diff --git a/README.md b/README.md index 2ac4ff815790692de7f879c0ac21f01648bde9f4..0d6e2766cbd6dd639a64a375d84c968ab8b4c0a1 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,8 @@ # Rekor -## Early Development / Experimental use only. +### Note that this CLI application will undergo refactoring to point at the rekor-server instead of direct connections to the trillian backend (which is what it does right now). + +Early Development / Experimental use only. Attestation and provenance of software, its generated artefacts and information on tools used to build said software, relies on an often disparate set of different approaches and data formats. The solutions that do exist, often rely on digests that are stored on insecure systems that are susceptible to tampering and can lead to various attacks such as swapping out of digests , replay attacks.