Skip to content

Push the policy time forward again.#193

Merged
TomHennen merged 1 commit intoslsa-framework:mainfrom
TomHennen:pushthepolicyagain
Jun 5, 2025
Merged

Push the policy time forward again.#193
TomHennen merged 1 commit intoslsa-framework:mainfrom
TomHennen:pushthepolicyagain

Conversation

@TomHennen
Copy link
Contributor

There's an issue where we don't look at all the available provenance just the first one we find. So even though prior commits have 'good' provenance that would meet this policy they also have 'bad' provenance that doesn't. That bad provenance is found 'first' which means we fail the policy check. We could fix that, but it's tricky. Better to get things working again and we can resolve later.

There's an issue where we don't look at all the available
provenance just the first one we find.  So even though
prior commits have 'good' provenance that would meet this
policy they also have 'bad' provenance that doesn't. That
bad provenance is found 'first' which means we fail the
policy check.  We could fix that, but it's tricky. Better
to get things working again and we can resolve later.

Signed-off-by: Tom Hennen <[email protected]>
@TomHennen
Copy link
Contributor Author

At least that was my theory. @puerco has noted that there seems to only be one provenance attestation. Some deeper analysis will be needed. Still better to get things working again.

@TomHennen TomHennen merged commit 467edf0 into slsa-framework:main Jun 5, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant