Mikhail Swift

Results 25 issues of Mikhail Swift

When a zarf package is created we should record some attestations about the package's creation. Some attestations could include - Environment details such as set variables, user, cloud metadata if...

sbom
packager

Currently hashes are being collected for some resources but not all. This should be expanded to include all images, helm charts, files, etc. When resources are fetched from a remote...

sbom
packager

#### Summary Adds a DSSE type that validated each signature on the envelope. If the payload is an in-toto statement all in-toto subjects will be indexed. The hash of the...

Currently the in-toto type does not contain any signatures. This prevents users of in-toto records from verifying attestations that are stored in rekor's attestation stores. Additionally, the IntotoObj.content.hash refers to...

bug

Rebased version of https://github.com/testifysec/witness/pull/181 onto latest main

A tracee may only be traced by a single tracer, where a tracer and tracee refer to OS threads. However each tracee can be traced by different tracers. Right now...

enhancement
priority low
trace
needs triage

Migrated from gitlab -- original author @colek42

priority medium

priority low
needs triage

#75 introduced file hashing of opened files by tracees. This allows us to tell exactly what went into a build, but it comes at a cost. Calculating hashes is not...

enhancement
priority medium
trace
debt
needs triage