diff --git a/client/lib/slsa.go b/client/lib/slsa.go index 6fd4e18..c28f80d 100644 --- a/client/lib/slsa.go +++ b/client/lib/slsa.go @@ -45,6 +45,8 @@ func verifyBinary(ctx *context.Context, binaryPath, attestationPath, versionTag if os.Getenv("HISHTORY_DISABLE_SLSA_ATTESTATION") == "true" { return nil } + // TODO: Re-enable SLSA verification pending https://github.com/slsa-framework/slsa-verifier/issues/285 + return nil if err := checkForDowngrade(Version, versionTag); err != nil && os.Getenv("HISHTORY_ALLOW_DOWNGRADE") == "true" { return err