ci: attest release artifact provenance - #8
Conversation
GenVM PR actionsTick a box to run it (the box unticks itself when handled). Actions only run while the PR has the
Full GenVM CI runs only when |
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
Safety
This PR does not create a tag or publish a release. The new step runs only when the existing manually dispatched release workflow reaches
release-publish.Validation
actionlint .github/workflows/release.yamlgit diff --checkConsumer
The matching genlayer-e2e artifact-validation work verifies these attestations against
genlayerlabs/genvm-manager/.github/workflows/release.yamland the frozen GenVM source SHA before caching release bytes.