Hello,
I would like to add a log to the witness-network lists.
Operator: fremverk ApS (Denmark)
Origin: log.frem.sh
Vkey: log.frem.sh+4e9c5de6+AcfzmSNWSmxIklo06ELrJzqR8VNCsdV3Sz9pFqL+5lH+
Checkpoint: https://log.frem.sh/checkpoint
Tiles: https://log.frem.sh/tile/...
Formats: c2sp.org/tlog-tiles, c2sp.org/tlog-checkpoint
Current size: 457 (grows a few leaves per day)
Add-checkpoint: ~4 per day (ceiling 96/day)
Requested list: staging - happy to be placed wherever you think appropriate
Contact: Soren Hartvig Jensen <info@fremverk.com>, +45 91886000
The log records SLSA provenance attestations for software we build. Each leaf
is the SHA-256 of a DSSE envelope, so the log is publicly verifiable without
revealing which repository produced an entry.
On the submission rate: our publisher runs every fifteen minutes but returns
early when the tree has not advanced, before contacting any witness. The tree
has grown 3.8 leaves per day over the last 119 days, so in practice witnesses
would see roughly four add-checkpoint requests a day rather than ninety-six.
Two things that may be relevant to you:
- Our client-side verifier already implements both cosignature types --
Ed25519 (0x04) and ML-DSA-44 (0x06), including the subtree/v1
cosigned-message construction. If ML-DSA-44 support is a gating concern for
the production tier, we are ready for it today and happy to be a test
consumer.
- Verification happens entirely on the caller's machine. Our CLI recomputes
every hash locally and never asks our server for a verdict.
With thanks,
|
|
|
|
Med venlig hilsen / best regards
|
|
Søren Hartvig Jensen
|
|
CEO, Co-founder & Enterprise Cloud Architect
|
|
|
|
|
|
|
|