Skip to content

ci: attest release artifacts - #3371

Open
mcc0nnell wants to merge 4 commits into
AOMediaCodec:mainfrom
mcc0nnell:feat/release-provenance
Open

mcc0nnell wants to merge 4 commits into
AOMediaCodec:mainfrom
mcc0nnell:feat/release-provenance

Conversation

@mcc0nnell

@mcc0nnell mcc0nnell commented Sep 18, 2026 •

Copy link
Copy Markdown

Summary

Add GitHub/SLSA build provenance attestations for the Linux, macOS, and Windows release artifact ZIPs.

Each release workflow already builds a deterministic local ZIP and uploads that exact file to the GitHub release. This change grants the workflows the OIDC/attestation permissions they need and attests each ZIP immediately before upload.

No artifact contents, filenames, build flags, or upload paths change.

Current gap

The current v1.4.2 release publishes:

  • linux-artifacts.zip
  • macOS-artifacts.zip
  • windows-artifacts.zip

GitHub records SHA-256 digests for all three, but the release artifacts have no GitHub provenance attestations. For example, gh attestation verify for the current Linux and macOS ZIPs returns 404.

Change

Each artifact workflow now:

  1. creates the release ZIP exactly as before;
  2. generates build provenance for that exact ZIP with actions/attest;
  3. uploads the same ZIP to the existing release.

The attestation action is pinned to the full commit for v4.

Validation

  • current v1.4.2 release ZIPs have recorded SHA-256 digests
  • current Linux/macOS release ZIPs return no existing GitHub provenance attestation
  • actionlint on all three changed workflows: PASS
  • git diff --check: PASS
  • no competing provenance PR found

@y-guyon

y-guyon commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

Thank you for your interest in libavif.

https://github.com/actions/attest-build-provenance#usage says:

new implementations should use actions/attest instead

@mcc0nnell

Copy link
Copy Markdown
Author

Updated — switched all three release workflows to pinned actions/attest@v4 while keeping the same subject-path inputs. actionlint passes on all three changed workflows. Thanks for the pointer.

@y-guyon y-guyon left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you

avifdec
avifgainmaputil
- name: Attest release artifact
uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Any reason not to use the latest tag?

Comment on lines +10 to +11
id-token: write
attestations: write

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requiring more permissions is unfortunate but seems necessary.

https://github.com/actions/attest#usage says

The artifact-metadata permission is necessary to create the artifact storage record.

Any clue why this is not needed here?

@@ -7,6 +7,8 @@ on:

permissions:
contents: write

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do you know if write is useful here? Could it be switched to read?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants