Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
content: draft: Add mitigation for compromised build tooling (#1251)
This threat can be mitigated in a number of ways, here I address it in the simplest one, verifying the tooling prior to use. You can also imagine resolving it by recording the digests in the provenance, and propagating VSAs so that downstream verifiers can verify recursively, but that's pretty complicated. You can also resolve this with the attested build environments track, but I don't think we should mention that here until it's finalized? Or maybe we can point to it now as 'coming soon'? fixes #1184 --------- Signed-off-by: Tom Hennen <[email protected]> Signed-off-by: Tom Hennen <[email protected]> Co-authored-by: Marcela Melara <[email protected]> Co-authored-by: Trishank Karthik Kuppusamy <[email protected]>
- Loading branch information