chainsaw bundle

Manage the offline intelligence bundle

Manage the offline intelligence bundle

SubcommandWhat it does
chainsaw bundle verifyVerify a bundle’s manifest, hashes, and signature
chainsaw bundle [command]

Manage the air-gapped intelligence bundle that powers offline policy evaluation (CHAINSAW_OFFLINE=1). The bundle is a signed tarball shipped alongside the chainsaw-proxy release; see docs/OPERATIONS.md for the refresh cadence and per-provider matrix.

chainsaw bundle verify

Verify a bundle’s manifest, hashes, and signature

chainsaw bundle verify <path> [flags]

Flags

FlagTypeDefaultDescription
--allow-unverifiedbool—Exit 0 even when signature verification was skipped via CHAINSAW_INTEL_BUNDLE_SKIP_VERIFY. Dev/test only — it makes ‘verify’ report success on a bundle nothing checked.
--strictbool—Require full Sigstore authenticity (Fulcio cert chain + Rekor inclusion + OIDC issuer + signer identity), not just digest binding. Equivalent to CHAINSAW_INTEL_BUNDLE_STRICT_VERIFY=1. Off by default until the chainsaw-release-signer bot cutover; today’s digest-only bundles fail –strict by design.

The global flags apply here too.