Skip to content

Graph evidence: typed SBOM/provenance/vuln/signature relationships + verification state #230

Description

@toddysm

Part of #168 (gap analysis bucket 3b: evidence/detail).

Problem

Attestations, SBOMs, signatures, and scan results are currently represented only as generic REFERS_TO referrers keyed by artifactType. #168 requires typed relationships and richer detail: signatures, signer identities, verification state and evidence, and typed links to SBOM/provenance/vulnerability reports.

Scope

  • Introduce typed relationships (or typed referrer roles) for SBOM, provenance, vulnerability report, and signature.
  • Model signer identity, signature verification state, and signature evidence.
  • Expose these in show (CLI + graph-service) and the visualization payloads.

Acceptance criteria

  • Typed evidence relationships modeled and indexed.
  • show returns signer/verification state and typed evidence links.
  • Tests + docs updated.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    catalogRelated to the Catalog stagefeatureNew feature or requestobservabilityRelated to Observability

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions