slsa-framework / slsa-github-generator

Language-agnostic SLSA provenance generation for Github Actions
Apache License 2.0
396 stars 118 forks source link

[feature] Add more tests for TRW's specific commit sha1 for v0.2 #2079

Open laurentsimon opened 1 year ago

laurentsimon commented 1 year ago

We need to verify that that generated provenance is correct. Unit tests and scheduled tests within this repo. The feature was introduced in https://github.com/slsa-framework/slsa-github-generator/pull/2078

laurentsimon commented 1 year ago

this should include verification for both v0.2 and v1.0 predicates

laurentsimon commented 1 year ago

Removing this issue from the BYOB milestone, because we want to support v1.0 first.