Skip to content

v1.1.0

Compare
Choose a tag to compare
@asraa asraa released this 20 Jun 21:15
· 402 commits to main since this release
5875b0a

What's Changed

  • Adds support to verify using an embedded certificate in the DSSE envelope. This avoids using a Redis index for searching for the signing certificate

To learn how to use it, see Verification of Provenance

This is meant to be used for GitHub workflow SLSA generation. Builders are located in slsa-github-generator.

Contributors

@asraa @ianlewis @joshuagl @laurentsimon @naveensrinivasan