We are excited to announce completion of a source code audit of the in-toto Python and Go implementations along with an architectural review of the specification. The audit was ordered by the Open Source Technology Improvement Fund (OSTIF) and conducted by X41 D-Sec GmbH over the course of three weeks in February 2023.
Motivation
While in-toto has previously undergone a security review by the CNCF’s TAG-Security, it had not been formally audited thus far. The in-toto implementations are currently used in production and the Python reference implementation reached v1.0 maturity in late 2020. The Go implementation has been the experimental testbed for several new features including the in-toto Attestation Framework. We decided in our roadmap that it is time to release v1.0 of the specification and to apply for graduation at the CNCF. To formally underline our confidence in the specification we initiated the in-toto audit.