Conversation
|
Thank you for your interest in libavif. https://github.com/actions/attest-build-provenance#usage says:
|
|
Updated — switched all three release workflows to pinned |
| avifdec | ||
| avifgainmaputil | ||
| - name: Attest release artifact | ||
| uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4 |
There was a problem hiding this comment.
Any reason not to use the latest tag?
| id-token: write | ||
| attestations: write |
There was a problem hiding this comment.
Requiring more permissions is unfortunate but seems necessary.
https://github.com/actions/attest#usage says
The
artifact-metadatapermission is necessary to create the artifact storage record.
Any clue why this is not needed here?
| @@ -7,6 +7,8 @@ on: | |||
|
|
|||
| permissions: | |||
| contents: write | |||
There was a problem hiding this comment.
Do you know if write is useful here? Could it be switched to read?
Summary
Add GitHub/SLSA build provenance attestations for the Linux, macOS, and Windows release artifact ZIPs.
Each release workflow already builds a deterministic local ZIP and uploads that exact file to the GitHub release. This change grants the workflows the OIDC/attestation permissions they need and attests each ZIP immediately before upload.
No artifact contents, filenames, build flags, or upload paths change.
Current gap
The current v1.4.2 release publishes:
linux-artifacts.zipmacOS-artifacts.zipwindows-artifacts.zipGitHub records SHA-256 digests for all three, but the release artifacts have no GitHub provenance attestations. For example,
gh attestation verifyfor the current Linux and macOS ZIPs returns 404.Change
Each artifact workflow now:
actions/attest;The attestation action is pinned to the full commit for v4.
Validation
actionlinton all three changed workflows: PASSgit diff --check: PASS