Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[feature] Document that signed provenance replaces signing artifacts #1880

Open
gabibguti opened this issue Mar 27, 2023 · 0 comments
Open
Labels
type:documentation Improvements or additions to documentation

Comments

@gabibguti
Copy link

Is your feature request related to a problem? Please describe.
It is not clear through the SLSA 3 Go Builder documentation if it signs both the provenance and the artifacts. As I understand, SLSA 3 Go Builder signs the provenance and does not sign the artifacts. That's because a signed provenance replaces the need of signed artifacts since the hash of the artifacts is included in the provenance subjects. There may be other reasons to sign the artifacts but not to "prove" the integrity of the artifacts as it's already done by the signed provenance.

Describe the solution you'd like
Document that SLSA 3 Go Builder signs the provenance and does not sign the artifacts, and that there's no need to sign the artifacts since the hash of the artifacts is included in the provenance subjects.

Describe alternatives you've considered
None.

Additional context
None.

@gabibguti gabibguti added status:triage Issue that has not been triaged type:feature New feature or request labels Mar 27, 2023
@ianlewis ianlewis added type:documentation Improvements or additions to documentation and removed type:feature New feature or request status:triage Issue that has not been triaged labels Mar 27, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type:documentation Improvements or additions to documentation
Projects
None yet
Development

No branches or pull requests

2 participants