pub const ARTIFACT_HASH: &str = "artifact.hash";
Expand description
The full hash value (see glossary), often found in checksum.txt on a release of the artifact and used to verify package integrity.
The specific algorithm used to create the cryptographic hash value is not defined. In situations where an artifact has multiple cryptographic hashes, it is up to the implementer to choose which hash value to set here; this should be the most secure hash algorithm that is suitable for the situation and consistent with the corresponding attestation. The implementer can then provide the other hash values through an additional set of attribute extensions as they deem necessary.
§Examples
9ff4c52759e2c4ac70b7d517bc7fcdc1cda631ca0045271ddd1b192544f8a3e9