Skip to content
This repository has been archived by the owner on Nov 22, 2024. It is now read-only.

Federation via ActivityPub #37

Conversation

johnandersen777
Copy link

@johnandersen777 johnandersen777 commented Oct 16, 2023

  • This pull request adds an option for federating events via the ActivityPub protocol.
    • Federation of SCITT events, such as receipt created, enable near real-time communication between supply chains.
    • Acceptance of claims to SCITT where payload data contains VEX, VSA, VRF, SBOM, S2C2F alignment attestations, etc. has the side effect of enabling a consistent pattern for notification of new vulnerability (OpenSSF Stream 8) and other Software Supply Chain Security data.

Jump to viewing docs

asciicast

asciicast

Last known working commit: 5c0918b
Previous last known working commit: 88b38ed

johnandersen777 pushed a commit to johnandersen777/scitt-api-emulator that referenced this pull request Oct 16, 2023
Related: scitt-community#37
Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
@johnandersen777 johnandersen777 force-pushed the federation_activitypub_bovine branch 2 times, most recently from 425ab37 to df3b772 Compare October 16, 2023 07:10
@johnandersen777 johnandersen777 force-pushed the federation_activitypub_bovine branch 16 times, most recently from b0c8585 to 78c7d7f Compare October 16, 2023 18:58
johnandersen777 pushed a commit to intel/dffml that referenced this pull request Oct 16, 2023
…usness: Remove references to Heartwood link to SCITT ActivityPub pull request

Related: scitt-community/scitt-api-emulator#37
@johnandersen777 johnandersen777 force-pushed the federation_activitypub_bovine branch 7 times, most recently from eb35cc1 to 19bcf6a Compare October 17, 2023 02:36
Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
…h other

Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
…e library)

Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
…service parameters use_lro

Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
…ctive working

Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
…ment read failure

Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
…yet tested if the mechanical-herd generated key is the one that gets exported as the public key

Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
@johnandersen777 johnandersen777 force-pushed the federation_activitypub_bovine branch 2 times, most recently from bdcd343 to 9a82a17 Compare November 23, 2023 00:05
Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
@johnandersen777 johnandersen777 force-pushed the federation_activitypub_bovine branch 2 times, most recently from 838115c to 2b19d26 Compare November 23, 2023 00:24
Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
@johnandersen777 johnandersen777 force-pushed the federation_activitypub_bovine branch 2 times, most recently from 3358b2e to e89a605 Compare November 23, 2023 00:26
Asciinema: https://asciinema.org/a/627130
Signed-off-by: John Andersen <johnandersenpdx@gmail.com>
@SteveLasker
Copy link
Contributor

Thank you @pdxjohnny. This repo flushed out a number of scenarios to enable the group to make progress.
At this point, the repo has become out of date with the drafts and we've shifted to production implementations making this repo more confusing to folks looking to engage.
We'll archive this repo for reference of the work.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants