Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
resourceUri SHOULD match the download URI
When verifying VSAs consumers are expected to match the resourceUri with the 'expected value' but the spec doesn't currently indicate how that expected value is to be determined. In this change we suggest the resourceUri be set to the URI the consumer will fetch the artifact from. If it's set to something else the producer MUST tell the user how to determine the expected value. fixes #1212 Signed-off-by: Tom Hennen <tomhennen@google.com>
- Loading branch information