magus v0.3.0 is out. See what's new
¶ View markdown source · ✎ Suggest an edit
2 min read

cosign

The cosign spell forks the Sigstore cosign CLI to sign, attest, and verify artifacts. Signing and attestation pass --yes for non-interactive (CI) use.

Runtime name: cosign (source spells/cosign/)

Version probe (cosign): cosign version

Passing arguments to ops

Every op is invoked as cosign["<op>"](ctx, opts?). The first argument is the target's context, which is what carries the execution environment; the optional options map shapes the command itself:

Key Type Description Source
args [str] Extra arguments appended to the resolved command. Omit it and a bare cosign["<op>"]() forwards magus run <target> -- <extra> to the tool automatically; pass it to set the arguments explicitly, which replaces that passthrough. source
stdin str Data written to the command's standard input. source

Working directory and environment are NOT options: they ride the context, as cosign["<op>"](ctx.withCwd("sub")) and cosign["<op>"](ctx.withEnv({"CGO_ENABLED": "0"})). Only the context reaches the cache key, so an option-table cwd or env would change what the tool did while the key said otherwise - passing either as an option is an error.

Charms (the :charm suffix, e.g. magus run test:rw) are orthogonal: they patch the base argv, while these options add to it. See Charms.

cosign-attest

Command: cosign attest --yes

Example

// cosign-attest attaches a signed attestation; pass the predicate file, its type,
// and the image reference.
import "magus";
import "magus/spell/cosign";

magus\project({ "spells": [cosign] });

export fun attest(ctx: magus\Context, args: [str]) > void {
    cosign["cosign-attest"](ctx, { "args": ["--predicate", "sbom.json", "--type", "cyclonedx", "app:latest"] });
}

cosign-sign

--yes skips the interactive transparency-log confirmation so signing/attesting runs unattended; the caller appends the target reference and flags.

Command: cosign sign --yes

Example

// cosign-sign signs an artifact keyless (--yes for CI); pass the image reference
// to sign, so `magus run sign` forks `cosign sign --yes app:latest`.
import "magus";
import "magus/spell/cosign";

magus\project({ "spells": [cosign] });

export fun sign(ctx: magus\Context, args: [str]) > void {
    cosign["cosign-sign"](ctx, { "args": ["app:latest"] });
}

cosign-verify

Command: cosign verify

Example

// cosign-verify checks an image's signature; pass the image reference (add
// --certificate-identity / --certificate-oidc-issuer for keyless verification).
import "magus";
import "magus/spell/cosign";

magus\project({ "spells": [cosign] });

export fun verify(ctx: magus\Context, args: [str]) > void {
    cosign["cosign-verify"](ctx, { "args": ["app:latest"] });
}
auto-generatedcosignspellsigstoresigningsupply-chaintools
Last updated (a103255f)
Earlier changes on this page (4)

Full history ↗ · Blame source ↗

Glossary

Project

A directory magus recognizes as a unit of work (it has a magusfile); the unit of caching, scheduling, and dependency tracking. See workspace.

Target

A named operation (build, test, ...) you invoke with magus run <target>; it may compose a spell's tool-native operations and depend on other targets. See targets.

Spell

A language/runtime adapter (e.g. go, md) that maps generic targets onto a toolchain's real commands. See spells.

Charm

An execution modifier attached with : (lint:rw) that changes how a target runs, not which one; the built-in rw flips a check-only target to mutate in place, and ci always strips it. See charms.

Ward

A coded diagnostic that inspects a resolved op and nudges or blocks an anti-pattern before it runs. See wards.

Buzz

The language magusfiles are written in (the .buzz engine). See engines.

Cache

The content-addressed store magus consults before running a target, so unchanged work is skipped. See cache.

CI

An ordinary magusfile-defined target you compose yourself with magus\needs - magus does not hardcode its stages. Magus.RunCI treats it specially only in that it strips the rw charm, it is the anchor magus affected ci keys off, and a selected scope with no project declaring it is a load error rather than a silent no-op. See targets.

Conventions

Placeholders

Angle brackets mark a value you replace with your own - never type the brackets:

magus run <target>
magus completion <shell>    # e.g. bash, zsh, fish

<target>, <path>, <shell>, <name> and the like are stand-ins, not literal text.