slsa-framework / slsa

Supply-chain Levels for Software Artifacts
https://slsa.dev
Other
1.53k stars 222 forks source link

Add 'profiles' for the Source Track #1142

Open TomHennen opened 1 week ago

TomHennen commented 1 week ago

@adityasaky suggested that it might make the source track more clear if we

  1. Define 'profiles' for source control systems as a combination of VCS, SCP, attestation issuers, etc...
  2. Each profile should explain how it would meet the various source level requirements
  3. Remove many of the examples that are currently inlined with the requirements themselves

@adityasaky mentions this would be made easier once we define a source control system #1128 .

TomHennen commented 1 week ago

This is probably a good way to address @marcelamelara's comment here https://github.com/slsa-framework/slsa/issues/1128#issuecomment-2360198417