Hey!
Very cool project, and we were curious about your SLSA leveling and roadmapping.
I believe this achieves SLSA 2 when creating attestations for a command that produces a build artifact, since it creates signed attestations with the provided key (and upcoming, Fulcio issued certificates).
I was curious about adding a build demo to achieve SLSA 2, and also, if there's a roadmap or way to achieve SLSA 3. We are also creating builders on slsa-framework/slsa-github-generator and some follow a similar model as this one, but we achieve SLSA 3 through some further isolation requirements.
I'd be happy to add a PR with some README documentation about SLSA. Let me know!
cc @laurentsimon @joshuagl
Hey!
Very cool project, and we were curious about your SLSA leveling and roadmapping.
I believe this achieves SLSA 2 when creating attestations for a command that produces a build artifact, since it creates signed attestations with the provided key (and upcoming, Fulcio issued certificates).
I was curious about adding a build demo to achieve SLSA 2, and also, if there's a roadmap or way to achieve SLSA 3. We are also creating builders on slsa-framework/slsa-github-generator and some follow a similar model as this one, but we achieve SLSA 3 through some further isolation requirements.
I'd be happy to add a PR with some README documentation about SLSA. Let me know!
cc @laurentsimon @joshuagl