-
Notifications
You must be signed in to change notification settings - Fork 130
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Inconsistent deduplication handing in subjects and materials #925
Labels
kind/bug
Categorizes issue or PR as related to a bug.
Comments
/assign |
chuangw6
added a commit
to chuangw6/chains
that referenced
this issue
Sep 15, 2023
Fixes tektoncd#925 Prior, deduplication handling for subjects and materials is different. Now, we use consistent approach to handle the deduplication. Signed-off-by: Chuang Wang <[email protected]>
3 tasks
chuangw6
added a commit
to chuangw6/chains
that referenced
this issue
Sep 15, 2023
Fixes tektoncd#925 Prior, deduplication handling for subjects and materials is different. Now, we use consistent approach to handle the deduplication. Signed-off-by: Chuang Wang <[email protected]>
chuangw6
added a commit
to chuangw6/chains
that referenced
this issue
Sep 15, 2023
Fixes tektoncd#925 Prior, deduplication handling for subjects and materials is different. Now, we use consistent approach to handle the deduplication. Signed-off-by: Chuang Wang <[email protected]>
chuangw6
added a commit
to chuangw6/chains
that referenced
this issue
Oct 5, 2023
Fixes tektoncd#925 Prior, deduplication handling for subjects and materials is different. Now, we use consistent approach to handle the deduplication. Signed-off-by: Chuang Wang <[email protected]>
tekton-robot
pushed a commit
that referenced
this issue
Oct 10, 2023
Fixes #925 Prior, deduplication handling for subjects and materials is different. Now, we use consistent approach to handle the deduplication. Signed-off-by: Chuang Wang <[email protected]>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
In 2023-09-14 Chains WG meeting, we discussed the deduplication handing in subjects and materials for slsa provenance. They are inconsistent in terms of when to deduplicate and how to identify the duplicates.
For Subjects:
name
and at least one common digest algorithm and hex.For Materials:
The problem with the approach for materials is that 2 entries with same uri and one common algorithm & hex will be identified as 2 completely different materials, but they should be the same artifact.
In the WG meeting, we agreed that we should consolidate and make the approach for handling duplications consistent across artifacts collection in slsa provenance.
The text was updated successfully, but these errors were encountered: