docker-sign-verify


Namedocker-sign-verify JSON
Version 2.1.0 PyPI version JSON
download
home_pagehttps://github.com/crashvb/docker-sign-verify
SummaryA utility that can be used to sign and verify docker images.
upload_time2024-08-18 01:07:34
maintainerNone
docs_urlNone
authorRichard Davis
requires_pythonNone
licenseApache License 2.0
keywords docker docker-sign docker-verify integrity sign signatures verify
VCS
bugtrack_url
requirements No requirements were recorded.
Travis-CI No Travis.
coveralls test coverage No coveralls.
            # docker-sign-verify

[![pypi version](https://img.shields.io/pypi/v/docker-sign-verify.svg)](https://pypi.org/project/docker-sign-verify)
[![build status](https://github.com/crashvb/docker-sign-verify/actions/workflows/main.yml/badge.svg)](https://github.com/crashvb/docker-sign-verify/actions)
[![coverage status](https://coveralls.io/repos/github/crashvb/docker-sign-verify/badge.svg)](https://coveralls.io/github/crashvb/docker-sign-verify)
[![python versions](https://img.shields.io/pypi/pyversions/docker-sign-verify.svg?logo=python&logoColor=FBE072)](https://pypi.org/project/docker-sign-verify)
[![linting](https://img.shields.io/badge/linting-pylint-yellowgreen)](https://github.com/PyCQA/pylint)
[![code style](https://img.shields.io/badge/code%20style-black-000000.svg)](https://github.com/psf/black)
[![license](https://img.shields.io/github/license/crashvb/docker-sign-verify.svg)](https://github.com/crashvb/docker-sign-verify/blob/master/LICENSE.md)

## Overview

A utility that can be used to create and verify embedded signatures in docker images, and verify the integrity of image metadata and layers.

The goal of this utility is to operate directly on Docker Registries (v2).

## Features

* Verifies and signs files in place; no need to replicate images using docker-cli.
* Extensible signing technologies; built-in support for GnuPG and PKI.
* Integrates with the docker credentials store.

## Installation
### From [pypi.org](https://pypi.org/project/docker-sign-verify/)

```
$ pip install docker_sign_verify
```

### From source code

```bash
$ git clone https://github.com/crashvb/docker-sign-verify
$ cd docker-sign-verify
$ virtualenv env
$ source env/bin/activate
$ python -m pip install --editable .[dev]
```

## Usage
### Signing and verifying an image

Using master key with id `7DDD762AFCDF1E55` and sukey with id `9DD1BB948581B0AD`:

```bash
$ gpg --keyid-format LONG --list-keys 7DDD762AFCDF1E55
pub   rsa4096/7DDD762AFCDF1E55 2017-11-30 [SC] [expires: 2027-11-28]
uid                 [ultimate] Richard Davis <crashvb>
sub   rsa4096/9DD1BB948581B0AD 2017-11-30 [S] [expires: 2027-11-28]
```

