Skip to content

adds slsa attestations page - #7

Merged
paulsavoie merged 20 commits into
mainfrom
slsa-attestations
Apr 27, 2026
Merged

adds slsa attestations page#7
paulsavoie merged 20 commits into
mainfrom
slsa-attestations

Conversation

@paulsavoie

Copy link
Copy Markdown
Member

No description provided.

Comment thread docs/artifact-configuration/reference.md Outdated
Comment thread docs/_data/tables/artifact-configuration.yml Outdated
<artifact-configuration xmlns="http://signpath.io/artifact-configuration/v1">
<zip-file>
<pe-file path="myApp.exe">
<include-in-provenance />

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

add a second file in this example to make this <include-in-provenance> more clear? but IDK.

Comment thread docs/artifact-configuration/reference.md Outdated
Comment thread docs/artifact-configuration/reference.md Outdated
Comment thread docs/artifact-configuration/reference.md Outdated
Comment thread docs/artifact-configuration/reference.md Outdated

SignPath creates SLSA attestation in three distinct steps:

1. SignPath Pipeline Integrity gathers and verifies relevant information from a supported _origin_ CI/CD system

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"Pipeline Integrity" is not explained anywhere? rly keep it here?

same with "DeepSign" and "SignPath Attest"

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That's from Stefan, didn't want to remove it - and also don't want to wait for the product names to really be out there. I can live with it for now, added an inline comment

Comment thread docs/origin-verification/slsa-attestations.md Outdated
> * Trust all hosted CI/CD system supported by SignPath or verify that the _origin_ system is one that you trust.
> * SignPath cannot guarantee that the CI/CD system is actually operated in a safe way and safe from manipulation.
>
> Clients do _not_ need to trust the publisher for these security properties, as they are evaluated on the _control plane_ without relying on the provider's configuration. However, SignPath can only make technical evaluations and enforce technical policies. The quality of the source code (including build scripts) and code reviews is still up to the publisher.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"control plane" wird nur hier auf dieser seite verwendet, aber nicht erklärt.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ja, stimmt. Lasse ich auch mal, auch von Stefan

@paulsavoie
paulsavoie merged commit 6356e72 into main Apr 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants