cnabio / signy

Go implementation for CNAB content trust verification using TUF, Notary, and in-toto
MIT License
31 stars 11 forks source link

Minimal example of a software supply chain #74

Closed trishankatdatadog closed 4 years ago

radu-matei commented 4 years ago

This is excellent! I would assume we want to also add a document / update the readme before merging, right?

radu-matei commented 4 years ago

This is of course non-blocking for this PR - but is there anything used here (potentially in the securesystemslib wheel) that is not implemented in Go?

trishankatdatadog commented 4 years ago

Ok, I consider this case closed. Can I get a ✅?

I would assume we want to also add a document / update the readme before merging, right?

Not yet: there will be another PR that will make use of these scripts.