-
Notifications
You must be signed in to change notification settings - Fork 66
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
HACDOCS-941-glossary #51
Conversation
🚀 Preview is available at |
@arewm I didn't find any instances of Devfile. I deleted the one mention of GitOps. And I deleted all references to environments, except for one mention of production environment under managed workspace, because I thought that might still be valid. Please take a look at that definition and let me know if I should delete that. And of course I'm happy to make any other changes you'd like to see. |
🚀 Preview is available at |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'm good with the updates I asked for
A collection of TaskRuns that are arranged in a specific order of execution. | ||
|
||
**provenance** + | ||
{ProductName} produces SLSA provenance, which consists of the attestation for an artifact, and a signature for that attestation. Attestation lists the steps that {ProductName} took to create a given artifact. The signature enables you to verify that no one tampered with that attestation. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The provenance lists the steps
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Isn't attestation the specific component of provenance that lists the steps? That's how we defined it here.
Or would you like me to change this to say:
"Konflux produces SLSA provenance, which includes a list of steps that Konflux took to build a given artifact, and a signature to verify that the provenance comes from Konflux."
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
An attestation is generically a claim being made about a subject (i.e. the container that is produced). The SLSA provenance is a type of attestation but there are many different types of attestations ... some that have been defined by the community, but others can certainly exist even without being vetted by the in-toto maintainers.
If we are talking about the build steps, that is the provenance attestation .. both here and in https://konflux-ci.dev/docs/#slsa-provenance. I didn't catch that issue in the overview previously.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Ok, I updated this def and the SLSA overview doc accordingly.
Capitalizing "Enterprise Contract" per this issue: https://issues.redhat.com/secure/RapidBoard.jspa?rapidView=18221&projectKey=RHTAPBUGS&view=detail&selectedIssue=HACDOCS-357#
No description provided.