Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feature: use gh "Artifact Attestations" #227

Open
thomas-fossati opened this issue May 25, 2024 · 0 comments
Open

feature: use gh "Artifact Attestations" #227

thomas-fossati opened this issue May 25, 2024 · 0 comments
Labels
enhancement New feature or request

Comments

@thomas-fossati
Copy link
Contributor

thomas-fossati commented May 25, 2024

G-H artifact attestation is now in public beta.

It seems like something we should enable to provide relying parties high quality and granular information about the veraison instance they are accepting results from.

The produced attestation could be added (or linked by) the .well-known/veraison API and/or to the produced EAR in the verifier-id object.

All of this should be associated with some kind of release process that, at the moment, we don't have. The closest we have though is the monthly tag, so I suggest we piggy-back on that G-H action to build and publish the services containers and create the associated attestations.

@thomas-fossati thomas-fossati added the enhancement New feature or request label May 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant