This Working Group standardizes the in-toto framework for securing the integrity of software supply chains. As such, it focuses on grouping, versioning and encoding the specification document and extensions to the specification (e.g., through ITE documents).
The working group shall oversee the standardization of core in-toto components, including:
- Metadata Formats: the layout metadata format that defines a supply chain, the link metadata format that records evidence of each step.
- Workflow definitions and Terminology: the roles (project owner, functionaries, and clients).
- Processing guidelines: The verification workflow, including signature validation, artifact rules, inspection guidelines, and sublayout identification.
In addition to the core components, the working group shall promote extensions as defined by the ITE standardization process and include as part of the standards family.
This working group shall not define the specific elements described above, but rather only carry out activities to encode documents as standards-friendly documents. Thus, the working group shall not standardize:
- specific language implementations & their architectures: these are handled by their specific working groups within in-toto.
- key management and distribution components (e.g., archivista): these are handled by users of in-toto.
- Attestation Predicate Registries: these are curated and handled by the attestation working group.
Any changes of Scope are not retroactive.