Skip to content
This repository was archived by the owner on Jan 23, 2025. It is now read-only.

v0.1.0

Compare
Choose a tag to compare
@crawford crawford released this 16 Nov 00:04
· 24 commits to main since this release

This is the initial release of the server and client components. They implement a minimal demonstration of in-toto and AWS Nitro Enclaves being used to verifiably generate an SBOM from an uploaded artifact. This release is intended for demonstration purposes only, but that should change in future releases.

Known Issues

  • The binaries and EIF were built in a one-off, manual process
  • The dist/ directory is missing the Enclaver configuration used to build the enclave image file (EIF)
  • The Build Type and Builder IDs are incorrect (missing a 'v' prefix on the version number)
  • When --attest is used, the client outputs the in-toto Statement instead of the inner SBOM