-
-
Notifications
You must be signed in to change notification settings - Fork 213
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
SLSA provenance attestation #922
Conversation
You want two things in one workflow ... |
Yeah it's not always easy to determine whether an action is a composite |
It is a reusable one. It cannot live as a step.
|
I think this level3 thing must be in your build process. |
I think I rabbit-holed on the actions provided by the SLSA framework due to the isolation requirement for level 3. The annoying thing about using a reusable workflow for a GitHub build provenance attestation is that you then need to verify it using the name of the repo that contains the reusable workflow that created the attestation. It looks like I need to read into this more. |
Co-authored-by: Viktor Szépe <[email protected]>
See johnbillion/action-wordpress-plugin-attestation#12