in-toto / community

in-toto is a framework to secure the software supply chain.
https://in-toto.io/
69 stars 10 forks source link

Exclude adopter from CLOMonitor check #23

Closed matglas closed 6 months ago

matglas commented 6 months ago

There is an exemptions option for CLO Monitor and I think we could exclude the adopters check because why would we need to mention adopters on the community repo. 😄

For reference this is how its done: https://github.com/cncf/clomonitor/blob/main/docs/metadata/.clomonitor.yml

Mention the check and the reason.

adityasaky commented 6 months ago

Can we point to in-toto/friends?

matglas commented 6 months ago

Yes that could be a good reference for community adopter. Good suggestion!

matglas commented 6 months ago

@adityasaky I created a PR with this small addition. Would you be able to review it?

adityasaky commented 6 months ago

I do not have maintainer bit on this repository anymore. I've flagged the ITSC over on slack to take a look.