Skip to content

Commit 375c003

Browse files
michaelbe-jfroggitbook-bot
authored andcommitted
GITBOOK-251: No subject
1 parent b6a3761 commit 375c003

File tree

1 file changed

+24
-25
lines changed

1 file changed

+24
-25
lines changed

jfrog-applications/jfrog-cli/binaries-management-with-jfrog-artifactory/evidence-service.md

Lines changed: 24 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -369,38 +369,37 @@ jf evd verify --release-bundle <name> --release-bundle-version <version-number>
369369

370370
The following command verifies Sigstore bundle evidence on an artifact using keys retrieved from Artifactory.
371371

372-
{% code overflow="wrap" %}
373372
```
374-
jf evd verify --subject-repo-path cli-sigstore-test/readme.txt --use-artifactory-keys --public-keys public.pem
375-
376-
Subject sha256: 4bf2da010af20d8ed0364caf14f90bcab22b312520c68b9a01bb3479ba9a742c
377-
Subject: cli-sigstore-test/readme.txt
373+
Subject sha256:        4bf2da010af20d8ed0364caf14f90bcab22b312520c68b9a01bb3479ba9a742c
374+
Subject:               cli-sigstore-test/readme.txt
378375
Loaded 3 evidence
376+
379377
Verification passed for 3 out of 3 evidence
378+
380379
- Evidence 1:
381-
- Media type: sigstore.bundle
382-
- Predicate type: in-toto
383-
- Evidence subject sha256: 4bf2da010af20d8ed0364caf14f90bcab22b312520c68b9a01bb3479ba9a742c
384-
- Key source: Sigstore Bundle Key
385-
- Sigstore verification status: success
380+
    - Media type:                            sigstore.bundle
381+
    - Predicate type:                        in-toto
382+
    - Evidence subject sha256:        4bf2da010af20d8ed0364caf14f90bcab22b312520c68b9a01bb3479ba9a742c
383+
    - Key source:                            Sigstore Bundle Key
384+
    - Sigstore verification status:     success
386385
- Evidence 2:
387-
- Media type: evidence.dsse
388-
- Predicate type: application/vnd.in-toto+json
389-
- Evidence subject sha256: 4bf2da010af20d8ed0364caf14f90bcab22b312520c68b9a01bb3479ba9a742c
390-
- Key source: User Provided Key
391-
- Key fingerprint: /IyvutGSsuTPykv+mGtG4sph4TGh3Cl4HRNxbEZo1z4=
392-
- Sha256 verification status: success
393-
- Signatures verification status: success
386+
    - Media type:                            evidence.dsse
387+
    - Predicate type:                        application/vnd.in-toto+json
388+
    - Evidence subject sha256:        4bf2da010af20d8ed0364caf14f90bcab22b312520c68b9a01bb3479ba9a742c
389+
    - Key source:                            User Provided Key
390+
    - Key fingerprint:                       /IyvutGSsuTPykv+mGtG4sph4TGh3Cl4HRNxbEZo1z4=
391+
    - Sha256 verification status:      success
392+
    - Signatures verification status: success
394393
- Evidence 3:
395-
- Media type: evidence.dsse
396-
- Predicate type: vulnerability-scan
397-
- Evidence subject sha256: 4bf2da010af20d8ed0364caf14f90bcab22b312520c68b9a01bb3479ba9a742c
398-
- Key source: Artifactory Key
399-
- Key fingerprint: uz1SAgymeLMkH+lJ5ROCvbTCCnbwgUgy3zeDAR4J47k=
400-
- Sha256 verification status: success
401-
- Signatures verification status: success
394+
    - Media type:                            evidence.dsse
395+
    - Predicate type:                        vulnerability-scan
396+
    - Evidence subject sha256:        4bf2da010af20d8ed0364caf14f90bcab22b312520c68b9a01bb3479ba9a742c
397+
    - Key source:                            Artifactory Key
398+
    - Key fingerprint:                       uz1SAgymeLMkH+lJ5ROCvbTCCnbwgUgy3zeDAR4J47k=
399+
    - Sha256 verification status:       success
400+
    - Signatures verification status:  success
401+
402402
```
403-
{% endcode %}
404403

405404
#### JSON format output
406405

0 commit comments

Comments
 (0)