Skip to content

Sign build provenance for release packages - #15

Merged
Commanderx-code merged 3 commits into
mainfrom
ci/build-attestations
Sep 25, 2026
Merged

Commanderx-code merged 3 commits into
mainfrom
ci/build-attestations

Conversation

@Commanderx-code

Copy link
Copy Markdown
Owner

Change

Release packages had checksums but no signatures. SHA256SUMS is uploaded to the same release as the packages, so it catches a damaged download but not a release whose files were replaced. This PR adds signed SLSA build provenance to each package.

New attest job in linux-packages.yml:

  • It runs only on tag pushes, and only after build, every install-deb, install-rpm and arch job passes.
  • It downloads the packages and arch-package artifacts, rechecks their checksums, and signs provenance for the .deb, .rpm and Arch package using actions/attest v4.2.2, pinned to 1e69f48.
  • It is the only job granted id-token, attestations and artifact-metadata write access. The build jobs stay read-only.

release:draft now checks each package before creating the draft. It runs gh attestation verify on every package and requires all of the following:

  • the signer is this repository's .github/workflows/linux-packages.yml;
  • the source ref is refs/tags/<tag>;
  • the source digest is the tagged commit;
  • the signing ran on a GitHub-hosted runner.

If any check fails, no draft is created. The release notes also tell users how to run the same check themselves.

Docs:

  • docs/installation.md shows how to verify a downloaded package with gh attestation verify.
  • docs/releases.md describes the attest job and the new check in release:draft.

Validation

  • npm run check: passed.
  • npm test: 78 passed.
  • node --check scripts/release-draft.mjs: passed.
  • The workflow YAML parses. gh 2.101.0 supports every verify flag used.
  • This PR's CI confirms the workflow is valid, including the new job-level permissions. It cannot run the attest job, because that job runs only on tags. It will run for the first time on the next release tag, and release:draft refuses to create a draft if that step fails.

Review notes

  • Attestations start with the next release. v0.7.1 and earlier have none, so the installation docs say "0.7.2 and later".
  • The attestation is signed after the install tests, in the same workflow run, over the exact files the draft publishes. The signer identity is the linux-packages.yml workflow at the release tag.

🤖 Generated with Claude Code

Commanderx-code and others added 3 commits September 25, 2026 13:33
Release assets had checksums but no signature. SHA256SUMS sits on the same
release as the packages, so it detects damaged downloads but not a
replaced release.

A tag-only attest job now runs after every build and install job passes,
downloads the packages and Arch artifacts, rechecks their checksums and
signs SLSA build provenance with actions/attest. It is the only job with
signing permissions. release:draft verifies each package's attestation
(this repository's linux-packages.yml, this tag and commit, a GitHub-hosted
runner) before creating a draft, and the release notes tell users how to
check a download with gh attestation verify.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Commanderx-code
Commanderx-code merged commit 9dae16e into main Sep 25, 2026
15 checks passed
@Commanderx-code
Commanderx-code deleted the ci/build-attestations branch September 25, 2026 17:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant