slsa-verifier
slsa-verifier copied to clipboard
[feature] inspect option
In certain scenario, a user may not know what the builder is. Example: someone create a monitoring service to monitor provenance changes for packages. The builder may change (and have different levels). An option inspect
would inspect the provenance and return how it was validated (source uri, builder, etc).
This is just something to think about. I don't think it's urgent or needs prioritization at this point.