-
Notifications
You must be signed in to change notification settings - Fork 130
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Support SLSA 1.0 provenance storage #889
Comments
Issues go stale after 90d of inactivity. /lifecycle stale Send feedback to tektoncd/plumbing. |
Hi @chitrangpatel I would like to follow up on the status of this ticket since it has been marked as stale. Has support for storage for OCI been added? I see that the documentation states that "Tekton Chains supports both SLSA v0.2 and v1.0 provenance for both task-level and pipeline-level provenance." |
A lot of these should apply as is to the new provenance type as well. We haven't verified that though. I |
@chitrangpatel thank you for your response. I can confirm that we were able to store attestations as OCI (GCR) in the SLSA v1.0 format. |
Thank you for reporting that! I've checked that off the list. |
The formatting for slsa v1.0 provenance was added in Chains Release 0.17.0. However, before declaring that Chains now produces SLSA v1.0 provenance, we need to add support for storage.
This issue highlights all the storage options we need to add support for:
/kind feature
The text was updated successfully, but these errors were encountered: