Markdown Version | Session Recording

Session Date/Time: 14 Aug 2023 15:00

SCITT

Summary

The meeting focused heavily on the API's content type and representation, particularly the trade-offs between CBOR/COSE for efficiency and cryptographic integrity versus JSON/YAML for developer experience and tooling compatibility. While the core authenticity structures (COSE) are to remain untouched, there was significant debate regarding the API's protocol messages. Progress was reported on the SCITT emulator, and a new proposal for an extended Vendor Response File (VRF) structure was introduced. Concerns were raised regarding the working group's charter scope in relation to query/storage capabilities and specific software supply chain document formats.

Key Discussion Points

Decisions and Action Items

Next Steps