Skip to content

docs(autonomy): decide whether agent-run artifact attestation is in scope #4703

Description

@kyle-sexton

Problem

Nothing in the marketplace covers signed attestation of an agent-produced change (what instructions,
review prompts, workflows and runs produced a commit, signed and verifiable). The only hit for
slsa|in-toto|attest-build-provenance|sigstore across the plugins was the old provenance README,
and that hit was a disclaimer ("prose provenance, not software supply chain"). The plugin has since
been renamed attribution (#4590), which removes even the name overlap. This is a scope question,
not a defect.

Evidence

  • Three senses of "provenance" were conflated in the research that raised this: prose provenance
    (owned by attribution), claim provenance (a qualifier traveling with its number; handled by the
    discovery:research joint-inference criterion), and artifact provenance (this issue, no home).
  • actions/attest-build-provenance (v4+) wraps actions/attest and emits a SLSA build predicate from
    the runner context, with no slot for prompts, model, skill set or instruction-file digests.
  • actions/attest accepts a custom predicate-type URI and a predicate body (up to 16 MB);
    verification then needs gh attestation verify --predicate-type <uri>, because the default
    enforces slsa.dev/provenance/v1.
  • The vetted in-toto predicate list has no predicate for AI-agent runs, so adoption means defining one.
  • GitHub documents that only signature.certificate and verifiedTimestamps cannot be manipulated
    by the workflow: a signature proves which workflow emitted the JSON, not that the digests inside
    match the commit, so a re-hash step is needed either way.
  • Carried from the original item, not re-checked this pass: the GitHub docs claims above.

Proposed approach

Decide one of:

  1. Out of scope (CI/CD supply-chain tooling, not agent tooling). Close this issue.
  2. A new plugin, only if someone wants the predicate designed.
  3. A leaf under autonomy (the item's lean): autonomy's return-accounting contract
    (plugins/autonomy/.../return-accounting.md) already reasons about what evidence an unattended
    run leaves and who attests it; a signed run attestation would be that contract's missing artifact.

Acceptance criteria

  • A recorded decision (ADR or a line in the autonomy docs) naming which option was chosen and why.
  • If option 2 or 3: a follow-up issue defining the predicate type URI, its fields, and the re-hash
    verification step.

Constraints and gotchas

  • Signing does not validate content; any design must re-hash inputs at verification time.
  • Do not reuse the slsa.dev/provenance/v1 predicate for agent-run data.

Context

Source: local handoff item 20260911-004136-artifact-attestation-has-no-home.md (retired into this
issue). Related: #4590 (provenance renamed to attribution).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority: lowNice-to-have, cosmetic, or speculative; opportunistic.status: needs-decisionAwaiting a human or maintainer judgment call.wayfind: designWayfind decision item: design-space or domain-model decision; human in the loop.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions