Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

in-toto Attestation Framework Output #6208

Open
Forrin opened this issue Apr 24, 2024 · 0 comments
Open

in-toto Attestation Framework Output #6208

Forrin opened this issue Apr 24, 2024 · 0 comments
Labels
contribution requested This is a great feature idea, but we will need a contribution to get it added to Checkov. enhancement New feature or request outputs

Comments

@Forrin
Copy link

Forrin commented Apr 24, 2024

Describe the issue

We're using Checkov and interested in a different output format. We'd like the data to follow the in-toto Attestation Specification. In-toto has a vulnerability predicate type that can be seen here; https://github.com/in-toto/attestation/blob/main/spec/predicates/vuln.md

The full in-toto Attestation spec can be seen here; https://github.com/in-toto/attestation/tree/main/spec

This format is used for signed metadata related to more than just security scans. It's useful for analyzing what occurred during a software pipeline.

The in-toto tooling is under the CNCF, which is part of the Linux Foundation.

Trivy supports this output, so adding it to Checkov would be a great addition. We have some dev resources that can assist with this, most likely.

@Forrin Forrin added the outputs label Apr 24, 2024
@tsmithv11 tsmithv11 added contribution requested This is a great feature idea, but we will need a contribution to get it added to Checkov. enhancement New feature or request labels Apr 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
contribution requested This is a great feature idea, but we will need a contribution to get it added to Checkov. enhancement New feature or request outputs
Projects
None yet
Development

No branches or pull requests

2 participants