license switch agpl -> busl1, sprints work, new product advisories
This commit is contained in:
@@ -29,10 +29,17 @@ See `etc/airgap.yaml.sample` for configuration options.
|
||||
Key settings:
|
||||
- Staleness policy (maxAgeHours, warnAgeHours, staleAction)
|
||||
- Time anchor requirements (requireTimeAnchor)
|
||||
- Per-content staleness budgets (advisories, VEX, packages, mitigations)
|
||||
- Per-content staleness budgets (advisories, VEX, packages, mitigations)
|
||||
- PostgreSQL connection (schema: `airgap`)
|
||||
- Export/import paths and validation rules
|
||||
|
||||
## Bundle manifest (v2) additions
|
||||
|
||||
- `canonicalManifestHash`: sha256 of canonical JSON for deterministic verification.
|
||||
- `subject`: sha256 (+ optional sha512) digest of the bundle target.
|
||||
- `timestamps`: RFC3161/eIDAS timestamp entries with TSA chain/OCSP/CRL refs.
|
||||
- `rekorProofs`: entry body/inclusion proof paths plus signed entry timestamp for offline verification.
|
||||
|
||||
## Dependencies
|
||||
|
||||
- PostgreSQL (schema: `airgap`)
|
||||
|
||||
Reference in New Issue
Block a user