Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Federation via ActivityPub #37

Draft
wants to merge 106 commits into
base: main
Choose a base branch
from

Conversation

johnandersen777
Copy link

@johnandersen777 johnandersen777 commented Oct 16, 2023

  • This pull request adds an option for federating events via the ActivityPub protocol.
    • Federation of SCITT events, such as receipt created, enable near real-time communication between supply chains.
    • Acceptance of claims to SCITT where payload data contains VEX, VSA, VRF, SBOM, S2C2F alignment attestations, etc. has the side effect of enabling a consistent pattern for notification of new vulnerability (OpenSSF Stream 8) and other Software Supply Chain Security data.

Jump to viewing docs

asciicast

asciicast

Last known working commit: 5c0918b
Previous last known working commit: 88b38ed

johnandersen777 pushed a commit to johnandersen777/scitt-api-emulator that referenced this pull request Oct 16, 2023
Related: scitt-community#37
Signed-off-by: John Andersen <[email protected]>
@johnandersen777 johnandersen777 force-pushed the federation_activitypub_bovine branch 2 times, most recently from 425ab37 to df3b772 Compare October 16, 2023 07:10
@johnandersen777 johnandersen777 force-pushed the federation_activitypub_bovine branch 16 times, most recently from b0c8585 to 78c7d7f Compare October 16, 2023 18:58
johnandersen777 pushed a commit to intel/dffml that referenced this pull request Oct 16, 2023
…usness: Remove references to Heartwood link to SCITT ActivityPub pull request

Related: scitt-community/scitt-api-emulator#37
@johnandersen777 johnandersen777 force-pushed the federation_activitypub_bovine branch 7 times, most recently from eb35cc1 to 19bcf6a Compare October 17, 2023 02:36
…service parameters use_lro

Signed-off-by: John Andersen <[email protected]>
Signed-off-by: John Andersen <[email protected]>
…yet tested if the mechanical-herd generated key is the one that gets exported as the public key

Signed-off-by: John Andersen <[email protected]>
@johnandersen777 johnandersen777 force-pushed the federation_activitypub_bovine branch 2 times, most recently from bdcd343 to 9a82a17 Compare November 23, 2023 00:05
Signed-off-by: John Andersen <[email protected]>
@johnandersen777 johnandersen777 force-pushed the federation_activitypub_bovine branch 2 times, most recently from 838115c to 2b19d26 Compare November 23, 2023 00:24
Signed-off-by: John Andersen <[email protected]>
@johnandersen777 johnandersen777 force-pushed the federation_activitypub_bovine branch 2 times, most recently from 3358b2e to e89a605 Compare November 23, 2023 00:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants