Conversation
This was referenced Aug 19, 2026
- Adds `AssetKind.attestation` for storing attestation bundles as `PackageVersionAsset` entities in Datastore. - In `packageBackend.publishUploadedBlob`, checks for accompanying `tmp/<guid>.sigstore.json` in the incoming bucket, reads it, and saves it as an attestation asset. - Exposes `GET /api/packages/<package>/versions/<version>/attestation` endpoint for client retrieval. - Updates `PubApiClientExt` and adds unit tests in `upload_test.dart`.
mosuem
force-pushed
the
accept-and-serve-attestations
branch
from
August 20, 2026 08:45
8d92052 to
8cae402
Compare
mosuem
marked this pull request as ready for review
August 28, 2026 12:42
… UploadSignerService
- Revert attestationUrl and attestationFields in UploadInfo, UploadSignerService, and FakeUploadSignerService.
- Support POST requests on /api/packages/versions/newUploadFinish and /api/packages/versions/newUploadFinish/<uploadId> to receive {'attestation': <bundle>} JSON body.
- Update PackageBackend.publishUploadedBlob to accept attestationContent directly rather than reading a separate object from Cloud Storage.
- Expose Client and sendRaw in api_builder to facilitate sending raw and POST finalize requests.
- Update PubApiClientExt.uploadPackageBytes to send attestation bundle in POST finalization request.
- Run codegen and update tests.
'/api/packages/versions/new' now returns an 'attestationUrl' pointing at '/api/packages/versions/newUploadAttestation/<uploadId>', where the client POSTs the attestation bundle before uploading the archive. The bundle is stored in the incoming bucket next to the archive, and read, stored and (later) verified when the upload is finished. 'newUploadFinish' is a GET endpoint again. Also: * reject attestations over maxAttestationContentLength instead of silently truncating them with capContent(), as a truncated bundle could never be verified, and * validate that the upload id is a uuid before deriving an object name from it.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
First PR in stack for package attestation support:
AssetKind.attestationfor storing attestation bundles asPackageVersionAssetentities in Datastore.GET /api/packages/versions/newnow returns anattestationUrl, pointing atPOST /api/packages/versions/newUploadAttestation/<uploadId>. Repositories that do not support publishing with attestations omit the property, which is howpubdetects support before uploading the archive (Support uploading package attestations during publish --from-archive pub#4876).maxAttestationContentLength(128 KB), and that it parses as a JSON object, and then stores it astmp/<guid>.attestation.jsonin the incoming bucket.packageBackend.publishUploadedBlob, reads that object if it is present, saves it as an attestation asset, and removes it together with the other temporary objects.newUploadFinishremains aGET-only endpoint.capContent(): oversized bundles are rejected when they are uploaded rather than silently truncated, since a truncated bundle could never be verified.GET /api/packages/<package>/versions/<version>/attestationendpoint for client retrieval.PubApiClientExtand adds unit tests inupload_test.dart.Since the attestation is uploaded to the app server, publishing with an attestation does not require a second signed upload policy, and therefore no extra
iam.signBlobcall per publish.Verifying the bundle against the uploaded archive (digest and provenance) follows in the next PR in the stack.