Skip to content

feat(vex): add VEX lifecycle - #218

Merged
nervgh merged 14 commits into
mainfrom
feat/sbom/vex-lifecycle
Aug 13, 2026
Merged

nervgh merged 14 commits into
mainfrom
feat/sbom/vex-lifecycle

Conversation

@nervgh

@nervgh nervgh commented Jul 31, 2026 •

Copy link
Copy Markdown

No description provided.

@nervgh
nervgh force-pushed the feat/sbom/vex-lifecycle branch 2 times, most recently from 051676b to 9cdb56e Compare July 31, 2026 18:06
@nervgh
nervgh marked this pull request as ready for review August 3, 2026 17:33
@nervgh
nervgh force-pushed the feat/sbom/vex-lifecycle branch 2 times, most recently from 13630b7 to 14f90f9 Compare August 4, 2026 14:47
Comment thread pkg/build/vex_step_test.go Outdated
Comment thread pkg/build/build_phase.go Outdated
Comment thread pkg/build/build_phase.go Outdated
Comment thread pkg/giterminism_manager/config/config.go
Comment thread pkg/giterminism_manager/file_reader/vexfile.go
Comment thread pkg/giterminism_manager/file_manager/file_manager.go Outdated
Comment thread pkg/vex/image/image.go Outdated
Comment thread pkg/vex/image/image.go Outdated
Comment thread pkg/build/vex_step.go Outdated
Comment thread pkg/config/raw_vex.go
Alexandr Zaytsev added 8 commits August 9, 2026 18:15
Signed-off-by: Alexandr Zaytsev <alexandr.zaytsev@flant.com>
Define contracts, data model, plan, quickstart, and research for VEX
document handling in werf.yaml. These documents establish the
architecture before implementation, mirroring the existing SBOM
pattern for OCI artifact storage and retrieval.

Signed-off-by: Alexandr Zaytsev <alexandr.zaytsev@flant.com>
Signed-off-by: Alexandr Zaytsev <alexandr.zaytsev@flant.com>
Add a `vex` option to Dockerfile and Stapel image definitions in
werf.yaml. During build, wrap the OpenVEX document in an in-toto
statement and DSSE envelope and attach it to the image manifest as an
OCI artifact.

Rebuilds skip publishing when the VEX document and image digest are
unchanged, and cleanup removes VEX artifacts orphaned with their
stages.

Signed-off-by: Alexandr Zaytsev <alexandr.zaytsev@flant.com>
Add tasks T026-T029 for git-tracking validation of VEX files
and cleanup of a duplicate VEX validation call.

Signed-off-by: Alexandr Zaytsev <alexandr.zaytsev@flant.com>
Add ReadVEXFile to FileReader and InspectConfigVexFilePath to Inspector
interfaces. Update convergeImageVex in build_phase.go to use these
methods instead of direct os.ReadFile, ensuring VEX files are validated
as Git-tracked.

Signed-off-by: Alexandr Zaytsev <alexandr.zaytsev@flant.com>
Signed-off-by: Alexandr Zaytsev <alexandr.zaytsev@flant.com>
Signed-off-by: Alexandr Zaytsev <alexandr.zaytsev@flant.com>
@nervgh
nervgh force-pushed the feat/sbom/vex-lifecycle branch from 14f90f9 to e96a4be Compare August 9, 2026 15:20
Alexandr Zaytsev added 4 commits August 9, 2026 18:42
Record the post-review findings from PR #218 in the VEX lifecycle spec:
use the DSSE media type for VEX artifacts, validate config at parsing
time,
add config.vex.allowUncommitted, use a separate VEX file cache, remove
PullVEX and the unused stagesStorage field, and error on empty vex
config.
Add Phase 8 cleanup tasks and a shared verification checklist.

Signed-off-by: Alexandr Zaytsev <alexandr.zaytsev@flant.com>
Update plan, spec, and tasks documents to:
- Reflect removal of PullVEX as dead code per PR #218
- Change test commands to use task paths and --focus instead of -run
- Add cross-references and new coverage tasks (T041-T043)
- Update dependency descriptions for US2

Signed-off-by: Alexandr Zaytsev <alexandr.zaytsev@flant.com>
Extract the publish-check logic into a proper production function
instead of being duplicated in tests. Move VEX file validation from
runtime to config parsing time. Add the config.vex.allowUncommitted
giterminism directive. Fix a cache collision where the Dockerfile
cache was reused for VEX files. Remove unused stagesStorage field
from vexStep. Add validation errors for empty vex config and improve
error messaging for registries lacking OCI subject reference support.

Signed-off-by: Alexandr Zaytsev <alexandr.zaytsev@flant.com>
PullVEX is never called; VEX retrieval is covered by
`werf attest get --type openvex`. Rename the PullVEX test block to
AttestationRoundTrip and record the completed convergence tasks in
the VEX lifecycle spec.

Signed-off-by: Alexandr Zaytsev <alexandr.zaytsev@flant.com>
Comment thread pkg/giterminism_manager/file_manager/file_manager.go
Comment thread pkg/giterminism_manager/file_manager/file_manager.go
@nervgh
nervgh marked this pull request as draft August 11, 2026 12:41
Alexandr Zaytsev added 2 commits August 11, 2026 22:33
Signed-off-by: Alexandr Zaytsev <alexandr.zaytsev@flant.com>
Signed-off-by: Alexandr Zaytsev <alexandr.zaytsev@flant.com>
@nervgh
nervgh marked this pull request as ready for review August 12, 2026 08:02
@nervgh nervgh changed the title feat(sbom): add VEX lifecycle feat(vex): add VEX lifecycle Aug 13, 2026
@nervgh
nervgh merged commit 596f3c1 into main Aug 13, 2026
15 checks passed
@nervgh
nervgh deleted the feat/sbom/vex-lifecycle branch August 13, 2026 07:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants