The importance of attestation data in securing the software delivery pipeline and the need for a verification process to establish trust in the attestation data.
- Attestation data provides proof of an event and allows tracing of outputs from inputs in the software delivery pipeline.
- Verification process is necessary to ensure integrity and authenticity of the attestation data.
- Integrity ensures that the attestation data cannot be tampered with, while authenticity ensures identification of the attestation creator.
- Non-forigibility and non-perishability ensure that the attestation content cannot be influenced by users operating the pipeline.
- Complete zero trust in the system is necessary to establish trust in the attestation data.