dsse

package
v1.3.3 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Nov 1, 2023 License: Apache-2.0 Imports: 5 Imported by: 2

README

DSSE Type Data Documentation

This document provides a definition for each field that is not otherwise described in the dsse schema. This document also notes any additional information about the values associated with each field such as the format in which the data is stored and any necessary transformations.

How do you identify an object as an DSSE object?

The "Body" field will include an "dsseObj" field.

Recognized content types

  • in-toto statements are recognized and parsed. The found subject hashes are indexed so they can be searched for.

What data about the envelope is stored in Rekor

Only the hash of the payload (the content covered by the digital signature inside the envelope), the hash of the entire DSSE envelope (including signatures), the signature(s) and their corresponding verifying materials (e.g. public key(s) or certificates) are stored.

Even if Rekor is configured to use attestation storage, the entire DSSE envelope will not be stored.

Directories

Path Synopsis

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL