slsa-verifier
slsa-verifier copied to clipboard
bug: check entryPoint is non empty for GCB provenance
GCB allows triggering builds via CLI, in which case the config is passed as an RPC input, but no in code. We should check the entryPoint is not empty.
I'll wait for https://github.com/slsa-framework/slsa-verifier/pull/572 to land since it defines new functions to retrieve provenance information, including the entryPoint.
#572 is merged.