Design expression of Baseline conformance
Open
@mlieberman85 is already working on this.
Since Apr 29, 2025.
documentation
- Dominant language
- Go
- Stars
- 166
- Forks
- 44
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 13
Description
As discussed in today's SIG meeting, we discussed the need to have a manual Baseline attestation predicate:
- While we’re waiting for tools to support automated scanning and reports we should probably have some mechanism.
- You can’t hold an automated tool accountable; you can hold a human accountable.
- Even with automated tooling, a human needs to sign off on the conformance to Baseline.
- We need some sort of manual attestation format (e.g. an in-toto attestation with some evidence or points to some evidence)
@mlieberman85 and @evankanderson volunteered to draft this.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.