-
Notifications
You must be signed in to change notification settings - Fork 225
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
content: draft: define how downstream users can verify the SLSA source track level of revisions #1094
Commits on Jul 10, 2024
-
Initial draft of a 'source attestation'.
Just focusing on how to communicate levels to downstream users. Future updates can include guidance for how to verify. Open question: should this live here or someplace else? refs slsa-framework#1071 Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for aa087ad - Browse repository at this point
Copy the full SHA aa087adView commit details -
Configuration menu - View commit details
-
Copy full SHA for 6ebf749 - Browse repository at this point
Copy the full SHA 6ebf749View commit details -
Configuration menu - View commit details
-
Copy full SHA for 2b076ab - Browse repository at this point
Copy the full SHA 2b076abView commit details -
Configuration menu - View commit details
-
Copy full SHA for 48f5301 - Browse repository at this point
Copy the full SHA 48f5301View commit details -
Configuration menu - View commit details
-
Copy full SHA for d028178 - Browse repository at this point
Copy the full SHA d028178View commit details -
allow other properties in verifiedLevels
Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for da726cd - Browse repository at this point
Copy the full SHA da726cdView commit details -
resourceUri does not need refs anymore
Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for 0c2d8af - Browse repository at this point
Copy the full SHA 0c2d8afView commit details
Commits on Jul 12, 2024
-
Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for a310289 - Browse repository at this point
Copy the full SHA a310289View commit details -
Configuration menu - View commit details
-
Copy full SHA for 1c51364 - Browse repository at this point
Copy the full SHA 1c51364View commit details -
add instructions on how to verify
Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for 9b05f90 - Browse repository at this point
Copy the full SHA 9b05f90View commit details -
Configuration menu - View commit details
-
Copy full SHA for 62d9375 - Browse repository at this point
Copy the full SHA 62d9375View commit details
Commits on Jul 25, 2024
-
Update docs/spec/draft/source-requirements.md
Co-authored-by: Zachariah Cox <zachariahcox@github.com> Signed-off-by: Tom Hennen <TomHennen@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 9c1b891 - Browse repository at this point
Copy the full SHA 9c1b891View commit details -
clarify tamper-proof properties, start section on evidence
Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for a540709 - Browse repository at this point
Copy the full SHA a540709View commit details -
Merge branch 'source_attestation' of github.com:TomHennen/slsa into s…
…ource_attestation
Configuration menu - View commit details
-
Copy full SHA for d310507 - Browse repository at this point
Copy the full SHA d310507View commit details -
flesh out Source Level Evidence
Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for fd051aa - Browse repository at this point
Copy the full SHA fd051aaView commit details -
Configuration menu - View commit details
-
Copy full SHA for c7e6fd7 - Browse repository at this point
Copy the full SHA c7e6fd7View commit details
Commits on Aug 14, 2024
-
Use standardized language for the source attestations
Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for 88f4fbc - Browse repository at this point
Copy the full SHA 88f4fbcView commit details
Commits on Aug 15, 2024
-
Configuration menu - View commit details
-
Copy full SHA for a50bfb5 - Browse repository at this point
Copy the full SHA a50bfb5View commit details -
clarify attestations are about revisions (for the most part)
Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for c54d16b - Browse repository at this point
Copy the full SHA c54d16bView commit details -
Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for f8b87a4 - Browse repository at this point
Copy the full SHA f8b87a4View commit details
Commits on Aug 16, 2024
-
Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for be65286 - Browse repository at this point
Copy the full SHA be65286View commit details -
Configuration menu - View commit details
-
Copy full SHA for 55b7108 - Browse repository at this point
Copy the full SHA 55b7108View commit details -
Configuration menu - View commit details
-
Copy full SHA for 7916e37 - Browse repository at this point
Copy the full SHA 7916e37View commit details -
Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for 21cadb0 - Browse repository at this point
Copy the full SHA 21cadb0View commit details -
clarify that the source track may define new types of tags
Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for 858d37f - Browse repository at this point
Copy the full SHA 858d37fView commit details
Commits on Aug 20, 2024
-
Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for 72d3163 - Browse repository at this point
Copy the full SHA 72d3163View commit details
Commits on Sep 9, 2024
-
Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for 7f2ad75 - Browse repository at this point
Copy the full SHA 7f2ad75View commit details -
Configuration menu - View commit details
-
Copy full SHA for 3e502cf - Browse repository at this point
Copy the full SHA 3e502cfView commit details -
'full attestation' -> 'provenance attestation'
Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for ef1eb82 - Browse repository at this point
Copy the full SHA ef1eb82View commit details -
clarify when source_branches get set
Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for 63d5c48 - Browse repository at this point
Copy the full SHA 63d5c48View commit details
Commits on Sep 13, 2024
-
Configuration menu - View commit details
-
Copy full SHA for c5ab4a9 - Browse repository at this point
Copy the full SHA c5ab4a9View commit details
Commits on Sep 17, 2024
-
Merge branch 'main' into source_attestation
Signed-off-by: Tom Hennen <TomHennen@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 2844f59 - Browse repository at this point
Copy the full SHA 2844f59View commit details
Commits on Sep 19, 2024
-
Update docs/spec/draft/source-requirements.md
Co-authored-by: Zachariah Cox <zachariahcox@github.com> Signed-off-by: Tom Hennen <TomHennen@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 85a6c7f - Browse repository at this point
Copy the full SHA 85a6c7fView commit details -
Update docs/spec/draft/source-requirements.md
Co-authored-by: Zachariah Cox <zachariahcox@github.com> Signed-off-by: Tom Hennen <TomHennen@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 2de9531 - Browse repository at this point
Copy the full SHA 2de9531View commit details -
attestor->issuer and full->provenance
Signed-off-by: Tom Hennen <tomhennen@google.com>
Configuration menu - View commit details
-
Copy full SHA for 7955011 - Browse repository at this point
Copy the full SHA 7955011View commit details
Commits on Sep 20, 2024
-
Update docs/spec/draft/source-requirements.md
Co-authored-by: Aditya Sirish <8928778+adityasaky@users.noreply.github.com> Signed-off-by: Tom Hennen <TomHennen@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for fb001a4 - Browse repository at this point
Copy the full SHA fb001a4View commit details -
Update docs/spec/draft/source-requirements.md
Co-authored-by: Aditya Sirish <8928778+adityasaky@users.noreply.github.com> Signed-off-by: Tom Hennen <TomHennen@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 01a55cd - Browse repository at this point
Copy the full SHA 01a55cdView commit details -
Configuration menu - View commit details
-
Copy full SHA for 0741877 - Browse repository at this point
Copy the full SHA 0741877View commit details
Commits on Sep 23, 2024
-
Update docs/spec/draft/source-requirements.md
Co-authored-by: Marcela Melara <marcela.melara@intel.com> Signed-off-by: Tom Hennen <TomHennen@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for bd71904 - Browse repository at this point
Copy the full SHA bd71904View commit details -
Update docs/spec/draft/source-requirements.md
Co-authored-by: Marcela Melara <marcela.melara@intel.com> Signed-off-by: Tom Hennen <TomHennen@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for b197be7 - Browse repository at this point
Copy the full SHA b197be7View commit details