sbp opened a new issue, #1390: URL: https://github.com/apache/tooling-trusted-releases/issues/1390
As SBOMs are security related metadata, we have been discussing requiring them to be signed. One edge case that we identified is that ATR can modify SBOMs. In this case, we are considering requiring release managers to re-sign the results; they need to check what ATR did to the SBOMs anyway, so their signature would record that they considered and approved ATRs changes. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
