Skip to content

ci(release): sign every asset and attach SLSA provenance - #101

Merged
mescon merged 1 commit into
masterfrom
ci/release-provenance
Sep 14, 2026
Merged

mescon merged 1 commit into
masterfrom
ci/release-provenance

Conversation

@mescon

@mescon mescon commented Sep 14, 2026

Copy link
Copy Markdown
Owner

Three jobs at the end of the release workflow: sign every asset without a detached signature (the old job covered only the Arch packages and the repo database, contrary to what the docs said), hash the whole asset list, and attach a SLSA provenance statement (release-assets.intoto.jsonl) signed through Sigstore by the SLSA generic generator v2.1.0. Adds a provenance-only dispatch input so the provenance jobs can be exercised against an existing release without uploading. Linted with actionlint (no new findings). Docs corrected to say what was signed up to 0.41.0.

Scorecard: Signed-Releases goes from 8 to 10 per release that carries provenance; the generator is referenced by tag (required by slsa-verifier), which Pinned-Dependencies will note.

The signing job only ever covered the Arch packages and their repository
database, although the README and the assurance document said every
asset was signed; the Debian packages, the telemetry helpers and the
SBOMs went out bare. The release workflow now ends with three jobs that
run once every asset is attached: one signs every asset that has no
detached signature yet with the same key, one hashes the whole asset
list, and one hands the list to the SLSA generic generator, which signs
a build provenance statement through Sigstore and attaches it as
release-assets.intoto.jsonl. slsa-verifier can then confirm an asset
against the repository and the tag. The generator is referenced by tag
because slsa-verifier cannot verify its ref otherwise. A provenance-only
dispatch input skips every channel and exercises the provenance jobs
against an existing release without uploading anything, which is how the
jobs get tested before the next release. The docs now say what was
signed up to 0.41.0 instead of overstating it.
@mescon
mescon enabled auto-merge September 14, 2026 21:02
@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
C Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

@mescon
mescon merged commit 3700e42 into master Sep 14, 2026
16 of 17 checks passed
@mescon
mescon deleted the ci/release-provenance branch September 22, 2026 14:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant