Difference between revisions of "Provenance attestation"
Jump to navigation
Jump to search
Line 1: | Line 1: | ||
[[Provenance]] attestation | [[Provenance]] attestation | ||
* https://docs.docker.com/build/metadata/attestations/slsa-provenance/ | * https://docs.docker.com/build/metadata/attestations/slsa-provenance/ | ||
+ | |||
+ | Provenance attestations include facts about the build process, including details such as: | ||
+ | * Build timestamp | ||
+ | * Build parameters and environment | ||
+ | * Version control metadata | ||
+ | * Source code details | ||
+ | *Materials (files, scripts) consumed during the build | ||
Revision as of 19:21, 27 October 2024
Provenance attestation
Provenance attestations include facts about the build process, including details such as:
- Build timestamp
- Build parameters and environment
- Version control metadata
- Source code details
- Materials (files, scripts) consumed during the build
- Provenance attestation (https://slsa.dev/provenance/v0.2) with max mode exists
- slsa.dev
- SBOM Attestations
See also
Advertising: