-
Notifications
You must be signed in to change notification settings - Fork 227
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add more example provenance and VSAs #1156
Comments
Linking to example SLSA provenances, VSAs, and tools that can process them is crucial and deserves more attention. Here’s a list of the build types we’ve encountered so far in the Macaron project: Build Types
Additional ResourcesTo further assist users in discovering existing tools that support SLSA, I propose the following:
|
@behnazh-w Re: 2, Github's Artifact Attestation is not yet supported in slsa-verifier, and there may be some disagreement or misunderstanding about whether it is SLSA provenance or not. |
@ramonpetgrave64 I wasn't aware of this potential disagreement. Could you share any discussions or resources on this? |
@behnazh-w Here's an active discussion about a separate issue: cli/cli#9602 (comment) |
Recently @NicoleSchwartz shared this query and these docs to provide example SLSA provenance and VSAs.
It occurred to me that we don't have those examples linked to from this repo, and that would be pretty handy?
We don't exactly have a great place to do that at the moment (though we do index some build types).
Any thoughts on how to make examples like this more discoverable?
The text was updated successfully, but these errors were encountered: