File: parse.go

package info (click to toggle)
docker.io 26.1.5%2Bdfsg1-9
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid, trixie
  • size: 68,576 kB
  • sloc: sh: 5,748; makefile: 912; ansic: 664; asm: 228; python: 162
file content (81 lines) | stat: -rw-r--r-- 1,807 bytes parent folder | download | duplicates (2)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
package attestations

import (
	"encoding/csv"
	"strings"

	"github.com/pkg/errors"
)

const (
	KeyTypeSbom       = "sbom"
	KeyTypeProvenance = "provenance"
)

const (
	defaultSBOMGenerator = "docker/buildkit-syft-scanner:stable-1"
)

func Filter(v map[string]string) map[string]string {
	attests := make(map[string]string)
	for k, v := range v {
		if strings.HasPrefix(k, "attest:") {
			attests[k] = v
			continue
		}
		if strings.HasPrefix(k, "build-arg:BUILDKIT_ATTEST_") {
			attests[k] = v
			continue
		}
	}
	return attests
}

func Validate(values map[string]map[string]string) (map[string]map[string]string, error) {
	for k := range values {
		if k != KeyTypeSbom && k != KeyTypeProvenance {
			return nil, errors.Errorf("unknown attestation type %q", k)
		}
	}
	return values, nil
}

func Parse(values map[string]string) (map[string]map[string]string, error) {
	attests := make(map[string]string)
	for k, v := range values {
		if strings.HasPrefix(k, "attest:") {
			attests[strings.ToLower(strings.TrimPrefix(k, "attest:"))] = v
			continue
		}
		if strings.HasPrefix(k, "build-arg:BUILDKIT_ATTEST_") {
			attests[strings.ToLower(strings.TrimPrefix(k, "build-arg:BUILDKIT_ATTEST_"))] = v
			continue
		}
	}

	out := make(map[string]map[string]string)
	for k, v := range attests {
		attrs := make(map[string]string)
		out[k] = attrs
		if k == KeyTypeSbom {
			attrs["generator"] = defaultSBOMGenerator
		}
		if v == "" {
			continue
		}
		csvReader := csv.NewReader(strings.NewReader(v))
		fields, err := csvReader.Read()
		if err != nil {
			return nil, errors.Wrapf(err, "failed to parse %s", k)
		}
		for _, field := range fields {
			parts := strings.SplitN(field, "=", 2)
			if len(parts) != 2 {
				parts = append(parts, "")
			}
			attrs[parts[0]] = parts[1]
		}
	}

	return Validate(out)
}