Meaning
Metadata exchange specifications document the exact steps taken during a software build process to ensure the product has not been tampered with. The in-toto attestation format provides a standardized way to record the inputs, the commands executed, and the resulting files for every stage of development. It allows downstream users to verify that the final binary was built according to the original developer’s instructions.
This verification relies on digital signatures from each actor in the supply chain.
Step Declaration
Definitions for each stage of the build process are stored in a layout file that specifies the expected signers. Using the in-toto attestation format allows an automated system to check if a step was performed by an unauthorized machine or user. This prevents the injection of malicious code between the source repository and the deployment target.
Supply Chain Evidence
Evidence collected during the build is bundled into a package that follows the software to its destination. The in-toto attestation format makes it possible to audit the entire history of a container image or software package without needing access to the original build server. This builds trust in third-party software.
Integrity Verification
Integrity verification fails if any step in the process is missing a valid signature. The in-toto attestation format ensures that no step was bypassed.