Skip to content

Conversation

@TomHennen
Copy link
Contributor

Now supports Source Level 4 if a review control is enabled.

If the user specifies L4 then they must have a review control enabled in GH. They do not need to have the ReviewEnforced field in their policy eneabled.

If the user doesn't specify ReviewEnforced in their policy then REVIEW_ENFORCED won't show up in the VSA, just L4. But, if they have L4 and ReviewEnforced then they'll get both SLSA_SOURCE_LEVEL_4 and REVIEW_ENFORCED.

TomHennen added 2 commits June 1, 2025 16:40
Now supports Source Level 4 if a review control is enabled.

If the user specifies L4 then they must have a review control
enabled in GH.  They _do not_ need to have the ReviewEnforced
field in their policy eneabled.

If the user doesn't specify ReviewEnforced in their policy
then REVIEW_ENFORCED won't show up in the VSA, just L4. But,
if they have L4 and ReviewEnforced then they'll get _both_
SLSA_SOURCE_LEVEL_4 _and_ REVIEW_ENFORCED.

Signed-off-by: Tom Hennen <tomhennen@google.com>
Signed-off-by: Tom Hennen <tomhennen@google.com>
@TomHennen TomHennen merged commit 0471efc into slsa-framework:main Jun 1, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant