MAQPNADocs

maqpna verify

Verify signatures, SBOM attestations and checksums of MAQPNA releases

Operate-o json | yaml

Synopsis#

maqpna verify release VERSION [--registry R] [--sbom] [--binaries DIR] [--no-images] [--no-chart]
maqpna verify image  REF [--identity I | --identity-regexp RE] [--issuer URL] [--sbom]
maqpna verify chart  REF|--version V [--registry R]
maqpna verify binary FILE [--bundle FILE.sigstore.json] [--checksums checksums.txt]
maqpna verify bundle DIR [--require-signature] [--key cosign.pub | --certificate-identity[-regexp] ...] [--trusted-root F]

Description#

Exit status 3 when any check fails. Defaults trust the MAQPNA release workflows: images and the chart signed by the MAQPNA release.yml at the tag, binaries by the MAQPNA maqpna-signed-release.yml.

Subcommands#

Examples#

maqpna verify release v1.4.0
maqpna verify binary ./maqpna --checksums checksums.txt
maqpna verify image ghcr.io/maqpna/gateway:v1.4.0 --sbom

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna verify --help.cast

This command downloads signatures, images or charts from the network, so the recording shows its help.