autocompletion script for the specified shell\n  extract     extract data from sigstore bundles\n  help        Help about any command\n  inspect     prints useful information about a bundle\n  pack        packs one or more bundles into a jsonl formatted file\n  predicate   packs a new attestation into a bundle from a JSON predicate\n  push        pushes an attestation or bundle to github or an OCI registry\n  statement   binds an in-toto attestation in a signed bundle\n  verify      Verifies a bundle signature\n  version     Prints the version\n\nFlags:\n  -h, --help               help for bnd\n      --log-level string   the logging verbosity, either 'panic', 'fatal', 'error', 'warning', 'info', 'debug', 'trace' (default \"info\")\n\nUse \"bnd [command] --help\" for more information about a command.\n```\n\n## Native Sigstore Signing\n\n`bnd` implements sigstore keyless signing just as cosign does. It supports the\ninteractive and device flows as well as limited initial support for ambient\ncredentials (initaially GitHub actions tokens).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcarabiner-dev%2Fbnd","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcarabiner-dev%2Fbnd","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcarabiner-dev%2Fbnd/lists"}