intoto

package
v0.8.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jun 21, 2022 License: Apache-2.0 Imports: 5 Imported by: 6

README

in-toto Type Data Documentation

This document provides a definition for each field that is not otherwise described in the in-toto schema. This document also notes any additional information about the values associated with each field such as the format in which the data is stored and any necessary transformations.

Attestation: authenticated, machine-readable metadata about one or more software artifacts. SLSA definiton

  • The Attestation value ought to be a Base64-encoded JSON object.
  • The in-toto Attestation specification provides detailed guidance on understanding and parsing this JSON object.

AttestationType: Identifies the type of attestation being made, such as a provenance attestation or a vulnerability scan attestation. AttestationType's value, even when prefixed with an http, is not necessarily a working URL.

How do you identify an object as an in-toto object?

The "Body" field will include an "IntotoObj" field.

Directories

Path Synopsis

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL