-
Notifications
You must be signed in to change notification settings - Fork 229
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
editorial: Clarify the requirements for self-hosted runners on provenance #989
Conversation
✅ Deploy Preview for slsa ready!
To edit notification comments on pull requests, go to your Netlify site configuration. |
…ance Resolves: slsa-framework#966 Some CI systems allow for users to configure self-hosted runner environments for perform builds and CI analysis. While both the build platform and the self-hosted runners have the ability to affect the build for the resulting artifact, the SLSA Build requirements do not need to be imposed on both systems. This addition to the FAQ is a clarification of the requirements as they relate to the generation of the provenance. Signed-off-by: arewm <[email protected]>
2ca64fa
to
31662a9
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks! Could you make the suggested changes to both files?
Signed-off-by: arewm <[email protected]>
Friendly ping. Could another maintainer or @slsa-framework/slsa-steering-committee member approve (editorial requires two approvals). |
Co-authored-by: Andrew McNamara <[email protected]> Signed-off-by: Michael Lieberman <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This LGTM (for now). We're trying to implement SLSA within our self-hosted GitLab, and will run into this issue soon, so if we find anything more specific, we'll be sure to update it here.
Co-authored-by: Arnaud J Le Hors <[email protected]> Signed-off-by: Mark Lodato <[email protected]>
Signed-off-by: Mark Lodato <[email protected]>
Signed-off-by: Mark Lodato <[email protected]>
Resolves: #966
Some CI systems allow for users to configure self-hosted runner environments for perform builds and CI analysis. While both the build platform and the self-hosted runners have the ability to affect the build for the resulting artifact, the SLSA Build requirements do not need to be imposed on both systems.
This addition to the FAQ is a clarification of the requirements as they relate to the generation of the provenance.