Skip to content
This repository was archived by the owner on Feb 16, 2026. It is now read-only.
This repository was archived by the owner on Feb 16, 2026. It is now read-only.

Add sigstore signing for remediation plans and execution results #1

Description

@mlieberman85

Look at converting remediation plans to in-toto attestations and signing them. Two reasons for this:

  1. Enables ingestion and aggregation of this data into tools like GUAC and associating it with identities
  2. Tracking what identity generated a remediation plan and what identity or identities that executed it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions