You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Feb 21, 2023. It is now read-only.
A feed is a great base for how we can create a series of statements for different artifacts, getting freshness for a receipt/or VEX report.
The current definition likely needs to expand a bit to account for:
What are the versions of a specific artifact
What are all the statements for a version of an artifact
What is the latest statement for a specific contentType of a specific versioned artifact: (eg: what's the latest VEX for the net-monitor:v1 software?
If the contentType is a referenced statement by reference, which stores SBOMs, VEX, Scan Reports, how do we drill into each if they all use the same payload contentType of satementByReference?
The text was updated successfully, but these errors were encountered:
A feed is a great base for how we can create a series of statements for different artifacts, getting freshness for a receipt/or VEX report.
The current definition likely needs to expand a bit to account for:
net-monitor:v1
software?The text was updated successfully, but these errors were encountered: