policy-controller
policy-controller copied to clipboard
Add support for slsa provenance verification
Description
We need to explore how to verify the existence of SLSA provenance attached to container images. It is currently possible to inspect SLSA attestations however this could be simplified by using the slsa-provenance-verifier.
Hi @hectorj2f, by slsa-provenance-verifier, are you referring to this: https://github.com/slsa-framework/slsa-verifier?
/assign @haydentherapper is this still open ?
Hey, I'm not a maintainer on policy-controller, but I think this is intertwined with ongoing work from @codysoyland already.