You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
At the time of writing this, there are some options for validating the final provenance like tag, branch, etc.1 We (w/@Dentrax) thought that maybe people could write Rego policies against them to do the same validation. Instead of adding every flag to the command, people can write a Rego policy to define what they want to validate, similar to what we did in cosign project.2
If the verifier was able to accept the same CUE or rego policies that cosign can verify that would be ideal. I don't know how specific they need to be to cosign though.
At the time of writing this, there are some options for validating the final provenance like tag, branch, etc.1 We (w/@Dentrax) thought that maybe people could write Rego policies against them to do the same validation. Instead of adding every flag to the command, people can write a Rego policy to define what they want to validate, similar to what we did in cosign project.2
Footnotes
https://github.com/slsa-framework/slsa-verifier/blob/main/options/options.go#L4 ↩
https://github.com/sigstore/cosign/pull/641 ↩
The text was updated successfully, but these errors were encountered: