Skip to content

fix: unbreak + add images + improvements for provenance.yml#1868

Merged
HastD merged 2 commits intosecureblue:livefrom
HastD:provenance-verification-fix
Jan 27, 2026
Merged

fix: unbreak + add images + improvements for provenance.yml#1868
HastD merged 2 commits intosecureblue:livefrom
HastD:provenance-verification-fix

Conversation

@HastD
Copy link
Copy Markdown
Collaborator

@HastD HastD commented Jan 27, 2026

  • Switch to same method used in build process for installing crane and slsa-verifier. This additionally works on the ubuntu-slim runner. Also make curl command for crane installation more efficient both here and in the build process.
  • Add IoT images to provenance verification workflow.
  • Specify live branch for provenance verification.
  • Improve provenance verification logic so it doesn't immediately stop when one image fails but instead continues checking all images.

* Switch to same method used in build process for installing `crane` and
  `slsa-verifier`. This additionally works on the `ubuntu-slim` runner.
  Also make curl command for crane installation more efficient both here
  and in the build process.
* Add IoT images to provenance verification workflow.
* Specify `live` branch for provenance verification.
* Improve provenance verification logic so it doesn't immediately stop
  when one image fails but instead continues checking all images.
RoyalOughtness
RoyalOughtness previously approved these changes Jan 27, 2026
@HastD HastD merged commit a770fa9 into secureblue:live Jan 27, 2026
11 checks passed
@HastD HastD deleted the provenance-verification-fix branch January 27, 2026 22:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants