Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Source track attestation claims #1042

Open
laurentsimon opened this issue Apr 8, 2024 · 1 comment
Open

Source track attestation claims #1042

laurentsimon opened this issue Apr 8, 2024 · 1 comment

Comments

@laurentsimon
Copy link
Contributor

laurentsimon commented Apr 8, 2024

Tracking issue for #1037 (comment)

Main comments:

  • The current claims are a mix of policy (who's allowed to review) and facts (who reviewed).
  • The current use case is useful when consumers and producers are the same but does not help for consumption of other (open source) projects

Current suggestion: Separate policy and fact claims, like we do in build track.

@marcelamelara
Copy link
Contributor

Also to consider in this context is the currently open PR on human review predicates: in-toto/attestation#151

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: 🆕 New
Development

No branches or pull requests

2 participants