fix tests. new product advisories enhancements
This commit is contained in:
@@ -12,8 +12,11 @@ Guidance on DSSE/TUF roots, rotation, and signed time tokens.
|
||||
- Verification in sealed mode uses bundled roots; no online Rekor needed.
|
||||
- Rotate signing keys with overlapping validity; publish new root in next bundle.
|
||||
|
||||
## TUF (optional)
|
||||
- If using TUF metadata, ship `root.json`, `snapshot.json`, `timestamp.json` with bundles.
|
||||
## TUF (planned enhancement)
|
||||
- **Current**: TUF metadata can be shipped with bundles (`root.json`, `snapshot.json`, `timestamp.json`).
|
||||
- **Planned**: Full TUF client integration for dynamic trust metadata distribution.
|
||||
- See: `SPRINT_20260125_001_Attestor_tuf_trust_foundation.md`
|
||||
- See: `SPRINT_20260125_002_Attestor_trust_automation.md`
|
||||
- In sealed mode, trust only bundled metadata; no remote refresh.
|
||||
|
||||
## Signed time tokens
|
||||
|
||||
Reference in New Issue
Block a user