Mechanism · Confidential multi-party verification
Guarantees depend on the host software stack and on review
On this page
SignificantTheoretical argumentOpen
Cove's developers state that compromise of the Docker daemon, host kernel or TEE stack breaks all guarantees. They also state that Docker policy alone cannot prove that guest code cannot generate a quote if the platform exposes quote instructions globally, and that compiled workflow bundles are hashed and reviewable but not signed by a publisher key.
Sources: [2]