Skip to content

Commit c85352e

Browse files
authored
feat: Add GitLab CI provenance (#6375)
This is a first pass at provenance generation for GitLab CI. This is based loosely off of existing GitLab provenance documents: https://about.gitlab.com/blog/2022/11/30/achieve-slsa-level-2-compliance-with-gitlab/ https://gist.github.com/wlynch/c7fd8f53adc77d3c0ec82356e4d43cb5
1 parent 3d5bbcc commit c85352e

File tree

3 files changed

+435
-62
lines changed

3 files changed

+435
-62
lines changed

workspaces/libnpmpublish/lib/provenance.js

Lines changed: 184 additions & 49 deletions
Original file line numberDiff line numberDiff line change
@@ -1,68 +1,203 @@
11
const { sigstore } = require('sigstore')
2+
const ci = require('ci-info')
3+
const { env } = process
24

35
const INTOTO_PAYLOAD_TYPE = 'application/vnd.in-toto+json'
46
const INTOTO_STATEMENT_TYPE = 'https://in-toto.io/Statement/v0.1'
57
const SLSA_PREDICATE_TYPE = 'https://slsa.dev/provenance/v0.2'
68

7-
const BUILDER_ID = 'https://github.com/actions/runner'
8-
const BUILD_TYPE_PREFIX = 'https://github.com/npm/cli/gha'
9-
const BUILD_TYPE_VERSION = 'v2'
9+
const GITHUB_BUILDER_ID = 'https://github.com/actions/runner'
10+
const GITHUB_BUILD_TYPE_PREFIX = 'https://github.com/npm/cli/gha'
11+
const GITHUB_BUILD_TYPE_VERSION = 'v2'
12+
13+
const GITLAB_BUILD_TYPE_PREFIX = 'https://github.com/npm/cli/gitlab'
14+
const GITLAB_BUILD_TYPE_VERSION = 'v0alpha1'
1015

