12장 attestation은 서명이 아니라 주장과 identity의 결합이다
attestation은 artifact에 대한 구조화된 주장이다. subject digest, source repository, commit, workflow, builder 같은 정보를 포함할 수 있다. signature 검증만 통과했다고 끝나지 않는다. 어떤 identity가 어떤 조건에서 서명했는지 policy로 확인한다.
ChainLab의 verifyAttestation은 세 조건을 본다.
subject digest == 실제 artifact digest
repository == withai/helpdesk-ai
ref == refs/heads/main
운영에서는 reusable workflow identity, environment, event, issuer, transparency log 또는 조직 trust root를 확인한다. GitHub artifact attestation은 build가 어디서 어떻게 만들어졌는지 provenance를 세우며, workflow에 id-token, contents, attestations permission이 필요하다. 지원 plan과 private repository 범위는 적용 시점 공식 문서를 확인한다.