Add support for SLSA attestation verification (pulp-service patch 0048)
@jobselko is already working on this.
Since Aug 20, 2026.
Assessment
This issue has not been assessed yet.
Description
Upstream the SLSA attestation verification support currently carried as a patch in pulp-service (https://github.com/pulp/pulp-service/pull/977).
SLSA attestations that lack a Sigstore certificate can be verified against a public key configured via ATTESTATION_VERIFICATION_KEY. This enables verification of attestations from build systems that use their own signing keys instead of Sigstore.
- Dominant language
- Python
- Stars
- 49
- Forks
- 88
- Avg merge
- 1d 10h
- Merged PRs (30d)
- 31
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from pulp/pulp_python
-
Difficulty 3/5 1-2 days Newbie friendliness 68/100
pulp/pulp_python#1381 ·
-
Feature Triage-Needed
Difficulty 5/5 Over a week Newbie friendliness 45/100
pulp/pulp_python#1371 ·
-
Difficulty 5/5 Over a week Newbie friendliness 45/100
pulp/pulp_python#1360 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 52/100
pulp/pulp_python#1358 ·
-
Issue
Difficulty 3/5 1-2 days Newbie friendliness 58/100
pulp/pulp_python#1219 · 1 comment ·
All issues in pulp/pulp_python
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100