Skip to content

Generate SLSA provenance for your release builds #729

Description

@laurentsimon

Hi

I am one of the authors of the SLSA3+ builder for GitHub workflows (https://github.com/slsa-framework/slsa-github-generator projects).

We released the v1 of the SLSA3+ builder last week. It will be officially announced during the Open Source Summit next week.

We are reaching out to projects to see if they'd be interested in using it. The scorecard project has recently added support for their Linux amd64 build.

Practically speaking, adoption should be easy. The configuration file is similar to Goreleaser's, except that we support a single build for this first release. You can select an OS/Arch to generate provenance for, and disable the correpsonding build for Goreleaser using the ignore option, as explained in builders/go/README.md#migration-from-goreleaser

I have prepared #730 to help you see what the changes are.

Feedback welcome!

/cc @asraa @ ianlewis

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions