From 483f46e12b77a419b7fbe043a4d0074fba2cba36 Mon Sep 17 00:00:00 2001 From: "Jose I. Paris" Date: Fri, 2 May 2025 19:09:41 +0200 Subject: [PATCH 1/3] change example for SLSA Signed-off-by: Jose I. Paris --- docs/examples/contracts/slsa/github.yaml | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/docs/examples/contracts/slsa/github.yaml b/docs/examples/contracts/slsa/github.yaml index aead5fd6a..ec43744bf 100644 --- a/docs/examples/contracts/slsa/github.yaml +++ b/docs/examples/contracts/slsa/github.yaml @@ -1,15 +1,12 @@ -# Require a container image reference, SLSA provenance and include SLSA complicance verification +# Require a container image reference and include SLSA complicance verification schemaVersion: v1 materials: - type: CONTAINER_IMAGE name: container - - type: SLSA_PROVENANCE - name: slsa-attestation policyGroups: - ref: slsa-checks with: - provenance_material_name: slsa-attestation runner: GITHUB_ACTION - issuer: "GitHub" \ No newline at end of file + environment: "managed" \ No newline at end of file From 550da618c49dfe5ec550202b868f42dda3fc66e6 Mon Sep 17 00:00:00 2001 From: "Jose I. Paris" Date: Fri, 2 May 2025 19:21:57 +0200 Subject: [PATCH 2/3] remove environment Signed-off-by: Jose I. Paris --- docs/examples/contracts/slsa/github.yaml | 1 - 1 file changed, 1 deletion(-) diff --git a/docs/examples/contracts/slsa/github.yaml b/docs/examples/contracts/slsa/github.yaml index ec43744bf..2a10eb0a6 100644 --- a/docs/examples/contracts/slsa/github.yaml +++ b/docs/examples/contracts/slsa/github.yaml @@ -9,4 +9,3 @@ policyGroups: - ref: slsa-checks with: runner: GITHUB_ACTION - environment: "managed" \ No newline at end of file From 4471317ac62dd04f6f6f583b229e68c9bc708f28 Mon Sep 17 00:00:00 2001 From: "Jose I. Paris" Date: Fri, 2 May 2025 19:22:39 +0200 Subject: [PATCH 3/3] add comment Signed-off-by: Jose I. Paris --- docs/examples/contracts/slsa/github.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/examples/contracts/slsa/github.yaml b/docs/examples/contracts/slsa/github.yaml index 2a10eb0a6..228febe27 100644 --- a/docs/examples/contracts/slsa/github.yaml +++ b/docs/examples/contracts/slsa/github.yaml @@ -8,4 +8,4 @@ materials: policyGroups: - ref: slsa-checks with: - runner: GITHUB_ACTION + runner: GITHUB_ACTION # or GITLAB_PIPELINE