Skip to main content

Disallow dependencies in SLSA Provenance Document

Type: Rule
ID: slsa-builder-unallowed-dependencies
Source: v2/rules/slsa/banned-builder-deps.yaml
Rego Source: banned-builder-deps.rego
Labels: SLSA, Image

Verify that dependencies in the block list do not appear in the SLSA Proveance document.

note

This rule requires SLSA Provenance. See here for more details.

tip

Signed Evidence for this rule IS NOT required by default but is recommended.

warning

Rule requires evaluation with a target. Without one, it will be disabled unless the --all-evidence flag is provided.

Usage example

uses: slsa/banned-builder-deps@v2

Evidence Requirements

FieldValue
signedFalse
content_body_typeslsa
target_typecontainer

Rule Parameters (with)

ParameterDefault
blocklist[]