Skip to content

Instantly share code, notes, and snippets.

@evankanderson
Created June 24, 2025 14:09
Show Gist options
  • Save evankanderson/1a0120e44edceba0626f448e90684488 to your computer and use it in GitHub Desktop.
Save evankanderson/1a0120e44edceba0626f448e90684488 to your computer and use it in GitHub Desktop.
SCAI attestations for OpenSSF Baseline
{
"_type": "https://in-toto.io/Statement/v1",
"subject": [
{
"name": "software",
"uri": "https://github.com/mindersec/minder"
},
{
"name": "governance",
"uri": "https://github.com/mindersec/community"
},
{
"name": "policies",
"uri": "https://github.com/mindersec/minder-ruless-and-profiles"
},
{
"name": "command-line binary",
"uri": "pkg:brew/minder"
},
{
"name": "helm chart",
"uri": "oci://minder@sha256:0dea682a64dc3baaee50ce778e07676440ae91aeabe94d41fb3090aa35a90802?repository_url=ghcr.io/mindersec/minder/helm/minder"
}
],
"predicateType": "https://in-toto.io/attestation/scai/v0.3",
"predicate": {
"producer": {
"name": "Baseline Merger",
"uri": "https://github.com/ossf/baseline-merger"
},
"attributes": [
{
"attribute": "OSPS-AC-01.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-AC-02.01",
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-AC-03.01",
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-AC-03.01",
"evidence": {
"name": "ref",
"uri": "file:./minder.json",
"annotations":{
"producerName": "Minder",
"producerUri": "https://api.custcodian.dev/"
}
}
},
{
"attribute": "OSPS-AC-03.02",
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-AC-03.02",
"evidence": {
"name": "ref",
"uri": "file:./minder.json",
"annotations":{
"producerName": "Minder",
"producerUri": "https://api.custcodian.dev/"
}
}
},
{
"attribute": "OSPS-BR-01.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-BR-01.01",
"evidence": {
"name": "ref",
"uri": "file:./minder.json",
"annotations":{
"producerName": "Minder",
"producerUri": "https://api.custcodian.dev/"
}
}
},
{
"attribute": "OSPS-BR-03.01",
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-BR-03.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "ref",
"uri": "file:./minder.json",
"annotations":{
"producerName": "Minder",
"producerUri": "https://api.custcodian.dev/"
}
}
},
{
"attribute": "OSPS-BR-03.01",
"target": {
"uri": "https://github.com/mindersec/minder-rules-and-profiles"
},
"evidence": {
"name": "ref",
"uri": "file:./minder.json",
"annotations":{
"producerName": "Minder",
"producerUri": "https://api.custcodian.dev/"
}
}
},
{
"attribute": "OSPS-DO-01.01",
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-DO-01.01",
"evidence": {
"name": "ref",
"uri": "file:./minder.json",
"annotations":{
"producerName": "Minder",
"producerUri": "https://api.custcodian.dev/"
}
}
},
{
"attribute": "OSPS-DO-02.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-DO-02.01",
"evidence": {
"name": "ref",
"uri": "file:./minder.json",
"annotations":{
"producerName": "Minder",
"producerUri": "https://api.custcodian.dev/"
}
}
},
{
"attribute": "OSPS-GV-02.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-GV-02.01",
"evidence": {
"name": "ref",
"uri": "file:./minder.json",
"annotations":{
"producerName": "Minder",
"producerUri": "https://api.custcodian.dev/"
}
}
},
{
"attribute": "OSPS-LE-02.01",
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-LE-02.01",
"evidence": {
"name": "ref",
"uri": "file:./minder.json",
"annotations":{
"producerName": "Minder",
"producerUri": "https://api.custcodian.dev/"
}
}
},
{
"attribute": "OSPS-LE-02.02",
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-LE-02.02",
"evidence": {
"name": "ref",
"uri": "file:./minder.json",
"annotations":{
"producerName": "Minder",
"producerUri": "https://api.custcodian.dev/"
}
}
},
{
"attribute": "OSPS-LE-03.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-LE-03.01",
"evidence": {
"name": "ref",
"uri": "file:./minder.json",
"annotations":{
"producerName": "Minder",
"producerUri": "https://api.custcodian.dev/"
}
}
},
{
"attribute": "OSPS-AC-03.02",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-AC-03.02",
"evidence": {
"name": "ref",
"uri": "file:./minder.json",
"annotations":{
