You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
***Scope 2 - Focusing on Trust boundaries:** Includes all of the areas of Scope 1 above, with deeper review focus of the following areas:
261
261
* Trusted execution environment assessment
262
262
* Handling of trust boundaries
263
263
* Attestation and non-repudiation across boundaries
@@ -295,10 +295,10 @@ has concluded:
295
295
***Signed Git Commits**\
296
296
The OCP GitHub repository is configured to require all commits to be [signed](https://docs.github.com/en/authentication/managing-commit-signature-verification/signing-commits). Please remember this when preparing the submission (use [--amend --signoff](https://stackoverflow.com/a/15667644) if you forget).
297
297
***SRF Pull Request Path**\
298
-
The location of the signed SFRs should be in Reports/$Vendor/$Year/$Product. As a convenience,
298
+
The signed SFRs are published to the location Reports/$Vendor/$Year/$Product. As a convenience,
299
299
the submission may choose to additionally include the human-readable SFR documents.
300
300
***SRP Public Key Pull Request Path**\
301
-
The location of the signing public key should be in SRP_certificates/$SRP. These are to be published and maintained by
301
+
The public signing key of each SRP is published to the location SRP_certificates/$SRP. These are to be published and maintained by
302
302
the SRP, and may be revoked by the TAC (see [Disqualification](#Disqualification) above).
0 commit comments