slsa-verifier icon indicating copy to clipboard operation
slsa-verifier copied to clipboard

Verify provenance from SLSA compliant builders

Results 123 slsa-verifier issues
Sort by recently updated
recently updated
newest added

Rebovatebot is inundating us with hash updates. Until https://github.com/renovatebot/renovate/issues/4404 is landed, I would like to propose that for unprivileged workflows(not write permissions AND no secrets), we use floating tags instead....

area:tooling
type:refactor

c/f https://github.com/slsa-framework/slsa-verifier/pull/132 Version 1.0.0 required a fix after a Rekor change, and this backported fix needs to be added to older releases. In order to support backports, we need to:...

type:discussion

It would be nice to use a logging library or a more standard way to log errors, especially with a good formatting

type:refactor

We can use https://github.com/sigstore/sigstore-maven-plugin as an example.

type:feature

This is something @asraa proposed in the past but I'm not able to find the issue, so creating this one. We currently hardcode builders. It's fine to have a pre-defined...

type:feature

To make the verifier accessible to everyone easily, we could have a REST/gRPC API to verify as a service. Possible use cases: - OSSF or another org runs a verifier...

type:feature

Hi! This PR relates to the discussion from #806 regarding the Node16 deprecation notice. During this we talked about adding support for multiple OSes, as well as addressing the caching...

This PR contains the following updates: | Package | Change | Age | Adoption | Passing | Confidence | |---|---|---|---|---|---| | [github.com/sigstore/sigstore-go](https://redirect.github.com/sigstore/sigstore-go) | `v0.5.1` -> `v0.6.1` | [![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fsigstore%2fsigstore-go/v0.6.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/github.com%2fsigstore%2fsigstore-go/v0.6.1?slim=true)](https://docs.renovatebot.com/merge-confidence/)...

I noticed that the installer Action is still using Node16 and throws a warning at users since it has been deprecated. Would it be possible to bump this to Node20?...

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | golang.org/x/exp | require | digest | `7f521ea` -> `701f63a` | --- ### Configuration...