slsa-verifier
slsa-verifier copied to clipboard
feat: remove support for special handling of material verification for npm
See https://github.com/slsa-framework/slsa-verifier/pull/521#discussion_r1131610475
I suppose we may want to be able to verify provenance generated during the public beta. So maybe we can check if it's been generated as of a certain date so that we can check this for provenance generated after the GA?
This should work, good idea.
Or maybe there's a versioning in their buildType or something else to identify stable format?
Or maybe there's a versioning in their buildType or something else to identify stable format?
That's maybe an even better idea.
Last time we talk they did not have, ie it was tied to the CLI version. But I think they will change that, so need to follow-up
This will get fixed by #641
#641 is merged.