TACOS + in-toto Attestations #2
adityasaky
started this conversation in
General
Replies: 1 comment 3 replies
-
My suspicion is that a custom predicate would be most appropriate. SCAI is great for communicating a very flexible set of information, with the downside that the flexibility requires additional coordination between producers and consumers and more generic field names. If TACOS has the goal of being a broadly adopted method of communicating this information to lots of consumers it's probably worth the effort to define a custom predicate tailored specifically for it. |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
In a discussion on the OpenSSF slack, @laurenhanford indicated that the project is interested in emitting TACOS information as in-toto attestations. We think that's a great fit as well and that it ties in well with several other predicates the community has defined so far! A good start is to use either a custom predicate or perhaps via SCAI. Thoughts?
cc @marcelamelara @TomHennen @pxp928 @joshuagl @mikhailswift
Beta Was this translation helpful? Give feedback.
All reactions