RESEARCH / RFCS

Proposals, before they're final.

RFCs are how changes to CDK's public specifications get proposed, argued about, and decided — in the open, before they ship.

ALL PROPOSALS

Six proposals, four still open.

0001

Predicate Type Registry

Formalizes how new predicate types are proposed, versioned, and deprecated.

Accepted
0002

Multi-Signature Attestations

Allows more than one signer on a single attestation, for dual-control approvals.

In Review
0003

Evidence Retention Policy Format

A standard way to express how long evidence must be kept, per framework.

In Review
0004

Kubernetes Admission Controller

Blocks non-attested deployments at the cluster level rather than the pipeline level.

Draft
0005

Trust Graph Query Language

A query syntax for traversing the Evidence Graph programmatically.

Draft
0006

Offline Verification Bundles

Superseded by the standard Sigstore bundle format once it stabilized.

Withdrawn
HOW IT WORKS

Four stages. No private ones.

01

Draft

A proposal is written up and opened for comment.

02

In Review

Open discussion, including from outside the core team.

03

Accepted

Merged into the relevant specification's next version.

04

Withdrawn

Closed without merging — the reasoning stays public either way.

Have a proposal of your own?

RFCs are open to anyone, not just the core team.