Build from signed source
This policy checks if the build was done from a signed commit.
Control evaluation result
Status
Evaluation result after comparing the policy with the current state of the asset
0 Violations
Update the attestation using the following command
devguard-scanner attest --token <Personal access token> --predicateType "https://slsa.dev/provenance/v1" <json file>
Create a Personal Access Token
To use the Devguard-Scanner, you need to create a Personal Access Token. You can create such a token by clicking the button below.