-
Notifications
You must be signed in to change notification settings - Fork 60
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
security: respond to weaknesses identified in the in-toto sec audit #268
Labels
needs triage
Issues to triage
Comments
Hi! Is there any update to this? Are all the issues still around? |
Note, this tracking issue is specific to the Witness implementation and isn't reflective of issues in the in-toto specification. |
Hey @linsun 👋 Here are some updates and information with respect to the above:
I'll update the above descriptions to better track this progress. Let us know if you have any further questions! |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Incorporate File Permissions into File Metadata Records
Remove Support for Configuration Files
Add Feature to Attest Internal Configuration Parameters
Strategies to Counter Layout Replay Attacks
Implement Measures against Link File Reuse
Improve Verification by Functionaries
Clarify Position on PGP Support
The text was updated successfully, but these errors were encountered: