You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Given the language in slsa-framework/slsa#525 we should revisit the parameters that we set in generated SLSA provenance.
According to the newer language, parameters should be any inputs that are sent over the trust boundary. The PR describes them as "independent" and "external" to the builder. In that light, all of the inputs given to the reusable workflows should be recorded in parameters and likely we should record config file inputs as well.
The text was updated successfully, but these errors were encountered:
How we record config files might need some thought. Perhaps just recording the relative path to the file is ok since the repo and digest is recorded in the invocation?
Given the language in slsa-framework/slsa#525 we should revisit the
parameters
that we set in generated SLSA provenance.According to the newer language,
parameters
should be any inputs that are sent over the trust boundary. The PR describes them as "independent" and "external" to the builder. In that light, all of the inputs given to the reusable workflows should be recorded inparameters
and likely we should record config file inputs as well.The text was updated successfully, but these errors were encountered: