TACOS + in-toto Attestations #2
adityasaky
started this conversation in
General
Replies: 1 comment 3 replies
-
My suspicion is that a custom predicate would be most appropriate. SCAI is great for communicating a very flexible set of information, with the downside that the flexibility requires additional coordination between producers and consumers and more generic field names. If TACOS has the goal of being a broadly adopted method of communicating this information to lots of consumers it's probably worth the effort to define a custom predicate tailored specifically for it. |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
In a discussion on the OpenSSF slack, @laurenhanford indicated that the project is interested in emitting TACOS information as in-toto attestations. We think that's a great fit as well and that it ties in well with several other predicates the community has defined so far! A good start is to use either a custom predicate or perhaps via SCAI. Thoughts?
cc @marcelamelara @TomHennen @pxp928 @joshuagl @mikhailswift
Beta Was this translation helpful? Give feedback.
All reactions