Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document detailed attested build environment verification flow #1169

Open
marcelamelara opened this issue Sep 30, 2024 · 2 comments
Open

Document detailed attested build environment verification flow #1169

marcelamelara opened this issue Sep 30, 2024 · 2 comments
Labels
build-environment-track Issues/PRs related to the SLSA BuildEnv track

Comments

@marcelamelara
Copy link
Contributor

The current build environment track levels spec only describes verification at a very high level. As part of the track, we need to write up a dedicated verification document that lays out all of the attestations/data needed to verify the integrity of a build environment, the policies used to verify against, attestation/policy storage, and responsible actors for each aspect.

This was also raised in
#1115 (comment)
#1115 (comment)

@marcelamelara
Copy link
Contributor Author

@tiziano88
Copy link

cc @thmsbinder @ipetr0v @conradgrobler perhaps some of the oak building blocks may be useful here

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
build-environment-track Issues/PRs related to the SLSA BuildEnv track
Projects
Status: 🆕 New
Development

No branches or pull requests

2 participants