adds slsa attestations page - #7
Merged
Merged
Conversation
stefan-wenig
had a problem deploying
to
website-fqa/main
August 22, 2025 17:06 — with
GitHub Actions
Failure
extended buildType and builder.id URIs added infos about trust, attestation vs code signing cleanup and typos
…entation into slsa-attestations
internal/external params restored
ulrichb
reviewed
Apr 22, 2026
| <artifact-configuration xmlns="http://signpath.io/artifact-configuration/v1"> | ||
| <zip-file> | ||
| <pe-file path="myApp.exe"> | ||
| <include-in-provenance /> |
Contributor
There was a problem hiding this comment.
add a second file in this example to make this <include-in-provenance> more clear? but IDK.
|
|
||
| SignPath creates SLSA attestation in three distinct steps: | ||
|
|
||
| 1. SignPath Pipeline Integrity gathers and verifies relevant information from a supported _origin_ CI/CD system |
Contributor
There was a problem hiding this comment.
"Pipeline Integrity" is not explained anywhere? rly keep it here?
same with "DeepSign" and "SignPath Attest"
Member
Author
There was a problem hiding this comment.
That's from Stefan, didn't want to remove it - and also don't want to wait for the product names to really be out there. I can live with it for now, added an inline comment
| > * Trust all hosted CI/CD system supported by SignPath or verify that the _origin_ system is one that you trust. | ||
| > * SignPath cannot guarantee that the CI/CD system is actually operated in a safe way and safe from manipulation. | ||
| > | ||
| > Clients do _not_ need to trust the publisher for these security properties, as they are evaluated on the _control plane_ without relying on the provider's configuration. However, SignPath can only make technical evaluations and enforce technical policies. The quality of the source code (including build scripts) and code reviews is still up to the publisher. |
Contributor
There was a problem hiding this comment.
"control plane" wird nur hier auf dieser seite verwendet, aber nicht erklärt.
Member
Author
There was a problem hiding this comment.
ja, stimmt. Lasse ich auch mal, auch von Stefan
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.