slsa-framework / slsa-github-generator

Language-agnostic SLSA provenance generation for Github Actions
Apache License 2.0
413 stars 127 forks source link

[feature] Support for Ko builder #590

Open laurentsimon opened 2 years ago

laurentsimon commented 2 years ago

Can use the PoC I created https://github.com/laurentsimon/slsa-github-generator-ko It should not be too difficult.

laurentsimon commented 2 years ago

sidenote: think about https://github.com/slsa-framework/slsa-github-generator/issues/684 when building this builder.

Also think about the SBOM generated by ko, and try to include these in the final attestation. (Probably not needed for first implementation)