Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update slsa-provenance predicate to v0.2 #1054

Merged
merged 2 commits into from
Nov 23, 2021

Conversation

priyawadhwa
Copy link
Contributor

Update the in-toto-golang dependency to generate the slsa-provenance predicate at version v0.2. This way chains can update to v0.2 as well without conflicting with the pinned version for in-toto-golang in cosign!

Signed-off-by: Priya Wadhwa priyawadhwa@google.com

This dep update also required updating the go-tuf dependency, so there are some bug fixes in the go-tuf code in this PR as well.

Signed-off-by: Priya Wadhwa <priyawadhwa@google.com>
@priyawadhwa priyawadhwa force-pushed the slsa-provenance-v0.2 branch 5 times, most recently from bf1572f to 8660314 Compare November 23, 2021 00:41
Signed-off-by: Priya Wadhwa <priyawadhwa@google.com>
@dlorenc dlorenc merged commit 98cf544 into sigstore:main Nov 23, 2021
@github-actions github-actions bot added this to the v1.4.0 milestone Nov 23, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants