Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Explicitly mention that BuildEnv L2 build platform MUST verify the SLSA Provenance OR its VSA. #1196

Open
marcelamelara opened this issue Oct 15, 2024 · 0 comments
Labels
build-environment-track Issues/PRs related to the SLSA BuildEnv track

Comments

@marcelamelara
Copy link
Contributor

marcelamelara commented Oct 15, 2024

Prior to the instantiation of a new build environment, the SLSA Provenance for the selected build image MUST be automatically verified.

If it must be, do we have to say what about the image is verified?
Just the VSA's "build level 2" claim about the build image?

Originally posted by @zachariahcox in #1115 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
build-environment-track Issues/PRs related to the SLSA BuildEnv track
Projects
Status: 🆕 New
Development

No branches or pull requests

1 participant