3 ms·
The rekor project under sigstore is interesting in this regard: https://github.com/sigstore/rekor https://github.com/sigstore/rekor Its listed as a signature t
by playcache 6y ago
The rekor project under sigstore is interesting in this regard: https://github.com/sigstore/rekor https://github.com/sigstore/rekor
Its listed as a signature transparency log, but they support some sort of custom manifest system, so you can set your own schema in your prefered format (xml, json, yaml) - the only thing is they require the manifest / material file is signed (I guess as it then brings a level of non-repudation). I am hoping someone works on an SBOM type.
I heard some of the in-toto folks are working on the project as well. This is a good step towards a SBOM recorded supply chain.
- dlor 6y agoMaintainer here! That's exactly the idea. We're working with intoto and others to get metadata that we can actually verify, directly from build systems. Rekor is a place to put and find that metadata that's globally visible and can't be tampered with. We're hoping to add support for the ITE-6 in-toto link format soon, which I see as kind of like an SBOM that can be produced directly from your build system.