Open
Description
What would you like to be added:
SLSA Attestation Generated with new releases.
Why is this needed:
SLSA's are resources that show evidence that the release consumers receive has not been tampered with during the supply chain process.
Completion requirements:
Implementation of a tool such as https://github.com/kubernetes-sigs/tejolote into the CI process for builds. This will generate the SLSA and attach it to the release.
This enhancement requires the following artifacts:
- Design doc
- API change
- Docs update
The artifacts should be linked in subsequent comments.