-
Notifications
You must be signed in to change notification settings - Fork 492
Add SLSA3 provenance to your builds #3468
Copy link
Copy link
Closed as not planned
Labels
Status: Needs volunteerbuildPull requests that updates CI codePull requests that updates CI codeclosed_staleClosed. Idle for more than 6 months. Please feel free to re-open to bring it back to lifeClosed. Idle for more than 6 months. Please feel free to re-open to bring it back to lifegithub_actionsPull requests that update Github_actions codePull requests that update Github_actions code
Description
Since you appear to be using goreleaser in your GH workflow, please consider tweaking your workflow to add SLSA3 provenance:
https://github.blog/changelog/2024-06-25-artifact-attestations-is-generally-available/
https://github.blog/enterprise-software/devsecops/enhance-build-security-and-reach-slsa-level-3-with-github-artifact-attestations/
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Status: Needs volunteerbuildPull requests that updates CI codePull requests that updates CI codeclosed_staleClosed. Idle for more than 6 months. Please feel free to re-open to bring it back to lifeClosed. Idle for more than 6 months. Please feel free to re-open to bring it back to lifegithub_actionsPull requests that update Github_actions codePull requests that update Github_actions code