1116
const generateProvenance = async (subject, opts) => {
12-
const { env } = process
13-
/* istanbul ignore next - not covering missing env var case */
14-
const [workflowPath] = (env.GITHUB_WORKFLOW_REF || '')
15-
.replace(env.GITHUB_REPOSITORY + '/', '')
16-
.split('@')
17-
const payload = {
18-
_type: INTOTO_STATEMENT_TYPE,
19-
subject,
20-
predicateType: SLSA_PREDICATE_TYPE,
21-
predicate: {
22-
buildType: `${BUILD_TYPE_PREFIX}/${BUILD_TYPE_VERSION}`,
23-
builder: { id: BUILDER_ID },
24-
invocation: {
25-
configSource: {
26-
uri: `git+${env.GITHUB_SERVER_URL}/${env.GITHUB_REPOSITORY}@${env.GITHUB_REF}`,
27-
digest: {
28-
sha1: env.GITHUB_SHA,
17+
let payload
18+
if (ci.GITHUB_ACTIONS) {
19+
/* istanbul ignore next - not covering missing env var case */
20+
const [workflowPath] = (env.GITHUB_WORKFLOW_REF || '')
21+
.replace(env.GITHUB_REPOSITORY + '/', '')
22+
.split('@')
23+
payload = {
24+
_type: INTOTO_STATEMENT_TYPE,
25+
subject,
26+
predicateType: SLSA_PREDICATE_TYPE,
27+
predicate: {
28+
buildType: `${GITHUB_BUILD_TYPE_PREFIX}/${GITHUB_BUILD_TYPE_VERSION}`,
29+
builder: { id: GITHUB_BUILDER_ID },
30+
invocation: {
31+
configSource: {
32+
uri: `git+${env.GITHUB_SERVER_URL}/${env.GITHUB_REPOSITORY}@${env.GITHUB_REF}`,
33+
digest: {
34+
sha1: env.GITHUB_SHA,
35+
},
36+
entryPoint: workflowPath,
37+
},
38+
parameters: {},
39+
environment: {
40+
GITHUB_EVENT_NAME: env.GITHUB_EVENT_NAME,
41+
GITHUB_REF: env.GITHUB_REF,
42+
GITHUB_REPOSITORY: env.GITHUB_REPOSITORY,
43+
GITHUB_REPOSITORY_ID: env.GITHUB_REPOSITORY_ID,
44+
GITHUB_REPOSITORY_OWNER_ID: env.GITHUB_REPOSITORY_OWNER_ID,
45+
GITHUB_RUN_ATTEMPT: env.GITHUB_RUN_ATTEMPT,
46+
GITHUB_RUN_ID: env.GITHUB_RUN_ID,
47+
GITHUB_SHA: env.GITHUB_SHA,
48+
GITHUB_WORKFLOW_REF: env.GITHUB_WORKFLOW_REF,
49+
GITHUB_WORKFLOW_SHA: env.GITHUB_WORKFLOW_SHA,
2950
},
30-
entryPoint: workflowPath,
3151
},
32-
parameters: {},
33-
environment: {
34-
GITHUB_EVENT_NAME: env.GITHUB_EVENT_NAME,
35-
GITHUB_REF: env.GITHUB_REF,
36-
GITHUB_REPOSITORY: env.GITHUB_REPOSITORY,
37-
GITHUB_REPOSITORY_ID: env.GITHUB_REPOSITORY_ID,
38-
GITHUB_REPOSITORY_OWNER_ID: env.GITHUB_REPOSITORY_OWNER_ID,
39-
GITHUB_RUN_ATTEMPT: env.GITHUB_RUN_ATTEMPT,
40-
GITHUB_RUN_ID: env.GITHUB_RUN_ID,
41-
GITHUB_SHA: env.GITHUB_SHA,
42-
GITHUB_WORKFLOW_REF: env.GITHUB_WORKFLOW_REF,
43-
GITHUB_WORKFLOW_SHA: env.GITHUB_WORKFLOW_SHA,
52+
metadata: {
53+
buildInvocationId: `${env.GITHUB_RUN_ID}-${env.GITHUB_RUN_ATTEMPT}`,
54+
completeness: {
55+
parameters: false,
56+
environment: false,
57+
materials: false,
58+
},
59+
reproducible: false,
4460
},
61+
materials: [
62+
{
63+
uri: `git+${env.GITHUB_SERVER_URL}/${env.GITHUB_REPOSITORY}@${env.GITHUB_REF}`,
64+
digest: {
65+
sha1: env.GITHUB_SHA,
66+
},
67+
},
68+
],
4569
},
46-
metadata: {
47-
buildInvocationId: `${env.GITHUB_RUN_ID}-${env.GITHUB_RUN_ATTEMPT}`,
48-
completeness: {
49-
parameters: false,
50-
environment: false,
51-
materials: false,
70+
}
71+
}
72+
if (ci.GITLAB) {
73+
payload = {
74+
_type: INTOTO_STATEMENT_TYPE,
75+
subject,
76+
predicateType: SLSA_PREDICATE_TYPE,
77+
predicate: {
78+
buildType: `${GITLAB_BUILD_TYPE_PREFIX}/${GITLAB_BUILD_TYPE_VERSION}`,
79+
builder: { id: `${env.CI_PROJECT_URL}/-/runners/${env.CI_RUNNER_ID}` },
80+
invocation: {
81+
configSource: {
82+
uri: `git+${env.CI_PROJECT_URL}`,
83+
digest: {
84+
sha1: env.CI_COMMIT_SHA,
85+
},
86+
entryPoint: env.CI_JOB_NAME,
87+
},
88+
parameters: {
89+
CI: env.CI,
90+
CI_API_GRAPHQL_URL: env.CI_API_GRAPHQL_URL,
91+
CI_API_V4_URL: env.CI_API_V4_URL,
92+
CI_BUILD_BEFORE_SHA: env.CI_BUILD_BEFORE_SHA,
93+
CI_BUILD_ID: env.CI_BUILD_ID,
94+
CI_BUILD_NAME: env.CI_BUILD_NAME,
95+
CI_BUILD_REF: env.CI_BUILD_REF,
96+
CI_BUILD_REF_NAME: env.CI_BUILD_REF_NAME,
97+
CI_BUILD_REF_SLUG: env.CI_BUILD_REF_SLUG,
98+
CI_BUILD_STAGE: env.CI_BUILD_STAGE,
99+
CI_COMMIT_BEFORE_SHA: env.CI_COMMIT_BEFORE_SHA,
100+
CI_COMMIT_BRANCH: env.CI_COMMIT_BRANCH,
101+
CI_COMMIT_REF_NAME: env.CI_COMMIT_REF_NAME,
102+
CI_COMMIT_REF_PROTECTED: env.CI_COMMIT_REF_PROTECTED,
103+
CI_COMMIT_REF_SLUG: env.CI_COMMIT_REF_SLUG,
104+
CI_COMMIT_SHA: env.CI_COMMIT_SHA,
105+
CI_COMMIT_SHORT_SHA: env.CI_COMMIT_SHORT_SHA,
106+
CI_COMMIT_TIMESTAMP: env.CI_COMMIT_TIMESTAMP,
107+
CI_COMMIT_TITLE: env.CI_COMMIT_TITLE,
108+
CI_CONFIG_PATH: env.CI_CONFIG_PATH,
109+
CI_DEFAULT_BRANCH: env.CI_DEFAULT_BRANCH,
110+
CI_DEPENDENCY_PROXY_DIRECT_GROUP_IMAGE_PREFIX:
111+
env.CI_DEPENDENCY_PROXY_DIRECT_GROUP_IMAGE_PREFIX,
112+
CI_DEPENDENCY_PROXY_GROUP_IMAGE_PREFIX: env.CI_DEPENDENCY_PROXY_GROUP_IMAGE_PREFIX,
113+
CI_DEPENDENCY_PROXY_SERVER: env.CI_DEPENDENCY_PROXY_SERVER,
114+
CI_DEPENDENCY_PROXY_USER: env.CI_DEPENDENCY_PROXY_USER,
115+
CI_JOB_ID: env.CI_JOB_ID,
116+
CI_JOB_NAME: env.CI_JOB_NAME,
117+
CI_JOB_NAME_SLUG: env.CI_JOB_NAME_SLUG,
118+
CI_JOB_STAGE: env.CI_JOB_STAGE,
119+
CI_JOB_STARTED_AT: env.CI_JOB_STARTED_AT,
120+
CI_JOB_URL: env.CI_JOB_URL,
121+
CI_NODE_TOTAL: env.CI_NODE_TOTAL,
122+
CI_PAGES_DOMAIN: env.CI_PAGES_DOMAIN,
123+
CI_PAGES_URL: env.CI_PAGES_URL,
124+
CI_PIPELINE_CREATED_AT: env.CI_PIPELINE_CREATED_AT,
125+
CI_PIPELINE_ID: env.CI_PIPELINE_ID,
126+
CI_PIPELINE_IID: env.CI_PIPELINE_IID,
127+
CI_PIPELINE_SOURCE: env.CI_PIPELINE_SOURCE,
128+
CI_PIPELINE_URL: env.CI_PIPELINE_URL,
129+
CI_PROJECT_CLASSIFICATION_LABEL: env.CI_PROJECT_CLASSIFICATION_LABEL,
130+
CI_PROJECT_DESCRIPTION: env.CI_PROJECT_DESCRIPTION,
131+
CI_PROJECT_ID: env.CI_PROJECT_ID,
132+
CI_PROJECT_NAME: env.CI_PROJECT_NAME,
133+
CI_PROJECT_NAMESPACE: env.CI_PROJECT_NAMESPACE,
134+
CI_PROJECT_NAMESPACE_ID: env.CI_PROJECT_NAMESPACE_ID,
135+
CI_PROJECT_PATH: env.CI_PROJECT_PATH,
136+
CI_PROJECT_PATH_SLUG: env.CI_PROJECT_PATH_SLUG,
137+
CI_PROJECT_REPOSITORY_LANGUAGES: env.CI_PROJECT_REPOSITORY_LANGUAGES,
138+
CI_PROJECT_ROOT_NAMESPACE: env.CI_PROJECT_ROOT_NAMESPACE,
139+
CI_PROJECT_TITLE: env.CI_PROJECT_TITLE,
140+
CI_PROJECT_URL: env.CI_PROJECT_URL,
141+
CI_PROJECT_VISIBILITY: env.CI_PROJECT_VISIBILITY,
142+
CI_REGISTRY: env.CI_REGISTRY,
143+
CI_REGISTRY_IMAGE: env.CI_REGISTRY_IMAGE,
144+
CI_REGISTRY_USER: env.CI_REGISTRY_USER,
145+
CI_RUNNER_DESCRIPTION: env.CI_RUNNER_DESCRIPTION,
146+
CI_RUNNER_ID: env.CI_RUNNER_ID,
147+
CI_RUNNER_TAGS: env.CI_RUNNER_TAGS,
148+
CI_SERVER_HOST: env.CI_SERVER_HOST,
149+
CI_SERVER_NAME: env.CI_SERVER_NAME,
150+
CI_SERVER_PORT: env.CI_SERVER_PORT,
151+
CI_SERVER_PROTOCOL: env.CI_SERVER_PROTOCOL,
152+
CI_SERVER_REVISION: env.CI_SERVER_REVISION,
153+
CI_SERVER_SHELL_SSH_HOST: env.CI_SERVER_SHELL_SSH_HOST,
154+
CI_SERVER_SHELL_SSH_PORT: env.CI_SERVER_SHELL_SSH_PORT,
155+
CI_SERVER_URL: env.CI_SERVER_URL,
156+
CI_SERVER_VERSION: env.CI_SERVER_VERSION,
157+
CI_SERVER_VERSION_MAJOR: env.CI_SERVER_VERSION_MAJOR,
158+
CI_SERVER_VERSION_MINOR: env.CI_SERVER_VERSION_MINOR,
159+
CI_SERVER_VERSION_PATCH: env.CI_SERVER_VERSION_PATCH,
160+
CI_TEMPLATE_REGISTRY_HOST: env.CI_TEMPLATE_REGISTRY_HOST,
161+
GITLAB_CI: env.GITLAB_CI,
162+
GITLAB_FEATURES: env.GITLAB_FEATURES,
163+
GITLAB_USER_ID: env.GITLAB_USER_ID,
164+
GITLAB_USER_LOGIN: env.GITLAB_USER_LOGIN,
165+
RUNNER_GENERATE_ARTIFACTS_METADATA: env.RUNNER_GENERATE_ARTIFACTS_METADATA,
166+
},
167+
environment: {
168+
name: env.CI_RUNNER_DESCRIPTION,
169+
architecture: env.CI_RUNNER_EXECUTABLE_ARCH,
170+
server: env.CI_SERVER_URL,
171+
project: env.CI_PROJECT_PATH,
172+
job: {
173+
id: env.CI_JOB_ID,
174+
},
175+
pipeline: {
176+
id: env.CI_PIPELINE_ID,
177+
ref: env.CI_CONFIG_PATH,
178+
},
179+
},
52180
},
53-
reproducible: false,
54-
},
55-
materials: [
56-
{
57-
uri: `git+${env.GITHUB_SERVER_URL}/${env.GITHUB_REPOSITORY}@${env.GITHUB_REF}`,
58-
digest: {
59-
sha1: env.GITHUB_SHA,
181+
metadata: {
182+
buildInvocationId: `${env.CI_JOB_URL}`,
183+
completeness: {
184+
parameters: true,
185+
environment: true,
186+
materials: false,
60187
},
188+
reproducible: false,
61189
},
62-
],
63-
},
190+
materials: [
191+
{
192+
uri: `git+${env.CI_PROJECT_URL}`,
193+
digest: {
194+
sha1: env.CI_COMMIT_SHA,
195+
},
196+
},
197+
],
198+
},
199+
}
64200
}
65-
66201
return sigstore.attest(Buffer.from(JSON.stringify(payload)), INTOTO_PAYLOAD_TYPE, opts)
67202
}
68203

