sbp opened a new issue, #1390:
URL: https://github.com/apache/tooling-trusted-releases/issues/1390

   As SBOMs are security related metadata, we have been discussing requiring 
them to be signed. One edge case that we identified is that ATR can modify 
SBOMs. In this case, we are considering requiring release managers to re-sign 
the results; they need to check what ATR did to the SBOMs anyway, so their 
signature would record that they considered and approved ATRs changes.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to