Skip to content

Reference

The Go API (types, functions, signatures) is published at pkg.go.dev/gitlab.com/phpboyscout/go/artifacts and its trust subpackage. That page is generated from the source, so it cannot drift; nothing here duplicates it.

What lives here is the part pkg.go.dev cannot describe: the shape of the channel this package talks to, and the bounds it operates within.

In this section

Sentinel errors

Twelve, matched with errors.Is. What to do about each is in Handle failures.

Error Means
ErrWithdrawn the signed index withdraws this artefact-version; terminal
ErrNotListed the index does not approve this artefact-version
ErrIndexUnavailable the index could not be fetched, so no approval decision was made
ErrStaleIndex the index verified but is expired, issued in the future, or older than one already accepted
ErrMalformedIndex signature good, contents are not an index
ErrTrustUnavailable the trust anchors could not be established, so nothing was checked
ErrUnverified bytes arrived and could not be trusted: bad signature, a manifest the index does not name, or a bad digest or length, deliberately not distinguished
ErrIdentityMismatch a genuine manifest for a different namespace, artefact or version
ErrNotFound no such artefact-version, or no such file in its manifest
ErrUnsigned the manifest exists and its signature does not
ErrMalformedManifest signature good, contents are not a manifest: a broken publisher, not an attack
ErrInvalidIdentifier a name, version or filename breaks the identifier grammar

Configuration mistakes (no verifier, no cache) return plain errors rather than sentinels. A caller branching on those is branching on its own bug.