You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I think a reasonable mitigation here is something like "Treat build tooling, including OS images, as any other software to be verified prior to use (as described in (G)). This will allow the build platform to detect any modified binaries."
Once the attested build environments track is finalized we can update this mitigation to reference it specifically. CC @marcelamelara
Separately, I'm wondering if this is a reason to move the mitigations from (G) (discussed in #1190, #1191) to (I) since 'usage' is more clearly aligned with this risk than with 'distribution channel'. (Or maybe we can just tweak the mitigation language here to discuss).
No description provided.
The text was updated successfully, but these errors were encountered: