-
Notifications
You must be signed in to change notification settings - Fork 511
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Feature - Record scorecard card scans into Rekor #1200
Comments
This would be pretty easy to do! do you mean the scorecard scans from the cron jobs? |
As of now in the cronjobs later in the GitHub Actions because we can utilize the OIDC Provider in GitHub Actions and probably in cronjob (if not KMS) Or should we wait for in-toto attestations #1121 (comment) before we do this? |
in-toto attestations for scans in-toto/attestation#58 |
We can use the existing in-toto attestations. |
@naveensrinivasan are you still working on this? |
This issue is stale because it has been open for 60 days with no activity. |
Is your feature request related to a problem? Please describe.
The scorecard scans should attest that the scan was done to a repository state (commit SHA) or binary release. https://rekor.sigstore.dev https://github.com/sigstore/rekor
The text was updated successfully, but these errors were encountered: