-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Description
P0 — Proof chain
- Define
policy.yamlschema and rule kinds (iac,deploy,device) - Implement OPA/Cedar engine adapter and 5 stock rules
- Emit in-toto Statement + SLSA Provenance; Sigstore keyless sign; record to Rekor
-
mondrian verifyvalidates signatures + Rekor inclusion; outputsproof.zip - Add pass/fail
examples/terraformwith golden outputs
P1 — Developer Experience & CI
-
goreleaserand Homebrew tap; publish v0.1.0 binaries - Add
go vet,golangci-lint,go testin CI - Upload
proof.zipon success; verify in a second job - Add CONTRIBUTING.md, SECURITY.md, CODEOWNERS
P2 — Evidence platform
- Minimal Merkle log chain per repo
-
mondrian serveread-only API for attestations - osquery pack +
devicerule mapping
Docs
- Data-flow diagram: code → gate → attestation → log → verify
- Show exact SLSA fields populated
- Threat model v0: attacker tries to bypass CI, tamper proofs, spoof device state
Metadata
Metadata
Assignees
Labels
No labels