tektoncd / tektoncd/chains

Update buildType in SLSAV1.0 provenance

Open
#838 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

kind/feature lifecycle/stale
Dominant language
Go
Stars
277
Forks
164
Avg merge
2d 3h
Merged PRs (30d)
61

Description

Feature request

The buildType is described as "An identifier for the template for how to perform the build and interpret the parameters and dependencies." And says the URI should resolve to a human-readable specification describing the externalParameters, internalParameters and resolvedDependencies. Right now the buildType URI is https://tekton.dev/chains/v2/slsa. I'm proposing this is updated to reflect either a taskRun or pipelineRun attestation which is similar to v0.2 of the provenance. Also, should the URI be resolvable at this point? I'm wondering what thoughts are on that.

Use case
  • Users writing policies need to differentiate between a taskRun and pipelineRun build.
  • It would be helpful to users if there's documentation explaining the buildType and it's parameters and dependencies.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No file, test, or entry point is named. Review the SLSA v1.0 buildType definition and existing taskRun and pipelineRun attestation behavior; done means an agreed buildType URI plus documentation for its parameters and dependencies.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.