Reference¶
The Go API (types, functions, signatures) is published at pkg.go.dev/gitlab.com/phpboyscout/go/artifacts and its trust subpackage. That page is generated from the source, so it cannot drift; nothing here duplicates it.
What lives here is the part pkg.go.dev cannot describe: the shape of the channel this package talks to, and the bounds it operates within.
In this section¶
- Channel layout: URL structure, manifest format, signature format
- Limits and defaults: timeouts, size ceilings, paths and modes
Sentinel errors¶
Twelve, matched with errors.Is. What to do about each is in
Handle failures.
| Error | Means |
|---|---|
ErrWithdrawn |
the signed index withdraws this artefact-version; terminal |
ErrNotListed |
the index does not approve this artefact-version |
ErrIndexUnavailable |
the index could not be fetched, so no approval decision was made |
ErrStaleIndex |
the index verified but is expired, issued in the future, or older than one already accepted |
ErrMalformedIndex |
signature good, contents are not an index |
ErrTrustUnavailable |
the trust anchors could not be established, so nothing was checked |
ErrUnverified |
bytes arrived and could not be trusted: bad signature, a manifest the index does not name, or a bad digest or length, deliberately not distinguished |
ErrIdentityMismatch |
a genuine manifest for a different namespace, artefact or version |
ErrNotFound |
no such artefact-version, or no such file in its manifest |
ErrUnsigned |
the manifest exists and its signature does not |
ErrMalformedManifest |
signature good, contents are not a manifest: a broken publisher, not an attack |
ErrInvalidIdentifier |
a name, version or filename breaks the identifier grammar |
Configuration mistakes (no verifier, no cache) return plain errors rather than sentinels. A caller branching on those is branching on its own bug.