"producerName": "Minder",
"producerUri": "https://api.custcodian.dev/"
}
}
},
{
"attribute": "OSPS-QA-01.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-QA-01.01",
"evidence": {
"name": "ref",
"uri": "file:./minder.json",
"annotations":{
"producerName": "Minder",
"producerUri": "https://api.custcodian.dev/"
}
}
},
{
"attribute": "OSPS-QA-01.02",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-QA-01.02",
"evidence": {
"name": "ref",
"uri": "file:./minder.json",
"annotations":{
"producerName": "Minder",
"producerUri": "https://api.custcodian.dev/"
}
}
},
{
"attribute": "OSPS-QA-02.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-QA-02.01",
"evidence": {
"name": "ref",
"uri": "file:./minder.json",
"annotations":{
"producerName": "Minder",
"producerUri": "https://api.custcodian.dev/"
}
}
},
{
"attribute": "OSPS-QA-04.01",
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-QA-05.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-QA-05.01",
"evidence": {
"name": "ref",
"uri": "file:./minder.json",
"annotations":{
"producerName": "Minder",
"producerUri": "https://api.custcodian.dev/"
}
}
},
{
"attribute": "OSPS-VM-02.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "ref",
"uri": "file:./manual.json",
"annotations": {
"producerName": "Evan Anderson",
"producerUri": "https://github.com/evankanderson"
}
}
},
{
"attribute": "OSPS-VM-02.01",
"evidence": {
"name": "ref",
"uri": "file:./minder.json",
"annotations":{
"producerName": "Minder",
"producerUri": "https://api.custcodian.dev/"
}
}
}
]
}
}
{
"_type": "https://in-toto.io/Statement/v1",
"subject": [
{
"name": "software",
"uri": "https://github.com/mindersec/minder"
},
{
"name": "governance",
"uri": "https://github.com/mindersec/community"
},
{
"name": "policies",
"uri": "https://github.com/mindersec/minder-ruless-and-profiles"
},
{
"name": "command-line binary",
"uri": "pkg:brew/minder"
},
{
"name": "helm chart",
"uri": "oci://minder@sha256:0dea682a64dc3baaee50ce778e07676440ae91aeabe94d41fb3090aa35a90802?repository_url=ghcr.io/mindersec/minder/helm/minder"
}
],
"predicateType": "https://in-toto.io/attestation/scai/v0.3",
"predicate": {
"producer": {
"name": "Evan Anderson",
"uri": "https://github.com/evankanderson"
},
"attributes": [
{
"attribute": "OSPS-AC-01.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "manual",
"content": "R2l0SHViIDJGQSBvbiBvcmcK" // GitHub 2FA
}
},
{
"attribute": "OSPS-AC-02.01",
"evidence": {
"name": "manual",
"content": "Q09ERU9XTkVSUwo=" // CODEOWNERS
}
},
{
"attribute": "OSPS-AC-03.01",
"evidence": {
"name": "manual",
"content": "R2l0SHViIGJyYW5jaCBwcm90ZWN0aW9uCg==" // GitHub branch protection
}
},
{
"attribute": "OSPS-AC-03.02",
"evidence": {
"name": "manual",
"content": "R2l0SHViIGJyYW5jaCBwcm90ZWN0aW9uCg==" // GitHub branch protection
}
},
{
"attribute": "OSPS-BR-01.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "manual",
"content": "bWFudWFsIGF1ZGl0Cg==" // manual audit
}
},
{
"attribute": "OSPS-BR-03.01",
"evidence": {
"name": "manual",
"content": "bWFudWFsIGF1ZGl0Cg==" // manual audit
}
},
{
"attribute": "OSPS-DO-01.01",
"evidence": {
"name": "manual",
"content": "aHR0cHM6Ly9taW5kZXJzZWMuZ2l0aHViLmlvLwo=" // https://mindersec.github.io/
}
},
{
"attribute": "OSPS-DO-02.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "manual",
"content": "R2l0SHViIElzc3Vlcwo=" // GitHub Isssues
}
},
{
"attribute": "OSPS-GV-02.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "manual",
"content": "R2l0SHViIElzc3Vlcwo=" // GitHub Issues
}
},
{
"attribute": "OSPS-LE-02.01",
"evidence": {
"name": "manual",
"content": "QXBhY2hlCg==" // Apache
}
},
{
"attribute": "OSPS-LE-02.02",
"evidence": {
"name": "manual",
"content": "QXBhY2hlCg==" // Apache
}
},
{
"attribute": "OSPS-LE-03.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "manual",
"content": "TElDRU5TRSBmaWxlCg==" // LICENSE file
}
},
{
"attribute": "OSPS-AC-03.02",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "manual",
"content": "TElDRU5TRSBmaWxlCg==" // LICENSE file
}
},
{
"attribute": "OSPS-QA-01.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "manual",
"content": "R2l0SHViIHB1YmxpYyByZXBvCg==" // GitHub public repo
}
},
{
"attribute": "OSPS-QA-01.02",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "manual",
"content": "R2l0SHViIHB1YmxpYyByZXBvCg==" // GitHub public repo
}
},
{
"attribute": "OSPS-QA-02.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "manual",
"content": "Z28ubW9kIGFuZCBwYWNrYWdlLmpzb24K" // go.mod and package.json
}
},
{
"attribute": "OSPS-QA-04.01",
"evidence": {
"name": "manual",
"content": "R2l0SHViIG9yZwo=" // GitHub org
}
},
{
"attribute": "OSPS-QA-05.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "manual",
"content": "bWFudWFsIGF1ZGl0Cg==" // manual audit
}
},
{
"attribute": "OSPS-VM-02.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "manual",
"content": "R2l0SHViIHZ1bG5lcmFiaWxpdHkgcmVwb3J0aW5nCg==" // GitHub vulnerability reporting
}
}
]
}
}
{
"_type": "https://in-toto.io/Statement/v1",
"subject": [
{
"name": "software",
"uri": "https://github.com/mindersec/minder"
},
{
"name": "governance",
"uri": "https://github.com/mindersec/community"
},
{
"name": "policies",
"uri": "https://github.com/mindersec/minder-rules-and-profiles"
},
{
"name": "command-line binary",
"uri": "pkg:brew/minder"
},
{
"name": "helm chart",
"uri": "oci://minder@sha256:0dea682a64dc3baaee50ce778e07676440ae91aeabe94d41fb3090aa35a90802?repository_url=ghcr.io/mindersec/minder/helm/minder"
}
],
"predicateType": "https://in-toto.io/attestation/scai/v0.3",
"predicate": {
"producer": {
"name": "Minder",
"uri": "https://api.custocodian.dev/"
},
"attributes": [
{
"attribute": "OSPS-AC-03.01",
"evidence": {
"name": "minder",
"uri": "https://api.custocodian.dev/v1/mindersec/attestations/osps/ac-03-01"
}
},
{
"attribute": "OSPS-AC-03.02",
"evidence": {
"name": "minder",
"uri": "https://api.custocodian.dev/v1/mindersec/attestations/osps/ac-03-02"
}
},
{
"attribute": "OSPS-BR-01.01",
"target": {
"uri": "https://github.com/mindersec/minder"
},
"evidence": {
"name": "minder",
"uri": "https://api.custocodian.dev/v1/mindersec/attestations/osps/br-01-01/github.com/mindersec/minder"
}
},
{
"attribute": "OSPS-BR-01.01",
"target": {
"uri": "https://github.com/mindersec/minder-rules-and-profiles"
},
"evidence": {
"name": "minder",
"uri": "https://api.custocodian.dev/v1/mindersec/attestations/osps/br-01-01/github.com/mindersec/minder-rules-and-profiles"
}
},
{
"attribute": "OSPS-DO-01.01",
"evidence": {
"name": "minder",
"uri": "https://api.custocodian.dev/v1/mindersec/attestations/osps/do-01-01"
}
},
{
"attribute": "OSPS-DO-02.01",
"evidence": {
"name": "minder",
"uri": "https://api.custocodian.dev/v1/mindersec/attestations/osps/do-02-01"
}
},
{
"attribute": "OSPS-GV-02.01",
"evidence": {
"name": "minder",
"uri": "https://api.custocodian.dev/v1/mindersec/attestations/osps/gv-02-01"
}
},
{
"attribute": "OSPS-LE-02.01",
"evidence": {
"name": "minder",
"uri": "https://api.custocodian.dev/v1/mindersec/attestations/osps/le-02-01"
}
},
{
"attribute": "OSPS-LE-02.02",
"evidence": {
"name": "minder",
"uri": "https://api.custocodian.dev/v1/mindersec/attestations/osps/le-02-02"
}
},
{
"attribute": "OSPS-LE-03.01",
"evidence": {
"name": "minder",
"uri": "https://api.custocodian.dev/v1/mindersec/attestations/osps/le-03-01"
}
},
{
"attribute": "OSPS-AC-03.02",
"evidence": {
"name": "minder",
"uri": "https://api.custocodian.dev/v1/mindersec/attestations/osps/le-03-02"
}
},
{
"attribute": "OSPS-QA-01.01",
"evidence": {
"name": "minder",
"uri": "https://api.custocodian.dev/v1/mindersec/attestations/osps/qa-01-01"
}
},
{
"attribute": "OSPS-QA-01.02",
"evidence": {
"name": "minder",
"uri": "https://api.custocodian.dev/v1/mindersec/attestations/osps/qa-01-02"
}
},
{
"attribute": "OSPS-QA-02.01",
"evidence": {
"name": "minder",
"uri": "https://api.custocodian.dev/v1/mindersec/attestations/osps/qa-02-01"
}
},
{
"attribute": "OSPS-QA-05.01",
"evidence": {
"name": "minder",
"uri": "https://api.custocodian.dev/v1/mindersec/attestations/osps/qa-05-01"
}
},
{
"attribute": "OSPS-VM-02.01",
"evidence": {
"name": "minder",
"uri": "https://api.custocodian.dev/v1/mindersec/attestations/osps/vm-02-01"
}
}
]
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment