This repository was archived by the owner on Jan 23, 2025. It is now read-only.
v0.1.0
This is the initial release of the server and client components. They implement a minimal demonstration of in-toto and AWS Nitro Enclaves being used to verifiably generate an SBOM from an uploaded artifact. This release is intended for demonstration purposes only, but that should change in future releases.
Known Issues
- The binaries and EIF were built in a one-off, manual process
- The
dist/
directory is missing the Enclaver configuration used to build the enclave image file (EIF) - The Build Type and Builder IDs are incorrect (missing a 'v' prefix on the version number)
- When
--attest
is used, the client outputs the in-toto Statement instead of the inner SBOM