You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently, rebuilderd can generate in-toto link metadata when a package is successfully rebuilt. However, in-toto has now introduced support for more specific attestation types, the first of which is SLSA provenance. By updating to this specification, rebuilderd can make more specific claims about the package rebuild process, and can better integrate with other parts of pipelines that are also generating SLSA provenance.
Currently, rebuilderd can generate in-toto link metadata when a package is successfully rebuilt. However, in-toto has now introduced support for more specific attestation types, the first of which is SLSA provenance. By updating to this specification, rebuilderd can make more specific claims about the package rebuild process, and can better integrate with other parts of pipelines that are also generating SLSA provenance.
Linked to: in-toto/in-toto-rs#17
cc @kpcyrd
The text was updated successfully, but these errors were encountered: