Skip to content

Add build attestations to all uploaded/released artifacts.#1964

Draft
andylockran wants to merge 6 commits intoopen-telemetry:mainfrom
lockran:main
Draft

Add build attestations to all uploaded/released artifacts.#1964
andylockran wants to merge 6 commits intoopen-telemetry:mainfrom
lockran:main

Conversation

@andylockran
Copy link
Copy Markdown

As a step suggested in #1963 , add the GH attestations for binaries produced by the Github workflows on this repository, so that all artefacts generated as a result of the workflows have provenance checks.

It may be that more work needs to be done on deciding how to manage the lifecycle of historic attestations.

https://github.com/actions/attest-build-provenance

Loading
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants