Commit bd51715
docs(signing): clarify Fulcio's role in builder ID extraction
Add detailed comment explaining:
- How Fulcio (Sigstore's CA) processes OIDC tokens
- Why attestation builder ID must match certificate SAN
- Uncertainty about GitHub's OIDC token structure
- Rationale for trying both extraction approaches
This helps future maintainers understand the critical relationship
between OIDC token claims, Fulcio certificate generation, and
SLSA attestation verification.
Co-authored-by: Ona <no-reply@ona.com>1 parent 7c393af commit bd51715
1 file changed
+9
-2
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
420 | 420 | | |
421 | 421 | | |
422 | 422 | | |
423 | | - | |
| 423 | + | |
| 424 | + | |
| 425 | + | |
| 426 | + | |
| 427 | + | |
| 428 | + | |
| 429 | + | |
| 430 | + | |
| 431 | + | |
424 | 432 | | |
425 | 433 | | |
426 | 434 | | |
427 | | - | |
428 | 435 | | |
429 | 436 | | |
430 | 437 | | |
| |||
0 commit comments