slsa
slsa copied to clipboard
Ephemeral vs. persistent artifacts
The definition of Build describes the inputs "may be sources, dependencies, or ephemeral build outputs."
To my understanding, "dependencies" are persistent build output artifacts. Is that correct? If so, I wonder what is the significance of differentiating the persistent vs. ephemeral artifacts? Could we unify them and just define build input as "may be sources and output artifacts of prior builds."?