CodeSampleX

Exemple

verify github.com/smallstep/pkcs7.SignerInfoConfig in pkg:golang/github.com/smallstep/pkcs7@v0.0.0-20231024181729-3b98ecc1ca81

sha256:4e914d1140de796668577760aa584c42ed97b59f5274054f5108bb6352bbee92

Ce réseau offre une seule chose : un échantillon qui compile. Il l'a exécuté dans un bac à sable et conservé le reçu signé. Il ne note rien et ne garantit rien : si le même code compile chez vous, il ne l'a pas mesuré. Combien de clés de signature distinctes ont déposé un reçu de contrat réussi. Une seule, c'est l'auteur ; plus d'une signifie que quelqu'un d'autre l'a compilé aussi. Une clé est auto-générée sans identité enregistrée derrière, donc on compte des clés, pas des personnes. MIT-0

Preuves d'exécution

L'environnement déclaré et les exécutions signées sont séparés, pour que vous voyiez exactement ce que cet échantillon a exécuté et où.

Base de preuve
Contrat signé réussi
Reçus de vérification
1
Clés de signature qui l’ont compilé
1
Environnement déclaré linux 24 · ubuntu · glibc 2.39 x64 go

Environnements des exécutions de vérification

Environnement Contrat Étapes Exécution
go 1.26 · linux alpine/x64 · docker ed25519:c1973797be207ac4 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · golang@1golang:1.26-alpine@sha256:28d89ee9cc0f…
2026-08-26

Cas

HOW
Objectif
verify github.com/smallstep/pkcs7.SignerInfoConfig in pkg:golang/github.com/smallstep/pkcs7@v0.0.0-20231024181729-3b98ecc1ca81
Paquets
Symboles
  • github.com/smallstep/pkcs7.SignerInfoConfig
Créé
2026-08-26T12:14:17Z

Contrat

  1. AddSigner accepts SignerInfoConfig with ExtraSignedAttributes and preserves custom signed attributes in DER output
  2. UnmarshalSignedAttribute decodes custom signed attributes added via SignerInfoConfig from parsed PKCS7
  3. UnmarshalSignedAttribute returns error when requested attribute is not present in SignerInfo
  4. Verify validates SignedData signature containing ExtraSignedAttributes configured through SignerInfoConfig
  5. AddSignerChain accepts SignerInfoConfig and includes parent certificate chain alongside custom signed attributes
  6. SignWithoutAttr accepts SignerInfoConfig with ExtraUnsignedAttributes to sign payload without authenticated attributes

Fichiers

  • PROMPT.md
  • csx.json
  • go.mod
  • go.sum
  • main.go
  • spec.json
  • test/contract.go

Télécharger l’artefact source (tar.gz)

Seeder d'origine

anonyme