-
Notifications
You must be signed in to change notification settings - Fork 103
Open
Description
In today's in-toto community call while discussing open ITE's we discussed it being useful for both adopters and maintainers to have a collection of different in-toto attestations that exist in the wild.
Some examples I know of:
- SLSA provenance (v0.2) – designed to describe how a subject artefact was produced, with several opaque fields to be defined by buildType:
invocation.parameters,invocation.environmentandbuildConfig - SLSA Verification Summary Attestation (VSA) – summarise verification of a number of SLSA attestations without a (trusting) user having to check, or even have access to, each attestation
- Cosign generic attestation – attest arbitrary data with a timestamp
- Cosign vulnerability attestation – designed for container vulnerability scans, has opaque type for scan results
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels