[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#1113699: ITP: golang-github-smallstep-go-attestation -- abstract attestation for remote machine/state validation



Hi Simon,

On Mon, 1 Sept 2025 at 10:29, Simon Josefsson <simon@josefsson.org> wrote:
>
> Package: wnpp
> Severity: wishlist
> Owner: Simon Josefsson <simon@josefsson.org>
>
> * Package name    : golang-github-smallstep-go-attestation
>   Version         : 0.4.3-1
>   Upstream Author : Smallstep
> * URL             : https://github.com/smallstep/go-attestation

Isn't upstream https://github.com/google/go-attestation ? Or I guess
this could be a required fork for the upstream?
It's a bit unclear to me in this current state.

> * License         : Apache-2.0
>   Programming Lang: Go
>   Description     : abstract attestation for remote machine/state validation
>
>  Go-Attestation abstracts remote attestation operations across a variety
>  of platforms and TPMs, enabling remote validation of machine identity
>  and state. This project attempts to provide high level primitives for
>  both client and server logic.
>
> Needed by modern golang-github-smallstep-certificates.  I hope to
> maintain this as part of the Go team.
>
> https://salsa.debian.org/go-team/packages/golang-github-smallstep-go-attestation
> https://salsa.debian.org/jas/golang-github-google-go-attestation/-/pipelines
>
> /Simon


Reply to: