#1149320 ITP: golang-github-moby-policy-helpers -- image signature verification helpers for Moby and BuildKit

#1149320#5
Date:
2026-09-29 12:21:47 UTC
From:
To:
* Package name    : golang-github-moby-policy-helpers
  Version         : 0.0~git20260901.72f704e (upstream has no tags)
  Upstream Contact: Tõnis Tiigi <tonistiigi@gmail.com>
* URL             : https://github.com/moby/policy-helpers
* License         : Apache-2.0
  Programming Lang: Go
  Description     : image signature verification helpers for Moby and BuildKit

 This Go module verifies Sigstore signatures and SLSA provenance
 attestations attached to container images and build artifacts, for the
 image policy features of the Docker engine and BuildKit.
 .
 It walks an image's referrers to find the signature chain, verifies the
 Sigstore bundles against the Sigstore public-good trust root, which it
 keeps up to date through TUF starting from an embedded copy, and reports
 the signer's certificate identity and timestamps. It also recognises
 Docker Hardened Images and verifies them with their own public key.

Binary package: golang-github-moby-policy-helpers-dev (import path
github.com/moby/policy-helpers).

Why: docker.io 29.8.1 (in preparation; unstable has 28.5.2, work in
progress at https://salsa.debian.org/mendezr/docker/-/tree/wip/moby-v29)
imports it from engine/daemon/daemon.go and engine/daemon/containerd/
(image_pull.go, image_identity.go, service.go); engine/go.mod pins
v0.0.0-20260901142052-72f704e6cdb6, the commit packaged here. BuildKit
v0.33.0 imports it from source/containerimage/source.go. The docker.io
update is needed by github.com/anchore/stereoscope (ITP
https://bugs.debian.org/1135909).

I intend to maintain this package within the Debian Go Packaging Team.