Sign build provenance for release packages - #15
Merged
Merged
Conversation
Release assets had checksums but no signature. SHA256SUMS sits on the same release as the packages, so it detects damaged downloads but not a replaced release. A tag-only attest job now runs after every build and install job passes, downloads the packages and Arch artifacts, rechecks their checksums and signs SLSA build provenance with actions/attest. It is the only job with signing permissions. release:draft verifies each package's attestation (this repository's linux-packages.yml, this tag and commit, a GitHub-hosted runner) before creating a draft, and the release notes tell users how to check a download with gh attestation verify. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Change
Release packages had checksums but no signatures.
SHA256SUMSis uploaded to the same release as the packages, so it catches a damaged download but not a release whose files were replaced. This PR adds signed SLSA build provenance to each package.New
attestjob inlinux-packages.yml:build, everyinstall-deb,install-rpmandarchjob passes.packagesandarch-packageartifacts, rechecks their checksums, and signs provenance for the.deb,.rpmand Arch package usingactions/attestv4.2.2, pinned to1e69f48.id-token,attestationsandartifact-metadatawrite access. The build jobs stay read-only.release:draftnow checks each package before creating the draft. It runsgh attestation verifyon every package and requires all of the following:.github/workflows/linux-packages.yml;refs/tags/<tag>;If any check fails, no draft is created. The release notes also tell users how to run the same check themselves.
Docs:
docs/installation.mdshows how to verify a downloaded package withgh attestation verify.docs/releases.mddescribes theattestjob and the new check inrelease:draft.Validation
npm run check: passed.npm test: 78 passed.node --check scripts/release-draft.mjs: passed.gh2.101.0 supports every verify flag used.attestjob, because that job runs only on tags. It will run for the first time on the next release tag, andrelease:draftrefuses to create a draft if that step fails.Review notes
linux-packages.ymlworkflow at the release tag.🤖 Generated with Claude Code