slsa-framework/slsa

Clarify what is within the scope of the build agent/executor measurement

Opened this issue · 0 comments

Do the "build agent" and "build executor" include their configuration and any subprocesses they execute, or just a single binary that is noted as an entrypoint?

Originally posted by @deeglaze in #1115 (comment)