tektoncd / chains

Supply Chain Security in Tekton Pipelines
Apache License 2.0
240 stars 125 forks source link

internalParameters update in SLSAv1.0 provenance #839

Open joejstuart opened 1 year ago

joejstuart commented 1 year ago

The SLSA documentation says the internalParameters maps to the predicate.invocation.environment from the v0.2 attestation. In the v0.2 attestation that chains created, the environment contains the taskRun and pipelineRun annotations and labels. Should this information be carried forward to the v1.0 attestation?

chitrangpatel commented 1 year ago

Our goal was to take something like the build type design doc and convert it to markdown and host it under https://tekton.dev/docs/chains/.

joejstuart commented 1 year ago

Our goal was to take something like the build type design doc and convert it to markdown and host it under https://tekton.dev/docs/chains/.

Thanks for the reply! I think it's in response to this issue? https://github.com/tektoncd/chains/issues/838. Also, please let me know if I can help with this issue or #838

chitrangpatel commented 1 year ago

Our goal was to take something like the build type design doc and convert it to markdown and host it under https://tekton.dev/docs/chains/.

Thanks for the reply! I think it's in response to this issue? #838. Also, please let me know if I can help with this issue or #838

Yes, you're right. I will move this comment there.

tekton-robot commented 9 months ago

Issues go stale after 90d of inactivity. Mark the issue as fresh with /remove-lifecycle stale with a justification. Stale issues rot after an additional 30d of inactivity and eventually close. If this issue is safe to close now please do so with /close with a justification. If this issue should be exempted, mark the issue as frozen with /lifecycle frozen with a justification.

/lifecycle stale

Send feedback to tektoncd/plumbing.

tekton-robot commented 8 months ago

Stale issues rot after 30d of inactivity. Mark the issue as fresh with /remove-lifecycle rotten with a justification. Rotten issues close after an additional 30d of inactivity. If this issue is safe to close now please do so with /close with a justification. If this issue should be exempted, mark the issue as frozen with /lifecycle frozen with a justification.

/lifecycle rotten

Send feedback to tektoncd/plumbing.