Issues
- 0
cleanup verifying-source content
#1242 opened by zachariahcox - 0
Add figure for build environment lifecycle
#1245 opened by marcelamelara - 0
Add figures for build environment track spec
#1165 opened by marcelamelara - 0
- 4
- 0
fill in or cut this bit about merge trains
#1239 opened by zachariahcox - 0
verifying-source should discuss verifying all the commits directly on a protected ref
#1238 opened by zachariahcox - 8
- 9
- 3
- 2
- 3
Add search to published doc
#1232 opened by shalper - 1
Fix broken link - SUSE source
#1230 opened by shalper - 1
Safe Expunging and 'legal' restrictions
#1222 opened by TomHennen - 0
Improve strength of Source Level 3
#1216 opened by TomHennen - 1
Clarify 'Tamper with provenance or VSA' threat
#1223 opened by TomHennen - 1
- 1
Grant Pavel triage access
#1218 opened by marcelamelara - 1
Threats overview page needs to be updated for 1.1
#1208 opened by TomHennen - 3
- 1
Clarify why builder level is meaningful in threats
#1215 opened by TomHennen - 1
TODO: Need to fill out description of "(I) Usage" in threat and mitigation section
#1182 opened by lehors - 1
- 2
- 4
- 1
- 2
- 0
Clarify that it's the CI's control plane that gives it privileged access
#1211 opened by marcelamelara - 0
- 8
- 2
TODO: Need mitigation description for "Include a vulnerable dependency" threat
#1183 opened by lehors - 2
TODO: Need mitigation description for "Software producer intentionally submits bad code" threat
#1178 opened by lehors - 0
Fix threats.md's outdated links
#1189 opened by TomHennen - 0
TODO: Need mitigation description for "Platform admin abuses privileges" threat
#1179 opened by lehors - 0
Document implementation of the BuildEnv track for non-Linux environments
#1198 opened by marcelamelara - 0
Add reference to TPM 2.0 spec defining "Quote"
#1197 opened by marcelamelara - 0
Explicitly mention that BuildEnv L2 build platform MUST verify the SLSA Provenance OR its VSA.
#1196 opened by marcelamelara - 0
Explicitly note that the build image should be included in the external parameters field of Provenance for artifacts built on BuildEnv platforms
#1195 opened by marcelamelara - 0
- 0
Update threats.md to discuss SLSA Source Track
#1187 opened by TomHennen - 2
final source track copy edit
#1172 opened by zachariahcox - 0
- 1
Link build environment terms to their definitions
#1177 opened by marcelamelara - 4
Add more example provenance and VSAs
#1156 opened by TomHennen - 1
source track: clarify definition of "contributor" and recommend best practices for SCPs.
#1162 opened by zachariahcox - 0
- 0
- 0
Attested build environment verification policy should have provenance/integrity guarantees
#1168 opened by marcelamelara - 0
Clarify what is within the scope of the build agent/executor measurement
#1164 opened by marcelamelara - 0
verifying-source levels should match final source-requirements terminology
#1163 opened by zachariahcox