workspaces/libnpmpublish/lib/publish.js

Lines changed: 21 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -144,19 +144,27 @@ const buildMetadata = async (registry, manifest, tarballData, spec, opts) => {
144144
digest: { sha512: integrity.sha512[0].hexDigest() },
145145
}
146146

147-
// Ensure that we're running in GHA, currently the only supported build environment
148-
if (ciInfo.name !== 'GitHub Actions') {
147+
if (ciInfo.GITHUB_ACTIONS) {
148+
// Ensure that the GHA OIDC token is available
149+
if (!process.env.ACTIONS_ID_TOKEN_REQUEST_URL) {
150+
throw Object.assign(
151+
/* eslint-disable-next-line max-len */
152+
new Error('Provenance generation in GitHub Actions requires "write" access to the "id-token" permission'),
153+
{ code: 'EUSAGE' }
154+
)
155+
}
156+
} else if (ciInfo.GITLAB) {
157+
// Ensure that the Sigstore OIDC token is available
158+
if (!process.env.SIGSTORE_ID_TOKEN) {
159+
throw Object.assign(
160+
/* eslint-disable-next-line max-len */
161+
new Error('Provenance generation in GitLab CI requires "SIGSTORE_ID_TOKEN" with "sigstore" audience to be present in "id_tokens". For more info see:\nhttps://docs.gitlab.com/ee/ci/secrets/id_token_authentication.html'),
162+
{ code: 'EUSAGE' }
163+
)
164+
}
165+
} else {
149166
throw Object.assign(
150-
new Error('Automatic provenance generation not supported outside of GitHub Actions'),
151-
{ code: 'EUSAGE' }
152-
)
153-
}
154-
155-
// Ensure that the GHA OIDC token is available
156-
if (!process.env.ACTIONS_ID_TOKEN_REQUEST_URL) {
157-
throw Object.assign(
158-
/* eslint-disable-next-line max-len */
159-
new Error('Provenance generation in GitHub Actions requires "write" access to the "id-token" permission'),
167+
new Error('Automatic provenance generation not supported for provider: ' + ciInfo.name),
160168
{ code: 'EUSAGE' }
161169
)
162170
}
@@ -173,7 +181,7 @@ const buildMetadata = async (registry, manifest, tarballData, spec, opts) => {
173181
const provenanceBundle = await generateProvenance([subject], opts)
174182

175183
/* eslint-disable-next-line max-len */
176-
log.notice('publish', 'Signed provenance statement with source and build information from GitHub Actions')
184+
log.notice('publish', `Signed provenance statement with source and build information from ${ciInfo.name}`)
177185

178186
const tlogEntry = provenanceBundle?.verificationMaterial?.tlogEntries[0]
179187
/* istanbul ignore else */

0 commit comments

Comments
 (0)