Skip to content

Consider creating an attestation predicate #87

@puerco

Description

@puerco

The security insights data file captures information about the state of the project at a particular commit that is, essentially, a set of claims about it.

I think the project should consider creating a json variant that can be used as a predicate for an ( @in-toto ) attestation. This would allow us to sign and embed the security insights file (for example in a @sigstore bundle) using the existing tooling from those ecosystems.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions