Giters
in-toto
/
attestation
in-toto Attestation Framework
Geek Repo:
Geek Repo
Github PK Tool:
Github PK Tool
Stargazers:
202
Watchers:
21
Issues:
125
Forks:
47
in-toto/attestation Issues
Ignoring unrecognised fields?
Closed
a year ago
Comments count
1
Add 'attester.id' field (or similar) to statement layer.
Closed
a year ago
Comments count
15
No way to bind attestations in attestation bundle together
Updated
a year ago
Comments count
16
Create Statement v1
Closed
a year ago
Comments count
14
Add contributing guidelines
Closed
a year ago
Comments count
3
Clean up documentation
Closed
8 months ago
Comments count
3
A Source Attestation for recording metadata about source code
Updated
a year ago
Comments count
9
Fix link to SLSA Attestation Model docs
Closed
a year ago
Add generic object/artifact reference attestation field type
Closed
a year ago
Comments count
10
Add evidence field to the statement layer
Updated
a year ago
Comments count
1
Need better clarity on bundle filename for chains of attestations
Closed
2 years ago
Comments count
5
Does "subjects" and "materials" field support multi-arch images?
Closed
5 months ago
Comments count
5
Determine types of artifacts in subjects and materials fields
Closed
2 years ago
Comments count
1
Link to known attestations in repository
Updated
10 months ago
Comments count
11
Proposal: support subjects that have no digests
Closed
a year ago
Comments count
1
Only require 1 approver
Closed
2 years ago
Comments count
3
Add support for Cyclonedx as a predicate type
Closed
a year ago
Comments count
17
Should the predicateType's hash be included as a digest?
Closed
8 months ago
Comments count
13
Attestation Context\Meta-data\Meta-information
Updated
2 years ago
Defining a generalized predicate format for "human reviews" of artifacts
Updated
2 years ago
Comments count
27
Add support for SCAI predicate
Closed
a year ago
Comments count
2
Question: Support of multiple SBOM formats.
Closed
a year ago
Comments count
7
Authenticated how?
Updated
a year ago
Comments count
2
Support attestation revocation
Updated
a year ago
Comments count
2
How do attestations change what verifiers are expected to support?
Updated
3 years ago
A good TLDR for attestations
Updated
3 years ago
Comments count
1
Explain why we recommend PURL and SPDX Download Location
Updated
3 years ago
Create an index of predicates
Closed
a year ago
Comments count
1
[Help Wanted] Determine attestation format for vuln scans
Closed
8 months ago
Comments count
52
Where to put implementations?
Closed
3 years ago
Comments count
4
Move Provenance to SLSA repo
Closed
3 years ago
Comments count
6
Add redirect from https://in-toto.io/Attestation/v0.1 to the spec
Closed
a year ago
Comments count
5
Create a protobuf schema for Statement & Predicates
Closed
a year ago
Comments count
3
Create a predicate to convey information about source control system security settings.
Updated
2 years ago
Comments count
14
Timestamp somewhere?
Closed
a year ago
Comments count
11
Container Native Provenance Predicate?
Closed
3 years ago
Comments count
38
Question: Why is the protocol included on _type and predicateType?
Closed
3 years ago
Comments count
10
Provenance: consider splitting `builder.id`
Closed
2 years ago
Comments count
2
Define a "attestation bundle" data structure and naming convention
Closed
3 years ago
Comments count
6
Consideration: where to place "workload" attestations
Updated
3 years ago
Comments count
2
Provide guidance on level of granularity for `recipe`
Closed
2 years ago
Comments count
1
Explain differences from Grafeas BuildProvenance
Closed
2 years ago
Comments count
1
Add ability to differentiate between different types of `materials`
Closed
2 years ago
Comments count
1
Consider adding a "digest kind" and/or "content type" to subject
Closed
a year ago
Comments count
12
Ability to refer to one attestation from another
Closed
a year ago
Comments count
4
Provide better guidance on `materials`
Closed
2 years ago
Comments count
6
Provide better guidance on `subject.name`
Updated
3 years ago
Explain "completeness"
Closed
2 years ago
Comments count
1
Clarify that any envelope can be used
Updated
5 months ago
Comments count
1
Provenance: remove `mediaType` and `tags` in favor of extensions
Closed
3 years ago
Previous
Next