Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Encourage user to attest to their SBOM #273

Open
laurentsimon opened this issue Sep 16, 2022 · 0 comments
Open

Encourage user to attest to their SBOM #273

laurentsimon opened this issue Sep 16, 2022 · 0 comments
Labels
documentation Improvements or additions to documentation
Milestone

Comments

@laurentsimon
Copy link

Hi

I'm one of the maintainers of OpenSSF project's SLSA native GitHub generators.

We would like to encourage users to add a provenance attestation to their SBOM documents. We can add a section "SBOM attestations" in our own documentation.

Similarly, encouraging users to generate SLSA attestation could be added to the documentation in this repo. Cross-linking to our repositories would be a great way to increase adoption of best practices across projects simultaneously.

Here's what I think the documentation would look like on the slsa-generator repo:

  1. Download the binary from the opensbom-generator.
  2. Verify the SLSA provenance of the binary (once Generate SLSA signature / provenance for your artifacts #272 is complete), using the slsa-verifier (We are releasing a GitHub action installer in the next couple weeks)
  3. Run the sbomgenerator
  4. Add a step to generate the attestation to the SBOM.

How does this sound? Would anyone be interested in helping out to make this happen?

@laurentsimon laurentsimon added the documentation Improvements or additions to documentation label Sep 16, 2022
@nishakm nishakm added this to the Release 0.1.0 milestone Sep 22, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation
Projects
None yet
Development

No branches or pull requests

2 participants