slsa-framework / slsa

Supply-chain Levels for Software Artifacts
https://slsa.dev
Other
1.56k stars 227 forks source link

Clarify that it's the CI's control plane that gives it privileged access #1211

Open marcelamelara opened 1 month ago

marcelamelara commented 1 month ago

I think that this statement isn't quite correct. It MAY be the case for build L2, but it MUST NOT be the case for build L3.

Are you considering this from the perspective of the infrastructure running the build platform. If the infrastructure is compromised then this may be the case even if it isn't the case from a running build itself?

_Originally posted by @arewm in https://github.com/slsa-framework/slsa/pull/1115#discussion_r1790324785_