in-toto / scai-demos

Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools
Apache License 2.0
18 stars 4 forks source link

Add SLSA v0.1 hermetic build evidence example #5

Closed marcelamelara closed 1 year ago

marcelamelara commented 1 year ago

This example shows how SCAI can be used to capture information as evidence for other supply chain metadata. Specifically, this example captures a run-time trace of a SLSA builder, and uses this log as evidence for the hermetic requirement of the SLSA v0.1 spec.