Attested build of burntsushi/ripgrep
172
Cryptographically attested builds of burntsushi/ripgrep, produced
inside a Confidential VM by Kettle.
Every build carries hardware-signed SLSA provenance, so anyone can verify exactly
which source, dependencies, and toolchain produced the binaries.
Image tags are the git commit SHA that was built.
Builds are OCI artifacts, pulled with oras:
oras pull docker.io/confidentialai/burntsushi-ripgrep:f127579b006d9fb388050281d7d7146799a9cd4c
This drops provenance.json, evidence.json, and the built binaries into the
current directory.
Install Kettle, then verify the pulled artifact:
kettle verify .
Kettle reads evidence.json, verifies the hardware signature against the vendor's
public keys, then validates the signed provenance.json and confirms the binary
checksums.
The check above proves the build's attestation. To verify the full launch chain (hardware launch measurement -> the exact IGVM that booted the CVM -> the dm-verity root hash committed in that IGVM -> the actual VM disk image), pull the exact, digest-pinned confidential-VM image this build ran on and re-run verification against it:
oras pull docker.io/confidentialai/kettle-server@sha256:cdded1227761820a4b1f66646414936e926601b08b52db4e0bab9f2a89fadfe3
kettle verify . --igvm guest-smp10.igvm --image disk.raw
Content type
Unrecognized
Digest
sha256:be661eb95…
Size
8.9 MB
Last updated
3 months ago
docker pull confidentialai/burntsushi-ripgrep:f127579b006d9fb388050281d7d7146799a9cd4c