Skip to content

Inject attestation bundle properties for policy validation #2006

@jiparis

Description

@jiparis

ATTESTATION material type injects the In-toto statement to the policy engine. It would be good if, in addition to the statement:

  • it verifies the attestation bundle (in Sigstore bundle format), including the certificate chain, TSA and signature
  • it passes the signing certificate properties to the policy engine
  • it passes the result of the verification to the policy engine

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions