chainsaw bundle
Manage the offline intelligence bundle
Copies the raw Markdown source of this guide, for pasting into an LLM or notes.
Manage the offline intelligence bundle
| Subcommand | What it does |
|---|---|
chainsaw bundle verify | Verify a bundle’s manifest, hashes, and signature |
chainsaw bundle [command]
Manage the air-gapped intelligence bundle that powers offline policy evaluation (CHAINSAW_OFFLINE=1). The bundle is a signed tarball shipped alongside the chainsaw-proxy release; see docs/OPERATIONS.md for the refresh cadence and per-provider matrix.
chainsaw bundle verify
Verify a bundle’s manifest, hashes, and signature
chainsaw bundle verify <path> [flags]
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--allow-unverified | bool | — | Exit 0 even when signature verification was skipped via CHAINSAW_INTEL_BUNDLE_SKIP_VERIFY. Dev/test only — it makes ‘verify’ report success on a bundle nothing checked. |
--strict | bool | — | Require full Sigstore authenticity (Fulcio cert chain + Rekor inclusion + OIDC issuer + signer identity), not just digest binding. Equivalent to CHAINSAW_INTEL_BUNDLE_STRICT_VERIFY=1. Off by default until the chainsaw-release-signer bot cutover; today’s digest-only bundles fail –strict by design. |
The global flags apply here too.