Add a Rego builtin called `attest.internals.parse_library_definition` for parsing the DOI definition files in https://github.com/docker-library/official-images/tree/master/library. This will allow us to verify DOI provenance fields against these files which are the source of truth for DOI images. This function just defers to https://github.com/docker-library/bashbrew/blob/master/manifest/rfc2822.go.
8 lines
80 B
Rego
8 lines
80 B
Rego
package attest
|
|
|
|
import rego.v1
|
|
|
|
success if {
|
|
some env in attest.fetch("foo")
|
|
}
|