You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
content: build L3 requires complete external parameters, not provenance
It was raised in the review of 1.1-RC2 that build L3 does not require
provenance to be complete. Instead, it only requires the external
parameters to be complete. With this requirement, it is still sufficient
to mitigate an attack by SSH on the artifact as the verifier would be
able to ensure that the external parameters meet expectations.
ref: slsa-framework#1298 (comment)
Signed-off-by: arewm <[email protected]>
0 commit comments