Skip to content

Conversation

andylockran
Copy link

As a step suggested in #1963 , add the GH attestations for binaries produced by the Github workflows on this repository, so that all artefacts generated as a result of the workflows have provenance checks.

It may be that more work needs to be done on deciding how to manage the lifecycle of historic attestations.

https://github.com/actions/attest-build-provenance

Copy link

linux-foundation-easycla bot commented Sep 15, 2025

CLA Not Signed

@tylerbenson
Copy link
Member

@maxday could you take a look at this PR. I'm curious if you think this would be a better solution than your proposal.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants