Skip to content

clarity: source track: continuity: should each technical control have its own continuity #1491

@arewm

Description

@arewm

#1483 (comment)

Should we require controls to have separate continuities or if not, can we recommend that instead? There is a tradeoff between being able to simply ratchet up controls vs. having one simple control requirement that can be enforced.

This might fall back to specific implementation details, but if we think that it would be better to separate controls, then we should make sure that the verification part of the spec is consistent.

Metadata

Metadata

Assignees

No one assigned

    Labels

    slsa 1.2Required for SLSA 1.2 release. Please apply it liberally!source-track

    Type

    No type

    Projects

    Status

    ✅ Done

    Status

    Done

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions