thephpf / attestation
A PHP library to aid in verifying artifact attestations
0.0.7
2026-07-20 18:42 UTC
Requires
- php: ^7.4||^8.0
- ext-json: *
- composer/composer: ^2.2
- webmozart/assert: ^1.11
Requires (Dev)
- doctrine/coding-standard: ^13.0 || ^14.0
- phpstan/phpstan: ^2.1
- phpstan/phpstan-webmozart-assert: ^2.0
- phpunit/phpunit: ^9.6.25
Suggests
- ext-openssl: Needed to verify certificates using OpenSSL
- ext-snappy: Decompress bundle attestations faster; if not, flow-php/snappy PHP fallback is used
Provides
None
Conflicts
None
Replaces
None
README
A PHP library to aid in verifying artifact attestations. This tool will carry out some basic verifications that the given file is genuine. The checks it carries out are:
- Verifies the attestation certificate was signed by a trusted root
- Verifies the given OID extensions match what you expect
- Checks the digest in the attestation record matches the actual file given
- Verifies the DSSE envelope signature
Library usage
Fetching a bundle from GitHub's Artifact Attestations API and verifying it:
<?php use ThePhpFoundation\Attestation\AttestationException; use ThePhpFoundation\Attestation\BundleSource\DownloadGitHubBundle; use ThePhpFoundation\Attestation\FilenameWithChecksum; use ThePhpFoundation\Attestation\FulcioSigstoreOidExtensions; use ThePhpFoundation\Attestation\Verification\VerifyBundleWithOpenSsl; try { $file = FilenameWithChecksum::fromFilename($fileYouWantToVerify); $bundles = DownloadGitHubBundle::factory('your-org') // the org/user in your GH URL, e.g. https://github.com/your-org ->getBundles($file); VerifyBundleWithOpenSsl::factory() ->verify( $bundles, $file, 'the-filename', // the filename of the subject when it was built [ FulcioSigstoreOidExtensions::ISSUER_V2 => 'https://token.actions.githubusercontent.com', FulcioSigstoreOidExtensions::SOURCE_REPOSITORY_URI => 'https://github.com/your-org/your-repo', FulcioSigstoreOidExtensions::SOURCE_REPOSITORY_OWNER_URI => 'https://github.com/your-org', ], ); } catch (AttestationException $issue) { // Handle a failure to fetch or verify the attestation in the way you see fit... }
CLI usage
A verify-bundle command is provided, implementing a subset of the
Sigstore conformance CLI protocol,
to verify a local Sigstore bundle file against a local artifact:
php bin/cli.php verify-bundle \ --bundle=path/to/bundle.json \ --certificate-oidc-issuer=https://token.actions.githubusercontent.com \ path/to/artifact
Pass --trusted-root=path/to/trusted-root.jsonl to verify against a custom
trusted root instead of the one bundled with this library.