Skip to content

fix: generate correct provenance on non-default branches#1637

Merged
RoyalOughtness merged 1 commit intosecureblue:livefrom
HastD:branch-provenance
Nov 30, 2025
Merged

fix: generate correct provenance on non-default branches#1637
RoyalOughtness merged 1 commit intosecureblue:livefrom
HastD:branch-provenance

Conversation

@HastD
Copy link
Copy Markdown
Collaborator

@HastD HastD commented Nov 29, 2025

The generated provenance should only be for the latest tag on the default branch; otherwise, the tag has a form generated from the branch name or PR number and the OS major version number.

Also simplified the base image verification steps in the build workflows so they don't rely on assumptions about secureblue image naming conventions.

The generated provenance should only be for the `latest` tag on the
default branch; otherwise, the tag has a form generated from the branch
name or PR number and the OS major version number.

Also simplified the base image verification steps in the build workflows
so they don't rely on assumptions about secureblue image naming
conventions.
@RoyalOughtness RoyalOughtness enabled auto-merge (squash) November 30, 2025 21:17
@RoyalOughtness RoyalOughtness merged commit cded742 into secureblue:live Nov 30, 2025
14 of 15 checks passed
@HastD HastD deleted the branch-provenance branch November 30, 2025 21:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants