package-analysis
package-analysis copied to clipboard
Record analysis runs in Transparency log - Rekor
Record analysis runs in the Transparency log https://github.com/sigstore/rekor
in-toto attestations for scans https://github.com/in-toto/attestation/issues/58
I think this is important, but needs to come after milestone 5 when we have a more formal data structure.