Skip to content

Conversation

@MadelineAu
Copy link
Collaborator

No description provided.

@vercel
Copy link

vercel bot commented Jan 6, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Review Updated (UTC)
eigencloud-docs Ready Ready Preview Jan 6, 2026 7:00pm

sidebar_position: 5
---

Verifiable builds provide cryptographic proof of the source code and build process for EigenCompute applications. EigenCompute verifiable builds
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Make it clear they are linked: "Verifiable builds provide cryptographic proof linking the source code and build process..."

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done


When submitting a build with dependencies, provenance is validated and dependency digests are recorded in the build's SLSA provenance.

The EigenCompute TLS and KMS clients are prebuilt and the digests included in all EigenCompute applications.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In the Read me of the EigenCompute containers repo you can see the official digests there that we keep up to date. Maybe just link to those here?

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done


EigenCompute applications with dependencies other than the TLS and KMS clients must submit those verifiable builds and include
the dependency's image digest when verifiably building the application.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we should include the Google SLSA Providence public key that we use to verify everything? And possibly link out to Google's documentation on SLSA provenance.

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yep - I need to add another topic for 'how to verify' and include those.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants