We are looking into using in-toto in combination with Grafeas. We tried out the demo that is available on GitHub. That is based on an older version and we are looking into updating it.
But we were wondering why this was build as a separate command line tool. And not just as a transporter in in-toto. Could someone elaborate on these design choices? Do you think they are still valid? Or is there already an idea on how to move forward with this?
PS: I also send the below message to in-to...@googlegroups.com
. But can't find that group. So I hope it is not double somewhere now