Description of the changes being introduced by the pull request:
Update apt transport to perform in-toto supply chain verification using link metadata fetched from remote rebuilders and a local configuration file that specifies the location of
local layout,
local layout gpg key,
remote rebuilders
The PR also updates the test script which mocks all entities that communicate with the intoto apt transport for testing purposes, i.e.
apt
http transport
rebuilder servers
Please verify and check that the pull request fulfills the following
requirements:
Fixes issue #:
3 (among other things), uses/closes #4
Description of the changes being introduced by the pull request: Update apt transport to perform in-toto supply chain verification using link metadata fetched from remote rebuilders and a local configuration file that specifies the location of
The PR also updates the test script which mocks all entities that communicate with the intoto apt transport for testing purposes, i.e.
Please verify and check that the pull request fulfills the following requirements: