Problem
Nothing in the marketplace covers signed attestation of an agent-produced change (what instructions,
review prompts, workflows and runs produced a commit, signed and verifiable). The only hit for
slsa|in-toto|attest-build-provenance|sigstore across the plugins was the old provenance README,
and that hit was a disclaimer ("prose provenance, not software supply chain"). The plugin has since
been renamed attribution (#4590), which removes even the name overlap. This is a scope question,
not a defect.
Evidence
- Three senses of "provenance" were conflated in the research that raised this: prose provenance
(owned by attribution), claim provenance (a qualifier traveling with its number; handled by the
discovery:research joint-inference criterion), and artifact provenance (this issue, no home).
actions/attest-build-provenance (v4+) wraps actions/attest and emits a SLSA build predicate from
the runner context, with no slot for prompts, model, skill set or instruction-file digests.
actions/attest accepts a custom predicate-type URI and a predicate body (up to 16 MB);
verification then needs gh attestation verify --predicate-type <uri>, because the default
enforces slsa.dev/provenance/v1.
- The vetted in-toto predicate list has no predicate for AI-agent runs, so adoption means defining one.
- GitHub documents that only
signature.certificate and verifiedTimestamps cannot be manipulated
by the workflow: a signature proves which workflow emitted the JSON, not that the digests inside
match the commit, so a re-hash step is needed either way.
- Carried from the original item, not re-checked this pass: the GitHub docs claims above.
Proposed approach
Decide one of:
- Out of scope (CI/CD supply-chain tooling, not agent tooling). Close this issue.
- A new plugin, only if someone wants the predicate designed.
- A leaf under
autonomy (the item's lean): autonomy's return-accounting contract
(plugins/autonomy/.../return-accounting.md) already reasons about what evidence an unattended
run leaves and who attests it; a signed run attestation would be that contract's missing artifact.
Acceptance criteria
Constraints and gotchas
- Signing does not validate content; any design must re-hash inputs at verification time.
- Do not reuse the
slsa.dev/provenance/v1 predicate for agent-run data.
Context
Source: local handoff item 20260911-004136-artifact-attestation-has-no-home.md (retired into this
issue). Related: #4590 (provenance renamed to attribution).
Problem
Nothing in the marketplace covers signed attestation of an agent-produced change (what instructions,
review prompts, workflows and runs produced a commit, signed and verifiable). The only hit for
slsa|in-toto|attest-build-provenance|sigstoreacross the plugins was the oldprovenanceREADME,and that hit was a disclaimer ("prose provenance, not software supply chain"). The plugin has since
been renamed
attribution(#4590), which removes even the name overlap. This is a scope question,not a defect.
Evidence
(owned by
attribution), claim provenance (a qualifier traveling with its number; handled by thediscovery:researchjoint-inference criterion), and artifact provenance (this issue, no home).actions/attest-build-provenance(v4+) wrapsactions/attestand emits a SLSA build predicate fromthe runner context, with no slot for prompts, model, skill set or instruction-file digests.
actions/attestaccepts a custompredicate-typeURI and apredicatebody (up to 16 MB);verification then needs
gh attestation verify --predicate-type <uri>, because the defaultenforces
slsa.dev/provenance/v1.signature.certificateandverifiedTimestampscannot be manipulatedby the workflow: a signature proves which workflow emitted the JSON, not that the digests inside
match the commit, so a re-hash step is needed either way.
Proposed approach
Decide one of:
autonomy(the item's lean):autonomy's return-accounting contract(
plugins/autonomy/.../return-accounting.md) already reasons about what evidence an unattendedrun leaves and who attests it; a signed run attestation would be that contract's missing artifact.
Acceptance criteria
verification step.
Constraints and gotchas
slsa.dev/provenance/v1predicate for agent-run data.Context
Source: local handoff item 20260911-004136-artifact-attestation-has-no-home.md (retired into this
issue). Related: #4590 (provenance renamed to attribution).