ossf / wg-securing-software-repos

OpenSSF Working Group on Securing Software Repositories
Other
84 stars 15 forks source link

Don't commit to a specific attestation predicate #26

Closed woodruffw closed 1 year ago

woodruffw commented 1 year ago

Per discussion in https://github.com/ossf/wg-securing-software-repos/pull/20#discussion_r1269906912: this gives us the flexibility to pick a different attestation format (or invent a new one), so long as it's compatible with the SLSA attestation model.