Update buildType in SLSAV1.0 provenance
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 277
- Forks
- 164
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 61
Description
Feature request
The buildType is described as "An identifier for the template for how to perform the build and interpret the parameters and dependencies." And says the URI should resolve to a human-readable specification describing the externalParameters, internalParameters and resolvedDependencies. Right now the buildType URI is https://tekton.dev/chains/v2/slsa. I'm proposing this is updated to reflect either a taskRun or pipelineRun attestation which is similar to v0.2 of the provenance. Also, should the URI be resolvable at this point? I'm wondering what thoughts are on that.
Use case
- Users writing policies need to differentiate between a taskRun and pipelineRun build.
- It would be helpful to users if there's documentation explaining the buildType and it's parameters and dependencies.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No file, test, or entry point is named. Review the SLSA v1.0 buildType definition and existing taskRun and pipelineRun attestation behavior; done means an agreed buildType URI plus documentation for its parameters and dependencies.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100