-
> File new TO DO issue: Add discussion about how to distinguish provenance and rights management. What hooks can we provide to rights management platforms?
_Originally posted by @scouten-adobe in h…
-
### What would you like to be added?
Ratify publishes images to GHCR. Ratify should generate and attach SBOM + provenance metadata to the published images.
### Anything else you would like to add?
…
-
## Overview
Develop way to track and report provenance of datasets. Where did the data come from, what's been done to it to get to current state of dataset.
## Sub-issues
1. #147: This will inclu…
-
The current code for the RefMaker is going to assume you have exactly one set of parameters for how to choose images that go into a reference.
There would be, however, situations where we may want t…
-
E.g.: Integrate operating system level with function level
-
This issue is part of the Strict Provenance Experiment - https://github.com/rust-lang/rust/issues/95228
I left a few little ` FIXME(strict_provenance_magic)` comments around core::ptr to indicate p…
-
- [ ] need provenance image asset
- [ ] need rollup image asset
- [ ] need rollup calculus algorithm
-
As ORT takes transparency and reproducibility of results serious, currently only local directories that are under version control can serve as the input to the analyzer. This is because for such "work…
-
_[This ticket helps track progress towards developing a particular feature in BODS where changes or revisions to the standard may be required. It should be placed on the [BODS Feature Tracker](https:/…
lgs85 updated
1 month ago
-
> **NOTE:** this issue was initially posted on the https://github.com/slsa-framework/slsa-github-generator repo and transferred here without modification.
Hello :wave:
Not really an issue but ra…