Build from signed source
This policy checks if the build was done from a signed commit.
Control evaluation result
Status
Evaluation result after comparing the policy with the current state of the asset
0 Violations
Update the attestation using the following command
devguard-scanner attest --predicateType "https://slsa.dev/provenance/v1" <json file>