Present Provisioning Infra lets one provision 1. Endorsements ( like Trust Anchors) and 2. Reference Values ( like Software Components) independently as they could appear from different supply chain actors. How does one ensures that the data submitted in 2. does correctly relates to 1. and is not a dis-jointed/incorrect information provisioned in the Veraison Provisioning Pipeline.
This issue tracks the enhancement required to validate the same at the time of submission so that the user can be sent a suitable error message in case such discrepancy is identified.
Present Provisioning Infra lets one provision 1. Endorsements ( like Trust Anchors) and 2. Reference Values ( like Software Components) independently as they could appear from different supply chain actors. How does one ensures that the data submitted in 2. does correctly relates to 1. and is not a dis-jointed/incorrect information provisioned in the Veraison Provisioning Pipeline.
This issue tracks the enhancement required to validate the same at the time of submission so that the user can be sent a suitable error message in case such discrepancy is identified.