in-toto / witness

Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.
https://witness.dev
Apache License 2.0
416 stars 60 forks source link

Add tags to git attestor #231

Closed colek42 closed 1 year ago

colek42 commented 1 year ago

The git attestor should query the tags for the commit and add it as a field on the attestation

colek42 commented 1 year ago

Author: []string Committer: []string Date: datetime Commit message: string SHA1 SHA256 Signatures: [][]byte Remotes: [][]byte