sigstore / model-transparency

Supply chain security for ML
Apache License 2.0
117 stars 33 forks source link

Custom timestamping servers #205

Open laurentsimon opened 5 months ago

laurentsimon commented 5 months ago

This would require a URL (+ optionally an expected identity?) to be configured

mihaimaruseac commented 2 months ago

Should this be handled by the signing infra instead of the library?

haydentherapper commented 2 months ago

+1, this is on the roadmap for sigstore-python

FYI @woodruffw

di commented 2 months ago

https://github.com/sigstore/sigstore-python/issues/349 is the relevant issue.

woodruffw commented 2 months ago

Yep! We have that queued up for our current phase of work, so we'll have an update on signing API side support shortly 🙂