Snap build transparency and trust

@chipaca That would depend on two questions:

  1. Is there is a standard way to retrieve the manifest used to produce the snap, or is the manifest embedded in the snap?
  2. Does the manifest always contain all the information needed to build the snap? At least as of last year, the manifest sometimes omitted important properties of the build environment, such as which repositories were configured. For example, refer to YAMLs for snaps built using PPAs
1 Like