witness
witness copied to clipboard
[Bug]: Using artifactsFrom fails when backrefs don't exist
What steps did you take and what happened:
When using a policy with artifactsFrom
for two or more attestations using only the products and materials attestors (or anything other combination that doesn't generate backrefs), the policy verification fails.
What did you expect to happen:
The policy should pass.
Anything else you would like to add:
Additional details in CNCF Slack: https://cloud-native.slack.com/archives/C068F87H1MF/p1710785890611579