Skip to content
This repository has been archived by the owner on Nov 14, 2023. It is now read-only.

Create software_artifact_examples.md #17

Closed
wants to merge 1 commit into from
Closed

Conversation

OR13
Copy link

@OR13 OR13 commented Sep 22, 2022

No description provided.

@OR13
Copy link
Author

OR13 commented Sep 22, 2022

can I have editor rights on this repo? I would live to be able to refine the software artifacts zoo :)

@SteveLasker
Copy link
Contributor

@OR13, is this a draft?

@OR13
Copy link
Author

OR13 commented Oct 21, 2022

@SteveLasker

This is ancient.... I requested the ability to create software artifacts examples, my intention was to just start a collection, so we have named examples to point to, when discussing specific artifact types.

@SteveLasker
Copy link
Contributor

@OR13, so, do you want to merge, or is this old and now outdated? Just looking for what action to take (LGTM or ?)

@rjb4standards
Copy link

Steve, I wish to contribute the artifacts I plan to demonstrate during the SCITT Hackathon:
https://github.com/rjb4standards/SCITT-MVP-USeCases
SBOM, VDR and a Vendor Response File for OMB M-22-18.
FYI, these are actual production artifacts from REA's SAG-PM V1.2 product distribution.

@SteveLasker
Copy link
Contributor

Thanks, @rjb4standards,
Could you open a PR or Issue to track separately from here?
Would these be examples of evidence submitted to a SCITT ledger? It would be great to get a narrative, or are you suggesting these could be the types of evidence documents we could submit as part of: https://github.com/ietf-scitt/scitt-web/blob/a604c8630217c43ec49dac461d2f75b66ae9d7d3/what-is-supply-chain.md

@rjb4standards
Copy link

In my view, a notary would examine these artifacts and the associated digital signatures of these artifacts and then insert a "trust declaration" claim into a SCITT Registry to indicate the combination of the artifact and digital signature are trustworthy.
I'll describe in more detail in an issue.

@rjb4standards
Copy link

Steve, I've created an Issue to track this concept: #26

@OR13
Copy link
Author

OR13 commented Oct 31, 2022

Closing this PR, moving the content to the web repo, where I can merge.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants