tektoncd / chains

Supply Chain Security in Tekton Pipelines
Apache License 2.0
245 stars 126 forks source link

Update buildType in SLSAV1.0 provenance #838

Open joejstuart opened 1 year ago

joejstuart commented 1 year ago

Feature request

The buildType is described as "An identifier for the template for how to perform the build and interpret the parameters and dependencies." And says the URI should resolve to a human-readable specification describing the externalParameters, internalParameters and resolvedDependencies. Right now the buildType URI is https://tekton.dev/chains/v2/slsa. I'm proposing this is updated to reflect either a taskRun or pipelineRun attestation which is similar to v0.2 of the provenance. Also, should the URI be resolvable at this point? I'm wondering what thoughts are on that.

Use case

chitrangpatel commented 1 year ago

Our goal was to take something like the build type design doc and convert it to markdown and host it under https://tekton.dev/docs/chains/.

chitrangpatel commented 1 year ago

We wanted to add this documentation after we had support for storage of the SLSA v1 provenance in Grafeas.

tekton-robot commented 11 months ago

Issues go stale after 90d of inactivity. Mark the issue as fresh with /remove-lifecycle stale with a justification. Stale issues rot after an additional 30d of inactivity and eventually close. If this issue is safe to close now please do so with /close with a justification. If this issue should be exempted, mark the issue as frozen with /lifecycle frozen with a justification.

/lifecycle stale

Send feedback to tektoncd/plumbing.

tekton-robot commented 10 months ago

Stale issues rot after 30d of inactivity. Mark the issue as fresh with /remove-lifecycle rotten with a justification. Rotten issues close after an additional 30d of inactivity. If this issue is safe to close now please do so with /close with a justification. If this issue should be exempted, mark the issue as frozen with /lifecycle frozen with a justification.

/lifecycle rotten

Send feedback to tektoncd/plumbing.