Clarify the semantics of the optional.creator field in simple signature payload

Signed-off-by: Miloslav Trmač <mitr@redhat.com>
This commit is contained in:
Miloslav Trmač 2022-12-08 21:16:37 +01:00
parent 72e90f76ca
commit 142ac62e41
1 changed files with 2 additions and 1 deletions

View File

@ -210,7 +210,8 @@ Consumers still SHOULD reject any signature where a member of an `optional` obje
### `optional.creator`
If present, this MUST be a JSON string, identifying the name and version of the software which has created the signature.
If present, this MUST be a JSON string, identifying the name and version of the software which has created the signature
(identifying the low-level software implementation; not the top-level caller).
The contents of this string is not defined in detail; however each implementation creating container signatures: