Skip to content

Can security attestations be limited to specific manufacturers or can anyone use them if they exist? #307

@tobie

Description

@tobie

Asked by @MathiasSchindler in the ORC mailing list:

Is an attestation issued as a voluntary security attestation under an article 25 system bound to the software alone or also to the recipient? For instance, if Manufacturer A gets an attestation for libfoo 0.9.6c, can Manufacturer B, who uses the exact same component, also use that attestation for their own due diligence (assuming for the purpose of this question that B learned of the existence of this attestation)? If the answer is 'no, it's recipient-bound,' could you help me understand what law or rule creates that restriction?

Metadata

Metadata

Assignees

No one assigned

    Labels

    FAQattestationsSecurity attestation requirementsdue-diligenceDue diligence obligations for manufacturers

    Type

    No type

    Projects

    Status

    Needs triaging

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions