-
Notifications
You must be signed in to change notification settings - Fork 264
Open
Labels
slsa 1.2Required for SLSA 1.2 release. Please apply it liberally!Required for SLSA 1.2 release. Please apply it liberally!slsa 1.2-RC1 feedbacksource-track
Description
I'm having difficulty parsing the Source Track Continuity requirement in v1.2-rc1. I suspect that most readers will not understand it or apply it correctly.
In git terminology, is the requirement that a protected branch prevent non-fast-forward updates, except through for Safe Expunging Process? Is there anything else required?
What about a reflog (again, using git terminology), keeping track of all the revisions that the branch pointed to? Is that required? If not, should it be?
Metadata
Metadata
Assignees
Labels
slsa 1.2Required for SLSA 1.2 release. Please apply it liberally!Required for SLSA 1.2 release. Please apply it liberally!slsa 1.2-RC1 feedbacksource-track
Type
Projects
Status
🆕 New
Status
No status
Status
No status