You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardexpand all lines: probes/releasesHaveVerifiedProvenance/def.yml
+1
Original file line number
Diff line number
Diff line change
@@ -13,6 +13,7 @@
13
13
# limitations under the License.
14
14
15
15
id: releasesHaveVerifiedProvenance
16
+
lifecycle: experimental
16
17
short: Checks if the project releases with provenance attestations that have been verified
17
18
motivation: >
18
19
Package provenance attestations provide a greater guarantee of authenticity and integrity than package signatures alone, since the attestation can be performed over a hash of both the package contents and metadata. Developers can attest to particular qualities of the build, such as the build environment, build steps or builder identity.
0 commit comments