Resolve the tag `crashvb/base:ubuntu` in a remote registry `registry:5000`, verify all layers, and sign the digest of the
canonicalized configuration. Then, upload a new manifest containing the embedded signatures, and assign it the tag
`crashvb/base:ubuntu_signed`.


```bash
$ dsv --debug sign --keyid="7DDD762AFCDF1E55" registry:5000/crashvb/base:ubuntu registry:5000/crashvb/base:ubuntu_signed
Keypass []:
INFO:root:Signing: registry:5000/crashvb/base:ubuntu ...
INFO:root:Verifying Integrity: registry:5000/crashvb/base:ubuntu ...
DEBUG:root:    config digest: sha256:8ff76ab7ecbe0...424bf93cacad083c0
DEBUG:root:    manifest layers:
                        sha256:3b37166ec6145...4e6a6e7580cdeff8e
                        sha256:504facff238fd...ddc52d31448a044bd
                        sha256:ebbcacd28e101...73bf796e12b1bb449
                        sha256:c7fb3351ecad2...042086fe72c902b8a
                        sha256:2e3debadcbf7e...eca27cb4d809d56c2
                        sha256:a5396a146776f...4e30f97ed2e9891a4
                        sha256:6389d93ef5c7f...243609c6f41637e84
                        sha256:e05442215521c...fbdadc15c5c80294f
                        sha256:f4ed07aa21a9b...f1fd5a4095bf575c9
                        sha256:e41e7b47a71d3...4611b5ed003208f81
                        sha256:ae19c1f4b6b19...b28fef2632aca9064
DEBUG:root:    image layers:
                        sha256:8823818c47486...45be9ba0eb149a643
                        sha256:19d043c86cbcb...da1e8fc6ce1e43d7f
                        sha256:883eafdbe580e...50cad1875e13e3915
                        sha256:4775b2f378bb7...91719367c739ef25a
                        sha256:75b79e19929ce...1ee48b949261770cf
                        sha256:440c82316bee2...ed8d2c3f168299db8
                        sha256:0538f6ef1ac4c...4cb5a61b9bd530929
                        sha256:090cbbe4fbc62...25f7322fb5cd1d619
                        sha256:5b42cc22f7bd7...4492f3790f05fccbc
                        sha256:ffd252d089fe6...b41e7336a18e12c8a
                        sha256:22681af0cc030...ca77af16b6bfeb204
INFO:root:Integrity check passed.
DEBUG:root:    Signature:
-----BEGIN PGP SIGNATURE-----

iQIcBAABCgAGBQJcW2I9AAoJEJ3Ru5SFgbCtfW0QAJO4WCS/0hPwby3RpIYxSZ74
dcr7lRccsH7afdEuFXp5SlxXBL8gXyfEAcmUcuwzhapGdBPntWXqf10R3tq9Bx0j
36AOwZGt+vSCGdvOz6MEyCgS/JBXXGAUt3L0ciB4dCh/Un2ANSqQ1g+vT2zhHoL5
HggzDTaddawU8sSGhIj/fR62+ari5xWIXs2Vn3+wTjrdiQ6G3W2cb64LWTCYo2sH
qenDO4Z3AkdzRMT10Z4IqkU2XjHQiqIJhdcdJMnF+JZU8pbzmKDyXLE5JOt8Dx39
R2G4AUNXA9vQClYBShAUSTSB2nMRd2fX2GWd/jKgn0mvLa3a+V27VmYW/jQGRWHW
qlJsh0WUBeVQjLGpf+zqknhAXnNmm5ZIvCYqPVJ3PAR6BGi7luzk9s2wBgzlDbED
JCaFka6U1b/YAAc+PTs6Am4N0bGS1p9r7GWb+i7PFWTwH/H5D1MDXDgDNyjE52Qh
DyXgcaJBnQbu2T6BbzYY2WSyvjPWVOkwQGb2lpBKrO7Y1w7T7VMlTVloI+hPWfSs
5VxmfyFNJFHq5Iqo1N76W1/mSDPxv6qF3NOxvK+rMsoqqGJ7/BR8RB4jueeXTgLf
Yr0rnXDsuKbNmh88x/GPg+xbf3m2nVv9kB0F5vhb9J756rlwb1A8+RDVDRs5ICLF
m7KvRvDb7+zZvnur5lTu
=voGn
-----END PGP SIGNATURE-----
DEBUG:root:    config digest (signed): sha256:d9e31c5898fe25bb7b3ac86f8570b8961d5d878aace796920a9da3f8cd8251cb
INFO:root:Created new image: registry:5000/crashvb/base:ubuntu_signed
```

Resolve the tag `crashvb/base:ubuntu_signed` in a remote registry `registry:5000`, verify all layers and embedded
signatures.

```bash
$ dsv --debug verify registry:5000/crashvb/base:ubuntu_signed
INFO:root:Verifying Integrity: registry:5000/crashvb/base:ubuntu_signed ...
DEBUG:root:    config digest: sha256:d9e31c5898fe2...20a9da3f8cd8251cb
DEBUG:root:    manifest layers:
                        sha256:3b37166ec6145...4e6a6e7580cdeff8e
                        sha256:504facff238fd...ddc52d31448a044bd
                        sha256:ebbcacd28e101...73bf796e12b1bb449
                        sha256:c7fb3351ecad2...042086fe72c902b8a
                        sha256:2e3debadcbf7e...eca27cb4d809d56c2
                        sha256:a5396a146776f...4e30f97ed2e9891a4
                        sha256:6389d93ef5c7f...243609c6f41637e84
                        sha256:e05442215521c...fbdadc15c5c80294f
                        sha256:f4ed07aa21a9b...f1fd5a4095bf575c9
                        sha256:e41e7b47a71d3...4611b5ed003208f81
                        sha256:ae19c1f4b6b19...b28fef2632aca9064
DEBUG:root:    image layers:
                        sha256:8823818c47486...45be9ba0eb149a643
                        sha256:19d043c86cbcb...da1e8fc6ce1e43d7f
                        sha256:883eafdbe580e...50cad1875e13e3915
                        sha256:4775b2f378bb7...91719367c739ef25a
                        sha256:75b79e19929ce...1ee48b949261770cf
                        sha256:440c82316bee2...ed8d2c3f168299db8
                        sha256:0538f6ef1ac4c...4cb5a61b9bd530929
                        sha256:090cbbe4fbc62...25f7322fb5cd1d619
                        sha256:5b42cc22f7bd7...4492f3790f05fccbc
                        sha256:ffd252d089fe6...b41e7336a18e12c8a
                        sha256:22681af0cc030...ca77af16b6bfeb204
INFO:root:Integrity check passed.
INFO:root:Verifying Signature(s): registry:5000/crashvb/base:ubuntu_signed ...
DEBUG:root:    config digest (signed): sha256:d9e31c5898fe2...20a9da3f8cd8251cb
DEBUG:root:    config digest (unsigned): sha256:8ff76ab7ecbe0...424bf93cacad083c0
DEBUG:root:    signtures:
DEBUG:root:        Signature made 2019-02-06 22:39:57 using key ID 9DD1BB948581B0AD
DEBUG:root:            Richard Davis <crashvb>
INFO:root:Signature check passed.
```

Replicate both images to a local repository

```bash
$ docker pull registry:5000/crashvb/base:ubuntu
ubuntu: Pulling from crashvb/base
3b37166ec614: Download complete
504facff238f: Download complete
ebbcacd28e10: Download complete
c7fb3351ecad: Download complete
2e3debadcbf7: Download complete
a5396a146776: Download complete
6389d93ef5c7: Download complete
e05442215521: Download complete
f4ed07aa21a9: Download complete
e41e7b47a71d: Download complete
ae19c1f4b6b1: Download complete
Digest: sha256:8acac09a29bb9364dca10cce18e7d2fd4f83cb495a8519af585b56bcfeba03ca
Status: Downloaded newer image for registry:5000/crashvb/base:ubuntu
```

```bash
$ docker pull registry:5000/crashvb/base:ubuntu_signed
ubuntu_signed: Pulling from crashvb/base
3b37166ec614: Already exists
504facff238f: Already exists
ebbcacd28e10: Already exists
c7fb3351ecad: Already exists
2e3debadcbf7: Already exists
a5396a146776: Already exists
6389d93ef5c7: Already exists
e05442215521: Already exists
f4ed07aa21a9: Already exists
e41e7b47a71d: Already exists
ae19c1f4b6b1: Already exists
Digest: sha256:36e6e7cae412993ba19c0cf9a4583d1988e7668b5ce8e959f1915aabd0bb3bb2
Status: Downloaded newer image for registry:5000/crashvb/base:ubuntu_signed
```

```bash
$ docker images --format="{{.ID}}" registry:5000/crashvb/base:ubuntu
8ff76ab7ecbe
```

```bash
$ docker images --format="{{.ID}}" registry:5000/crashvb/base:ubuntu_signed
d9e31c5898fe
```

### Environment Variables

| Variable | Default Value | Description |
| ---------| ------------- | ----------- |
| DSV\_CREDENTIALS\_STORE | ~/.docker/config.json | The docker credentials store. |
| DSV\_DEFAULT\_REGISTRY | index.docker.io | The dockerhub registry API endpoint. |
| DSV\_DOCKERHUB\_AUTH | auth.docker.io | The dockerhub authentication endpoint. |
| DSV\_GPG\_DATASTORE | ~/.gnupg | The GnuPG home directory. |
| DSV\_GPG\_LOG\_ERRORS | | If defined, errors from gnupg will be logged. |
| DSV\_KEYID | _undefined_ | Identifier of the signing key. For GnuPG this is the keyid. For PKI this is the path to PEM encoded private key. |
| DSV\_KEYPASS | "" | The corresponding key passphrase. |
| DSV\_KEYTYPE | GPG | The signature type. Either GPG or PKI.
| DSV\_PKI\_DATASTORE | ~/.dsv.pem | The PKI key store and trust store (concatenated PEM entities). |


