Giter VIP home page Giter VIP logo

Comments (4)

ianlewis avatar ianlewis commented on July 17, 2024

Sure. I can take a look at it.

from example-package.

laurentsimon avatar laurentsimon commented on July 17, 2024

I'm still actively updating https://github.com/slsa-framework/example-package/tree/main/.github/workflows. I have a couple more to add then I will start adding adversarial e2e tests (caller workflow tampers with the artifact registry we use to pass binaries around). I loosely keep track of it in slsa-framework/slsa-github-generator#76
Don't hesitate to ask if you have questions: I have not documented everything yet

from example-package.

ianlewis avatar ianlewis commented on July 17, 2024

@laurentsimon I see, you've gone ahead and done a lot of the work already.

Why don't you get started on the adversarial tests and I can handle the TODOs you've got in e2e-verify.sh
https://github.com/slsa-framework/example-package/blob/main/.github/workflows/scripts/e2e-verify.sh

I'll also spend some time understanding a bit more how it works and documenting it.

from example-package.

laurentsimon avatar laurentsimon commented on July 17, 2024

most TODOs in the e2e-verify.sh are done or cannot be done until we update the verifier (https://github.com/slsa-framework/example-package/blob/main/.github/workflows/scripts/e2e-verify.sh#L176) or cut a release for the verifier (https://github.com/slsa-framework/example-package/blob/main/.github/workflows/scripts/e2e-verify.sh#L177). The other TODOs need to be removed.

Feel free to use slsa-framework/slsa-github-generator#76 to add support:

Let me know if you want to take these

from example-package.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.