-
Notifications
You must be signed in to change notification settings - Fork 409
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
v0.13.0 release failed provenance validation #978
Comments
ianlewis
added a commit
to ianlewis/ko
that referenced
this issue
Mar 13, 2023
Fixes ko-build#978 Uses the `attestation-name` output from `generator_generic_slsa3.yml` to get the artifact name to download. Also removes the `compile-generator` input as slsa-framework/slsa-github-generator#1163 was fixed. Signed-off-by: Ian Lewis <[email protected]>
ianlewis
added a commit
to ianlewis/ko
that referenced
this issue
Mar 13, 2023
Fixes ko-build#978 Uses the `attestation-name` output from `generator_generic_slsa3.yml` to get the artifact name to download. Also removes the `compile-generator` input as slsa-framework/slsa-github-generator#1163 was fixed. Signed-off-by: Ian Lewis <[email protected]>
ianlewis
added a commit
to ianlewis/ko
that referenced
this issue
Mar 13, 2023
Fixes ko-build#978 Uses the `attestation-name` output from `generator_generic_slsa3.yml` to get the artifact name to download. Also removes the `compile-generator` input as slsa-framework/slsa-github-generator#1163 was fixed. Signed-off-by: Ian Lewis <[email protected]>
Apologies. It seems we updated the default name of the attestation artifact that gets uploaded. #980 addresses this by using the |
Thanks for fixing this @ianlewis! |
imjasonh
pushed a commit
that referenced
this issue
Mar 13, 2023
Fixes #978 Uses the `attestation-name` output from `generator_generic_slsa3.yml` to get the artifact name to download. Also removes the `compile-generator` input as slsa-framework/slsa-github-generator#1163 was fixed. Signed-off-by: Ian Lewis <[email protected]>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
The release workflow failed during verification: https://github.com/ko-build/ko/actions/runs/4386793516/jobs/7681560335
Looking at the release artifacts, here: https://github.com/ko-build/ko/releases/tag/v0.13.0
There's a
multiple.intoto.jsonl
uploaded by the provenance generation workflow, but the verification step seems to be looking forattestation.intoto.jsonl
. Please let me know if this is a bug onko
's end, or if this is a misconfiguration, or a bug in the SLSA provenance generation.cc @laurentsimon @ianlewis
The text was updated successfully, but these errors were encountered: