veraison / services

Attestation verification services based on Veraison components
Apache License 2.0
25 stars 14 forks source link

Enhance Tooling to check the validity of provisioning submissions #66

Open yogeshbdeshpande opened 1 year ago

yogeshbdeshpande commented 1 year ago

Present Provisioning Infra lets one provision 1. Endorsements ( like Trust Anchors) and 2. Reference Values ( like Software Components) independently as they could appear from different supply chain actors. How does one ensures that the data submitted in 2. does correctly relates to 1. and is not a dis-jointed/incorrect information provisioned in the Veraison Provisioning Pipeline.

This issue tracks the enhancement required to validate the same at the time of submission so that the user can be sent a suitable error message in case such discrepancy is identified.

yogeshbdeshpande commented 1 year ago

Issue migrated here from: https://github.com/veraison/veraison/issues/155