* Package name : golang-github-moby-policy-helpers Version : 0.0~git20260901.72f704e (upstream has no tags) Upstream Contact: Tõnis Tiigi <tonistiigi@gmail.com> * URL : https://github.com/moby/policy-helpers * License : Apache-2.0 Programming Lang: Go Description : image signature verification helpers for Moby and BuildKit This Go module verifies Sigstore signatures and SLSA provenance attestations attached to container images and build artifacts, for the image policy features of the Docker engine and BuildKit. . It walks an image's referrers to find the signature chain, verifies the Sigstore bundles against the Sigstore public-good trust root, which it keeps up to date through TUF starting from an embedded copy, and reports the signer's certificate identity and timestamps. It also recognises Docker Hardened Images and verifies them with their own public key. Binary package: golang-github-moby-policy-helpers-dev (import path github.com/moby/policy-helpers). Why: docker.io 29.8.1 (in preparation; unstable has 28.5.2, work in progress at https://salsa.debian.org/mendezr/docker/-/tree/wip/moby-v29) imports it from engine/daemon/daemon.go and engine/daemon/containerd/ (image_pull.go, image_identity.go, service.go); engine/go.mod pins v0.0.0-20260901142052-72f704e6cdb6, the commit packaged here. BuildKit v0.33.0 imports it from source/containerimage/source.go. The docker.io update is needed by github.com/anchore/stereoscope (ITP https://bugs.debian.org/1135909). I intend to maintain this package within the Debian Go Packaging Team.