slsa-framework / slsa

Supply-chain Levels for Software Artifacts
https://slsa.dev
Other
1.48k stars 212 forks source link

content: Add attested build environments level requirements #1051

Open marcelamelara opened 1 month ago

marcelamelara commented 1 month ago

This (draft) PR introduces the following spec changes associated with #975. Per https://github.com/slsa-framework/slsa/issues/975#issuecomment-1773315232 and https://github.com/slsa-framework/slsa/issues/975#issuecomment-1852559183 the spec enhancements are being proposed as a new Build track level. The spec changes introduced in this PR are meant to be complementary to possible requirements being developed in parallel in #977 .

Spec changes:

Part 1 of #975 CC @chkimes

netlify[bot] commented 1 month ago

Deploy Preview for slsa ready!

Name Link
Latest commit a531f5057febb5fdf8c290f27aa215a5599bba35
Latest deploy log https://app.netlify.com/sites/slsa/deploys/664e9c3086f1d600081e0be5
Deploy Preview https://deploy-preview-1051--slsa.netlify.app
Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

marcelamelara commented 2 weeks ago

@mdwood-intel @pdxjohnny PTAL