[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#1113699: ITP: golang-github-smallstep-go-attestation -- abstract attestation for remote machine/state validation



Christopher Obbard <obbardc@gmail.com> writes:

> Hi Simon,
>
> On Mon, 1 Sept 2025 at 10:29, Simon Josefsson <simon@josefsson.org> wrote:
>>
>> Package: wnpp
>> Severity: wishlist
>> Owner: Simon Josefsson <simon@josefsson.org>
>>
>> * Package name    : golang-github-smallstep-go-attestation
>>   Version         : 0.4.3-1
>>   Upstream Author : Smallstep
>> * URL             : https://github.com/smallstep/go-attestation
>
> Isn't upstream https://github.com/google/go-attestation ? Or I guess
> this could be a required fork for the upstream?
> It's a bit unclear to me in this current state.

Yes you are right.  I realized this too (just look at my mixed up
personal salsa URL which was for the google project).  Sometime it
seemed like both of these were imported from the same project, but I
think they could be patched to just use one of them.

I will step back and attempt to package
golang-github-google-go-attestation, so we have a baseline.

Thanks for thinking about these aspects and bringing it up!

/Simon

Attachment: signature.asc
Description: PGP signature


Reply to: