-
Notifications
You must be signed in to change notification settings - Fork 226
Insights: slsa-framework/slsa
Overview
Could not load contribution data
Please try again later
4 Pull requests merged by 4 people
-
build(deps): bump cross-spawn from 7.0.3 to 7.0.6
#1246 merged
Nov 21, 2024 -
content: Update website with current steering committee
#1241 merged
Nov 19, 2024 -
nonspec: remove Joshua as a maintainer
#1234 merged
Nov 18, 2024
5 Pull requests opened by 4 people
-
content: source track: address org threats
#1236 opened
Nov 18, 2024 -
content: source-track: merge train summary
#1240 opened
Nov 18, 2024 -
content: Add figure for the build environment model
#1244 opened
Nov 19, 2024 -
build(deps): bump smol-toml from 1.3.0 to 1.3.1
#1247 opened
Nov 22, 2024 -
impl: Update dependency markdownlint-cli to v0.43.0
#1248 opened
Nov 23, 2024
5 Issues closed by 2 people
-
How should the Source track address merge strategies?
#1040 closed
Nov 22, 2024 -
Transfer image-attestation demo to slsa-framework org
#1110 closed
Nov 18, 2024 -
Is 'branch protection' only applicable for cloud-hosted SCPs?
#1136 closed
Nov 18, 2024 -
[Specification SIG] Clarify/refine SLSA source requirements
#463 closed
Nov 18, 2024 -
Clarify what must be retained during source migrations
#1079 closed
Nov 18, 2024
5 Issues opened by 2 people
-
Add figure for build environment lifecycle
#1245 opened
Nov 19, 2024 -
Write detailed requirements/guidance for BuildEnv track
#1243 opened
Nov 18, 2024 -
cleanup verifying-source content
#1242 opened
Nov 18, 2024 -
fill in or cut this bit about merge trains
#1239 opened
Nov 18, 2024 -
verifying-source should discuss verifying all the commits directly on a protected ref
#1238 opened
Nov 18, 2024
8 Unresolved conversations
Sometimes conversations happen on old items that aren’t yet closed. Here is a list of all the Issues and Pull Requests with unresolved conversations.
-
start discussion with ossf/scorecard team to build an initial prototype
#1160 commented on
Nov 18, 2024 • 0 new comments -
Clarify where to use SLSA Provenance vs. VSA
#974 commented on
Nov 18, 2024 • 0 new comments -
Add figures for build environment track spec
#1165 commented on
Nov 19, 2024 • 0 new comments -
Clarify language around 'identity'
#1133 commented on
Nov 21, 2024 • 0 new comments -
source track: create a "levels" table for the source track
#1111 commented on
Nov 22, 2024 • 0 new comments -
clarify relationship between attestations and refs / branches
#1081 commented on
Nov 22, 2024 • 0 new comments -
Dependency Dashboard
#431 commented on
Nov 23, 2024 • 0 new comments -
content: Update mitigation section for the Dependency Confusion threat.
#1226 commented on
Nov 18, 2024 • 0 new comments