Skip to content

Try actions/attest-build-provenance for our builds #170

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Nov 24, 2024
Merged

Conversation

malor
Copy link
Member

@malor malor commented Nov 23, 2024

Per https://github.blog/news-insights/product-news/introducing-artifact-attestations-now-in-public-beta/, this should allow users to verify attestations using GitHub CLI.

@malor malor requested a review from ikalnytskyi November 23, 2024 21:40
Copy link
Member

@ikalnytskyi ikalnytskyi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wow! I didn't know there's an official action now. I wonder how it works? As I understand it, it doesn't upload a sigstore attestion as an artifact but rather store it somewhere on the organization level.

@malor
Copy link
Member Author

malor commented Nov 24, 2024

Wow! I didn't know there's an official action now. I wonder how it works? As I understand it, it doesn't upload a sigstore attestion as an artifact but rather store it somewhere on the organization level.

That's my understanding as well. Let's give it a try!

@malor malor merged commit b20f641 into master Nov 24, 2024
8 checks passed
@malor malor deleted the attestation branch November 24, 2024 11:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

2 participants