fix: extract digest from provenance when repo path is provided but digest is not provided from the user #711
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This Pull Request fixes the issue mentioned here - #698 (comment)
This can be seen as a continuation of #708
Description
When the user provide only a repository path from
--repo-path
to Macaron without providing--digest
. The expected behavior is that Macaron will use the repository path from the user provided--repo-path
and try to extract the digest extracted from provenance if it's available (provided from user via--provenance-file
or obtained from the PURL using provenance finder).This combination will be handled inside this block
macaron/src/macaron/slsa_analyzer/analyzer.py
Lines 702 to 708 in e214326
However, its logic doesn't extract the commit hash from provenance, which leave
Analyzer.AnalysisTarget.digest
as empty.Solution
--digest
, the digest will not be extracted from the provenance.