in-toto / witness

Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.
https://witness.dev
Apache License 2.0
416 stars 60 forks source link

in-toto conformance tracking issue #240

Open colek42 opened 1 year ago

colek42 commented 1 year ago

As part of the donation process to in-toto, we need to ensure that Witness meets the proposed in-toto specification. This issue is meant to track and discuss the tasks that need to be completed.

[ ] Change policy language to match ITE-10 [ ] Switch from an attestation collection to an attestation bundle [ ] Generate SLSA attestation. Most of the attributes for SLSA are going to be in the CI provider attestation and the command run attestation.

Questions: