-
Notifications
You must be signed in to change notification settings - Fork 229
Issues: slsa-framework/slsa
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
Clarify 'dependencies complete' at L4
clarification
Clarification of the spec, without changing meaning
slsa 4
Applies to a SLSA 4 requirement
#326
opened Mar 16, 2022 by
TomHennen
v0.2: Simplify terminology and concepts: "platform" vs "service", "trusted person", "non-falsifiable", etc.
clarification
Clarification of the spec, without changing meaning
How does SLSA fit into broader supply chain security?
clarification
Clarification of the spec, without changing meaning
#276
opened Jan 26, 2022 by
MarkLodato
Add Bad Design as a supply chain scenario
blocked
Blocked by another issue
clarification
Clarification of the spec, without changing meaning
#249
opened Dec 14, 2021 by
moshe-apiiro
Project maintainer package vs. Distribution package
applied ruling
Documentation of how a specific case maps into SLSA
clarification
Clarification of the spec, without changing meaning
Define more cases for well-understood automatic or reviewless merges
clarification
Clarification of the spec, without changing meaning
slsa 4
Applies to a SLSA 4 requirement
#234
opened Nov 30, 2021 by
simonbasle
How to convey build service guarantees via attestations
attestation
Updates to attestation formats
clarification
Clarification of the spec, without changing meaning
#211
opened Nov 8, 2021 by
MarkLodato
Differentiate between "data owner" and "system admin"?
clarification
Clarification of the spec, without changing meaning
slsa 4
Applies to a SLSA 4 requirement
"hermetic" term, ambiguity
clarification
Clarification of the spec, without changing meaning
#60
opened Jun 17, 2021 by
vielmetti
Provide audience-specific "how to" guidance
clarification
Clarification of the spec, without changing meaning
#39
opened May 29, 2021 by
dlorenc
Add rationale and examples for all of the requirements
clarification
Clarification of the spec, without changing meaning
Digital signatures? At least cite sigstore
clarification
Clarification of the spec, without changing meaning
slsa 1
Applies to a SLSA 1 requirement
#15
opened Apr 3, 2021 by
david-a-wheeler
Previous Next
ProTip!
Adding no:label will show everything without a label.