-
-
Notifications
You must be signed in to change notification settings - Fork 249
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Architect a "Verified Reproducible Build Attestation" #3950
Comments
@tellison @smlambert fyi |
Also:
|
An interesting read, this is what I understand from reading their various docs:
I take from that we could maybe:
|
Thanks Shelley, I am going to follow up with some questions to in-toto in their Slack (https://cloud-native.slack.com/archives/CM46K2VT2/p1727340094818479) |
Further research, and references:
|
Option 1: I am currently thinking of this outline architecture:
Future:
|
From talking to members of the in-toto community, their suggestion points to looking at https://github.com/in-toto/witness |
Option 2:
|
Architect a "Verified Reproducible Build Attestation".
Some useful links:
The text was updated successfully, but these errors were encountered: