Skip to content

Attestation is redundantly downloaded into temporary files #1095

@benmss

Description

@benmss

As part of the analysis process regarding attestation files, data received from the various possible sources is stored into a temporary file before being analysed. This functionality was originally created for users passing their own attestation files to Macaron at runtime, but has been reused in cases where it is not the ideal solution. Instead, attestation files that are downloaded from remote sources should be analysed while still in memory. Storage of the provenance data is already handled by the database as appropriate.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementEnhancement of a featureslsa-provenanceThe issues related to SLSA provenances

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions