old sprints work, new sprints for exposing functionality via cli, improve code_of_conduct and other agents instructions
This commit is contained in:
@@ -538,9 +538,26 @@ Evidence packets can be exported in multiple formats:
|
||||
| Format | Use Case |
|
||||
|--------|----------|
|
||||
| JSON | API consumption, archival |
|
||||
| SignedJSON | DSSE-signed JSON for verification workflows |
|
||||
| Markdown | Human-readable documentation |
|
||||
| HTML | Styled web reports |
|
||||
| PDF | Human-readable compliance reports |
|
||||
| CSV | Spreadsheet analysis |
|
||||
| SLSA | SLSA provenance format |
|
||||
| **EvidenceCard** | Single-file evidence card with SBOM excerpt, DSSE envelope, and Rekor receipt (v1.1) |
|
||||
| **EvidenceCardCompact** | Compact evidence card without full SBOM (v1.1) |
|
||||
|
||||
### Evidence Card Format (v1.1)
|
||||
|
||||
The evidence-card format packages related artifacts into a single JSON file for offline verification:
|
||||
|
||||
- **SBOM Excerpt**: Relevant component information from the full SBOM
|
||||
- **DSSE Envelope**: Dead Simple Signing Envelope containing the signed payload
|
||||
- **Rekor Receipt**: Optional Sigstore Rekor transparency log receipt for audit trail
|
||||
|
||||
Content type: `application/vnd.stellaops.evidence-card+json`
|
||||
|
||||
See [Evidence Decision API](../../../api/evidence-decision-api.openapi.yaml) for schema details.
|
||||
|
||||
## References
|
||||
|
||||
|
||||
Reference in New Issue
Block a user