## Development

[Source Control](https://github.com/crashvb/docker-sign-verify)



            

Raw data

            {
    "_id": null,
    "home_page": "https://github.com/crashvb/docker-sign-verify",
    "name": "docker-sign-verify",
    "maintainer": null,
    "docs_url": null,
    "requires_python": null,
    "maintainer_email": null,
    "keywords": "docker docker-sign docker-verify integrity sign signatures verify",
    "author": "Richard Davis",
    "author_email": "crashvb@gmail.com",
    "download_url": "https://files.pythonhosted.org/packages/88/e1/ea469b057a2a7010cc2e4dc7dcf438325148fc193a1b3972813307852c4b/docker_sign_verify-2.1.0.tar.gz",
    "platform": null,
    "description": "# docker-sign-verify\n\n[![pypi version](https://img.shields.io/pypi/v/docker-sign-verify.svg)](https://pypi.org/project/docker-sign-verify)\n[![build status](https://github.com/crashvb/docker-sign-verify/actions/workflows/main.yml/badge.svg)](https://github.com/crashvb/docker-sign-verify/actions)\n[![coverage status](https://coveralls.io/repos/github/crashvb/docker-sign-verify/badge.svg)](https://coveralls.io/github/crashvb/docker-sign-verify)\n[![python versions](https://img.shields.io/pypi/pyversions/docker-sign-verify.svg?logo=python&logoColor=FBE072)](https://pypi.org/project/docker-sign-verify)\n[![linting](https://img.shields.io/badge/linting-pylint-yellowgreen)](https://github.com/PyCQA/pylint)\n[![code style](https://img.shields.io/badge/code%20style-black-000000.svg)](https://github.com/psf/black)\n[![license](https://img.shields.io/github/license/crashvb/docker-sign-verify.svg)](https://github.com/crashvb/docker-sign-verify/blob/master/LICENSE.md)\n\n## Overview\n\nA utility that can be used to create and verify embedded signatures in docker images, and verify the integrity of image metadata and layers.\n\nThe goal of this utility is to operate directly on Docker Registries (v2).\n\n## Features\n\n* Verifies and signs files in place; no need to replicate images using docker-cli.\n* Extensible signing technologies; built-in support for GnuPG and PKI.\n* Integrates with the docker credentials store.\n\n## Installation\n### From [pypi.org](https://pypi.org/project/docker-sign-verify/)\n\n```\n$ pip install docker_sign_verify\n```\n\n### From source code\n\n```bash\n$ git clone https://github.com/crashvb/docker-sign-verify\n$ cd docker-sign-verify\n$ virtualenv env\n$ source env/bin/activate\n$ python -m pip install --editable .[dev]\n```\n\n## Usage\n### Signing and verifying an image\n\nUsing master key with id `7DDD762AFCDF1E55` and sukey with id `9DD1BB948581B0AD`:\n\n```bash\n$ gpg --keyid-format LONG --list-keys 7DDD762AFCDF1E55\npub   rsa4096/7DDD762AFCDF1E55 2017-11-30 [SC] [expires: 2027-11-28]\nuid                 [ultimate] Richard Davis <crashvb>\nsub   rsa4096/9DD1BB948581B0AD 2017-11-30 [S] [expires: 2027-11-28]\n```\n\nResolve the tag `crashvb/base:ubuntu` in a remote registry `registry:5000`, verify all layers, and sign the digest of the\ncanonicalized configuration. Then, upload a new manifest containing the embedded signatures, and assign it the tag\n`crashvb/base:ubuntu_signed`.\n\n\n```bash\n$ dsv --debug sign --keyid=\"7DDD762AFCDF1E55\" registry:5000/crashvb/base:ubuntu registry:5000/crashvb/base:ubuntu_signed\nKeypass []:\nINFO:root:Signing: registry:5000/crashvb/base:ubuntu ...\nINFO:root:Verifying Integrity: registry:5000/crashvb/base:ubuntu ...\nDEBUG:root:    config digest: sha256:8ff76ab7ecbe0...424bf93cacad083c0\nDEBUG:root:    manifest layers:\n                        sha256:3b37166ec6145...4e6a6e7580cdeff8e\n                        sha256:504facff238fd...ddc52d31448a044bd\n                        sha256:ebbcacd28e101...73bf796e12b1bb449\n                        sha256:c7fb3351ecad2...042086fe72c902b8a\n                        sha256:2e3debadcbf7e...eca27cb4d809d56c2\n                        sha256:a5396a146776f...4e30f97ed2e9891a4\n                        sha256:6389d93ef5c7f...243609c6f41637e84\n                        sha256:e05442215521c...fbdadc15c5c80294f\n                        sha256:f4ed07aa21a9b...f1fd5a4095bf575c9\n                        sha256:e41e7b47a71d3...4611b5ed003208f81\n                        sha256:ae19c1f4b6b19...b28fef2632aca9064\nDEBUG:root:    image layers:\n                        sha256:8823818c47486...45be9ba0eb149a643\n                        sha256:19d043c86cbcb...da1e8fc6ce1e43d7f\n                        sha256:883eafdbe580e...50cad1875e13e3915\n                        sha256:4775b2f378bb7...91719367c739ef25a\n                        sha256:75b79e19929ce...1ee48b949261770cf\n                        sha256:440c82316bee2...ed8d2c3f168299db8\n                        sha256:0538f6ef1ac4c...4cb5a61b9bd530929\n                        sha256:090cbbe4fbc62...25f7322fb5cd1d619\n                        sha256:5b42cc22f7bd7...4492f3790f05fccbc\n                        sha256:ffd252d089fe6...b41e7336a18e12c8a\n                        sha256:22681af0cc030...ca77af16b6bfeb204\nINFO:root:Integrity check passed.\nDEBUG:root:    Signature:\n-----BEGIN PGP SIGNATURE-----\n\niQIcBAABCgAGBQJcW2I9AAoJEJ3Ru5SFgbCtfW0QAJO4WCS/0hPwby3RpIYxSZ74\ndcr7lRccsH7afdEuFXp5SlxXBL8gXyfEAcmUcuwzhapGdBPntWXqf10R3tq9Bx0j\n36AOwZGt+vSCGdvOz6MEyCgS/JBXXGAUt3L0ciB4dCh/Un2ANSqQ1g+vT2zhHoL5\nHggzDTaddawU8sSGhIj/fR62+ari5xWIXs2Vn3+wTjrdiQ6G3W2cb64LWTCYo2sH\nqenDO4Z3AkdzRMT10Z4IqkU2XjHQiqIJhdcdJMnF+JZU8pbzmKDyXLE5JOt8Dx39\nR2G4AUNXA9vQClYBShAUSTSB2nMRd2fX2GWd/jKgn0mvLa3a+V27VmYW/jQGRWHW\nqlJsh0WUBeVQjLGpf+zqknhAXnNmm5ZIvCYqPVJ3PAR6BGi7luzk9s2wBgzlDbED\nJCaFka6U1b/YAAc+PTs6Am4N0bGS1p9r7GWb+i7PFWTwH/H5D1MDXDgDNyjE52Qh\nDyXgcaJBnQbu2T6BbzYY2WSyvjPWVOkwQGb2lpBKrO7Y1w7T7VMlTVloI+hPWfSs\n5VxmfyFNJFHq5Iqo1N76W1/mSDPxv6qF3NOxvK+rMsoqqGJ7/BR8RB4jueeXTgLf\nYr0rnXDsuKbNmh88x/GPg+xbf3m2nVv9kB0F5vhb9J756rlwb1A8+RDVDRs5ICLF\nm7KvRvDb7+zZvnur5lTu\n=voGn\n-----END PGP SIGNATURE-----\nDEBUG:root:    config digest (signed): sha256:d9e31c5898fe25bb7b3ac86f8570b8961d5d878aace796920a9da3f8cd8251cb\nINFO:root:Created new image: registry:5000/crashvb/base:ubuntu_signed\n```\n\nResolve the tag `crashvb/base:ubuntu_signed` in a remote registry `registry:5000`, verify all layers and embedded\nsignatures.\n\n```bash\n$ dsv --debug verify registry:5000/crashvb/base:ubuntu_signed\nINFO:root:Verifying Integrity: registry:5000/crashvb/base:ubuntu_signed ...\nDEBUG:root:    config digest: sha256:d9e31c5898fe2...20a9da3f8cd8251cb\nDEBUG:root:    manifest layers:\n                        sha256:3b37166ec6145...4e6a6e7580cdeff8e\n                        sha256:504facff238fd...ddc52d31448a044bd\n                        sha256:ebbcacd28e101...73bf796e12b1bb449\n                        sha256:c7fb3351ecad2...042086fe72c902b8a\n                        sha256:2e3debadcbf7e...eca27cb4d809d56c2\n                        sha256:a5396a146776f...4e30f97ed2e9891a4\n                        sha256:6389d93ef5c7f...243609c6f41637e84\n                        sha256:e05442215521c...fbdadc15c5c80294f\n                        sha256:f4ed07aa21a9b...f1fd5a4095bf575c9\n                        sha256:e41e7b47a71d3...4611b5ed003208f81\n                        sha256:ae19c1f4b6b19...b28fef2632aca9064\nDEBUG:root:    image layers:\n                        sha256:8823818c47486...45be9ba0eb149a643\n                        sha256:19d043c86cbcb...da1e8fc6ce1e43d7f\n                        sha256:883eafdbe580e...50cad1875e13e3915\n                        sha256:4775b2f378bb7...91719367c739ef25a\n                        sha256:75b79e19929ce...1ee48b949261770cf\n                        sha256:440c82316bee2...ed8d2c3f168299db8\n                        sha256:0538f6ef1ac4c...4cb5a61b9bd530929\n                        sha256:090cbbe4fbc62...25f7322fb5cd1d619\n                        sha256:5b42cc22f7bd7...4492f3790f05fccbc\n                        sha256:ffd252d089fe6...b41e7336a18e12c8a\n                        sha256:22681af0cc030...ca77af16b6bfeb204\nINFO:root:Integrity check passed.\nINFO:root:Verifying Signature(s): registry:5000/crashvb/base:ubuntu_signed ...\nDEBUG:root:    config digest (signed): sha256:d9e31c5898fe2...20a9da3f8cd8251cb\nDEBUG:root:    config digest (unsigned): sha256:8ff76ab7ecbe0...424bf93cacad083c0\nDEBUG:root:    signtures:\nDEBUG:root:        Signature made 2019-02-06 22:39:57 using key ID 9DD1BB948581B0AD\nDEBUG:root:            Richard Davis <crashvb>\nINFO:root:Signature check passed.\n```\n\nReplicate both images to a local repository\n\n```bash\n$ docker pull registry:5000/crashvb/base:ubuntu\nubuntu: Pulling from crashvb/base\n3b37166ec614: Download complete\n504facff238f: Download complete\nebbcacd28e10: Download complete\nc7fb3351ecad: Download complete\n2e3debadcbf7: Download complete\na5396a146776: Download complete\n6389d93ef5c7: Download complete\ne05442215521: Download complete\nf4ed07aa21a9: Download complete\ne41e7b47a71d: Download complete\nae19c1f4b6b1: Download complete\nDigest: sha256:8acac09a29bb9364dca10cce18e7d2fd4f83cb495a8519af585b56bcfeba03ca\nStatus: Downloaded newer image for registry:5000/crashvb/base:ubuntu\n```\n\n```bash\n$ docker pull registry:5000/crashvb/base:ubuntu_signed\nubuntu_signed: Pulling from crashvb/base\n3b37166ec614: Already exists\n504facff238f: Already exists\nebbcacd28e10: Already exists\nc7fb3351ecad: Already exists\n2e3debadcbf7: Already exists\na5396a146776: Already exists\n6389d93ef5c7: Already exists\ne05442215521: Already exists\nf4ed07aa21a9: Already exists\ne41e7b47a71d: Already exists\nae19c1f4b6b1: Already exists\nDigest: sha256:36e6e7cae412993ba19c0cf9a4583d1988e7668b5ce8e959f1915aabd0bb3bb2\nStatus: Downloaded newer image for registry:5000/crashvb/base:ubuntu_signed\n```\n\n```bash\n$ docker images --format=\"{{.ID}}\" registry:5000/crashvb/base:ubuntu\n8ff76ab7ecbe\n```\n\n```bash\n$ docker images --format=\"{{.ID}}\" registry:5000/crashvb/base:ubuntu_signed\nd9e31c5898fe\n```\n\n### Environment Variables\n\n| Variable | Default Value | Description |\n| ---------| ------------- | ----------- |\n| DSV\\_CREDENTIALS\\_STORE | ~/.docker/config.json | The docker credentials store. |\n| DSV\\_DEFAULT\\_REGISTRY | index.docker.io | The dockerhub registry API endpoint. |\n| DSV\\_DOCKERHUB\\_AUTH | auth.docker.io | The dockerhub authentication endpoint. |\n| DSV\\_GPG\\_DATASTORE | ~/.gnupg | The GnuPG home directory. |\n| DSV\\_GPG\\_LOG\\_ERRORS | | If defined, errors from gnupg will be logged. |\n| DSV\\_KEYID | _undefined_ | Identifier of the signing key. For GnuPG this is the keyid. For PKI this is the path to PEM encoded private key. |\n| DSV\\_KEYPASS | \"\" | The corresponding key passphrase. |\n| DSV\\_KEYTYPE | GPG | The signature type. Either GPG or PKI.\n| DSV\\_PKI\\_DATASTORE | ~/.dsv.pem | The PKI key store and trust store (concatenated PEM entities). |\n\n\n## Development\n\n[Source Control](https://github.com/crashvb/docker-sign-verify)\n\n\n",
    "bugtrack_url": null,
    "license": "Apache License 2.0",
    "summary": "A utility that can be used to sign and verify docker images.",
    "version": "2.1.0",
    "project_urls": {
        "Bug Reports": "https://github.com/crashvb/docker-sign-verify/issues",
        "Homepage": "https://github.com/crashvb/docker-sign-verify",
        "Source": "https://github.com/crashvb/docker-sign-verify"
    },
    "split_keywords": [
        "docker",
        "docker-sign",
        "docker-verify",
        "integrity",
        "sign",
        "signatures",
        "verify"
    ],
    "urls": [
        {
            "comment_text": "",
            "digests": {
                "blake2b_256": "bd53e3e33128490c1a251f80282154c1d310ae6d9959915cb0bf35df954880bf",
                "md5": "d3986cbb3678b221a21bf9e637275e08",
                "sha256": "b10a9494d995f1365b34ba61f063f00f553078b044a52308b71e729a12c834bc"
            },
            "downloads": -1,
            "filename": "docker_sign_verify-2.1.0-py3-none-any.whl",
            "has_sig": false,
            "md5_digest": "d3986cbb3678b221a21bf9e637275e08",
            "packagetype": "bdist_wheel",
            "python_version": "py3",
            "requires_python": null,
            "size": 56786,
            "upload_time": "2024-08-18T01:07:33",
            "upload_time_iso_8601": "2024-08-18T01:07:33.024483Z",
            "url": "https://files.pythonhosted.org/packages/bd/53/e3e33128490c1a251f80282154c1d310ae6d9959915cb0bf35df954880bf/docker_sign_verify-2.1.0-py3-none-any.whl",
            "yanked": false,
            "yanked_reason": null
        },
        {
            "comment_text": "",
            "digests": {
                "blake2b_256": "88e1ea469b057a2a7010cc2e4dc7dcf438325148fc193a1b3972813307852c4b",
                "md5": "621ade45b43d38566d8878284c77edc2",
                "sha256": "71a9b9ef32957564371001a53d958392e9f51711fdc2df77751c41c88bf3d5e8"
            },
            "downloads": -1,
            "filename": "docker_sign_verify-2.1.0.tar.gz",
            "has_sig": false,
            "md5_digest": "621ade45b43d38566d8878284c77edc2",
            "packagetype": "sdist",
            "python_version": "source",
            "requires_python": null,
            "size": 47628,
            "upload_time": "2024-08-18T01:07:34",
            "upload_time_iso_8601": "2024-08-18T01:07:34.356022Z",
            "url": "https://files.pythonhosted.org/packages/88/e1/ea469b057a2a7010cc2e4dc7dcf438325148fc193a1b3972813307852c4b/docker_sign_verify-2.1.0.tar.gz",
            "yanked": false,
            "yanked_reason": null
        }
    ],
    "upload_time": "2024-08-18 01:07:34",
    "github": true,
    "gitlab": false,
    "bitbucket": false,
    "codeberg": false,
    "github_user": "crashvb",
    "github_project": "docker-sign-verify",
    "travis_ci": false,
    "coveralls": false,
    "github_actions": true,
    "lcname": "docker-sign-verify"
}
        
Elapsed time: 0.29658s