chainguard-dev / vex

vexctl is a tool to attest VEX impact statements
Apache License 2.0
44 stars 12 forks source link

Store the VEX source data in an OCI registry #9

Open puerco opened 2 years ago

puerco commented 2 years ago

Currently, we read the known VEX data for a project from a simple file. At some point I think we should store it in the registry using a schema that makes it easy to find to update and use when attesting. @jdolitsky thinks we should use the new OCI Reference Types and I'm down for it.