project-oak / oak

Meaningful control of data in distributed systems.
Apache License 2.0
1.3k stars 112 forks source link

Always name the provenance file attestation.intoto, fixing wildcard error #4991

Closed jul-sh closed 6 months ago

jul-sh commented 6 months ago

Previously the provenance was named after the artifact path, which was a problem if that path contained a wildcard.

Now it's named as a constant, like slsa does https://github.com/slsa-framework/example-package/blob/501736af032201ffb1ab20b5021fc38224a1bf79/.github/workflows/e2e.container-based.schedule.main.registry-username-secret.yml#L66

Change-Id: Ia8493efb4614d2b57bd061588988697d14a53ac6