slsa-framework/slsa

Explicitly note that the build image should be included in the external parameters field of Provenance for artifacts built on BuildEnv platforms

Opened this issue · 0 comments

is it also the case that we're including this build image as one of the "components" or dependencies of any artifacts built using the image?
It seems to me that the answer should be "yes", but just checking!

Originally posted by @zachariahcox in #1115 (comment)