Skip to content

Commit

Permalink
certification: remove registry
Browse files Browse the repository at this point in the history
We should remove the registry in preperation to move it to a dedicated
repository.
  • Loading branch information
Joshua Mulliken committed Feb 1, 2023
1 parent 004214b commit 4453e6f
Show file tree
Hide file tree
Showing 3 changed files with 5 additions and 31 deletions.
5 changes: 0 additions & 5 deletions docs/_data/spec_v1-0/certification-registry.yml

This file was deleted.

21 changes: 0 additions & 21 deletions docs/spec/v1.0/certification-registry.md

This file was deleted.

10 changes: 5 additions & 5 deletions docs/spec/v1.0/certification.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,13 +2,14 @@

## **TODO**

- [ ] Create a certification registry repo and add links in this doc.
- [ ] Create a self-certification questionnaire.
- [ ] Add a link to the SLSA Self-Certification Questionnaire.

## Overview

> User's looking for certifications for a particular build system can find them
> on the [Certification Registry](certification-registry.md).
> on the Certification Registry (**TODO:** create repo for certification registry and link here).
The SLSA Framework defines a series of levels that describe increasing security
guarantees. The certification process is intended to verify that a build system
Expand All @@ -24,7 +25,7 @@ trust they can place in a build system. The following tiers are defined:
### Tier 0 - No evidence of conformance

> **Note:** If a build system is not listed in the
> [Certification Registry](certification-registry.md), you should assume that it
> Certification Registry (**TODO:** create repo for certification registry and link here), you should assume that it
> is in Tier 0.
The Tier 0 trust tier is the lowest level of trust. Build systems in this tier
Expand All @@ -36,7 +37,7 @@ build system before using it.
### Tier 1 - Self-certified conformance

> Build systems in this trust tier are listed in the
> [Certification Registry](certification-registry.md).
> Certification Registry (**TODO:** create repo for certification registry and link here).
Tier 1 signifies that a build system owner has self-certified their build system
to a particular SLSA level. This certification is intended to be a reasonable
Expand All @@ -55,8 +56,7 @@ The self-certification process includes the following steps:
and publishes it on their website.
3. The build system owner publishes their public key to a public key server.
4. The build system owner submits a pull request to add their build system to
the [Certification Registry](certification-registry.md). **[TODO] provide PR
template link**
the Certification Registry (**TODO:** create repo for certification registry and link here).

### Tier 2 - Third-party verified conformance [TODO]

Expand Down

0 comments on commit 4453e6f

Please sign in to comment.