• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

mindersec / minder / 35018273281
62%
main: 62%

Build:
Build:
LAST BUILD BRANCH: add-metrics-tests
DEFAULT BRANCH: main
Ran 15 Sep 2026 08:22PM UTC
Jobs 1
Files 363
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

15 Sep 2026 05:19PM UTC coverage: 61.975%. First build
35018273281

push

github

web-flow
Expose OCI image identity in artifact ingester (#6775)

* Expose OCI image identity in artifact ingester

Preserve artifact version tags (previously discarded) and surface an
imageIdentity (registry, repository, tags, digest) alongside each
verification result so Rego rules can key off exact image references.

getAndFilterArtifactVersions now returns the full ArtifactVersion
objects instead of bare digest strings, since Sha alone lost the tags.
Repository is built as owner/name when Owner is populated (GHCR, where
owner is a distinct registry path segment), or just name otherwise
(e.g. DockerHub, where the owner/namespace is baked into the
provider's configured base URL rather than tracked per artifact).
Registry is populated only when the provider implements the OCI
interface; GitHub/GHCR is left empty since ghcr.io isn't guaranteed to
be correct for every GitHub-backed registry.

Part of mindersec#6774. Raw manifest/index preservation (the other half of
that issue's scope) is held pending confirmation from the maintainer on how
it should apply to providers that don't implement the OCI interface.

* Document buildRepository's Owner assumption; assert multi-tag identity

Note that buildRepository's owner/name split assumes only GitHub
populates artifact.Owner today, since no DockerHub/Quay properties
package sets it, and this needs revisiting if that changes.

Also assert Identity.Tags in the multi-tag test case, which is the
one that actually exercises multi-tag preservation but wasn't
checking it.

* Resolve GHCR registry as GitHub's default, per PR review

getRegistryForProvider previously left Registry empty for GitHub-backed
artifacts since GitHub doesn't implement the OCI interface. Per
intelligent-ears' review on #6775, treat GitHub as a second explicit
branch and resolve it to ghcr.io, mirroring the default the sigstore
verifier itself already assumes (newContainerAuth in
internal/verifier/sigstore/container/container.go).

Adds coverage: an e... (continued)

42 of 45 new or added lines in 2 files covered. (93.33%)

21993 of 35487 relevant lines covered (61.97%)

40.33 hits per line

Uncovered Changes

Lines Coverage ∆ File
2
68.08
internal/engine/ingester/artifact/artifact.go
1
42.27
internal/verifier/sigstore/container/container.go
Jobs
ID Job ID Ran Files Coverage
1 35018273281.1 15 Sep 2026 08:22PM UTC 363
61.97
GitHub Action Run
Source Files on build 35018273281
  • Tree
  • List 363
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #35018273281
  • 447c13e3 on github
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc