Skip to content

Ch 6: Attestation Generation - #43

Draft
Uk-jake wants to merge 5 commits into
SBOMit:draft-v0.3.0from
Uk-jake:ch6-attestation-generation
Draft

Ch 6: Attestation Generation#43
Uk-jake wants to merge 5 commits into
SBOMit:draft-v0.3.0from
Uk-jake:ch6-attestation-generation

Conversation

@Uk-jake

@Uk-jake Uk-jake commented Aug 24, 2026

Copy link
Copy Markdown

I am currently writing Chapter 6 (Attestation Generation)

related
#37

@stupendoussuperpowers

Copy link
Copy Markdown

Let's have this section follow this:

6.1 Overview: Brief description of this
6.2 Capturing the Required Evidence. This will have headings/paragraphs covering each of files opened network trace, materials products git etc. For each we explain what qualifies as an entry and what information should be captured. Here we can rely on describing what witness currently does and update the spec accordingly.
6.3 Delegated Builds
6.4 Containerized Builds
6.5 Example workflow: Describing when attestations should be run/example of using witness etc.

In this PR you can focus on 6.1, 6.2, and 6.5. I will handle 6.3 and 6.4 in a separate PR.

@stupendoussuperpowers

Copy link
Copy Markdown

Also: Please add a DCO signoff to all your commits (git commit --signoff -m '...') so that it passes the checks.

@Uk-jake

Uk-jake commented Aug 25, 2026

Copy link
Copy Markdown
Author

Makes sense. I'll change the section based on the suggestion and focus on parts 6.1, 6.2, and 6.5. Thanks for reviewing.

Signed-off-by: Uk-jake <mag0225@naver.com>
Signed-off-by: Uk-jake <mag0225@naver.com>
Signed-off-by: Uk-jake <mag0225@naver.com>
Comment thread specification.md

### 6.4 Containerized Builds

### 6.5 Example Workflow

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just have this be "Example Workflow - Witness" and talk about how to use witness to generate this attestation. We don't need to have multiple subheadings within it. All the implementation details we can mention will only be about witness and not something generally applicable.

Need to mention: What stage of the build is used typically. What witness flags/command can be used. How the captured information is represented in the final attestation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants