slsa-framework / slsa

Supply-chain Levels for Software Artifacts
https://slsa.dev
Other
1.56k stars 227 forks source link

Clarify the connection between the Build and BuildEnv tracks #1210

Open marcelamelara opened 1 month ago

marcelamelara commented 1 month ago

I read this initially as build L2 for the artifacts being generated, not for the build image. I think that this is because I was looking for a connection/commentary on how the BuildEnv and Build tracks support each other. Should we explicitly state this somewhere?

_Originally posted by @arewm in https://github.com/slsa-framework/slsa/pull/1115#discussion_r1790415694_