Skip to content

Conversation

@TomHennen
Copy link
Contributor

The prior language made it sound like the SCS was responsible for only performing expunging for legal requests. That's not reasonable from a technical perspective. With this update we clarify that it's the organization's responsibility to ensure this bar is met.

I had thought about adding a whole section of requirements just for the organization, but that seems out of scope for this change and it would be a lot of work. We can still do so if we want, but not here.

fixes #1222

The prior language made it sound like the SCS was responsible for
only performing expunging for legal requests.  That's not
reasonable from a technical perspective.  With this update we
clarify that it's the _organization's_ responsibility to ensure
this bar is met.

fixes slsa-framework#1222

Signed-off-by: Tom Hennen <[email protected]>
@netlify
Copy link

netlify bot commented Dec 3, 2024

Deploy Preview for slsa ready!

Name Link
🔨 Latest commit 9fa4997
🔍 Latest deploy log https://app.netlify.com/sites/slsa/deploys/674f7125efd350000817a2d1
😎 Deploy Preview https://deploy-preview-1252--slsa.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

@TomHennen TomHennen changed the title clarify orgs are responsible for what gets expunged content: draft: clarify orgs are responsible for what gets expunged Dec 3, 2024
Copy link
Collaborator

@zachariahcox zachariahcox left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

100%, this makes sense. Thanks!
@TomHennen I think we should come through separately and talk about organization vs. "producer" terminology, based on our discussion from a couple weeks ago at the spec sync.

@TomHennen TomHennen merged commit e68ed5d into slsa-framework:main Dec 4, 2024
5 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

Safe Expunging and 'legal' restrictions

3 participants