v1.1.0
What's Changed
- Adds support to verify using an embedded certificate in the DSSE envelope. This avoids using a Redis index for searching for the signing certificate
To learn how to use it, see Verification of Provenance
This is meant to be used for GitHub workflow SLSA generation. Builders are located in slsa-github-generator.