Skip to content

Add build attestations. Closes #343 #371

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

orf
Copy link
Contributor

@orf orf commented Oct 16, 2024

@zanieb
Copy link
Member

zanieb commented Oct 16, 2024

Thank you! Should we only be attesting the artifacts on main?

zanieb added a commit that referenced this pull request Jan 10, 2025
Follow up on feedback from #371 and the previous work from @orf which I
cherry-picked.

This adds build attestations for the builds using
[actions/attest-build-provenance](https://github.com/actions/attest-build-provenance).

Closes #343

### Test Plan

Did a trial CI run which results in attestations like below for
`cpython-3.10-aarch64-unknown-linux-gnu-lto`

*
https://github.com/samypr100/python-build-standalone/attestations/4246020
* https://search.sigstore.dev/?logIndex=160192732

Co-authored-by: Thomas Forbes <tom.forbes@gitguardian.com>
Co-authored-by: Zanie Blue <contact@zanie.dev>
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Add release atteststions
2 participants