From c25d48087a6f1e7bdf5e146a8ef4ebe14993f544 Mon Sep 17 00:00:00 2001 From: askalf <263217947+askalf@users.noreply.github.com> Date: Sat, 26 Sep 2026 09:46:15 -0400 Subject: [PATCH] ci: attach the provenance DSSE envelope to releases as .intoto.jsonl Scorecard Signed-Releases credits provenance only to release assets named *.intoto.jsonl. The release job already uploads the attest-build-provenance Sigstore bundle; it now also extracts the bundle's DSSE envelope with jq and uploads it as .intoto.jsonl beside it. npm and GHCR publishing are unchanged. --- .github/workflows/release.yml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 7281875..43c254c 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -139,4 +139,7 @@ jobs: run: | set -euo pipefail cp "$BUNDLE" "cordon-${TAG}-image.sigstore.json" - gh release upload "$TAG" --clobber "cordon-${TAG}-image.sigstore.json" + # Scorecard credits provenance only to *.intoto.jsonl assets: one + # DSSE envelope per line, taken from the v0.3 Sigstore bundle. + jq -ec '.dsseEnvelope' "$BUNDLE" > "cordon-${TAG}-image.intoto.jsonl" + gh release upload "$TAG" --clobber "cordon-${TAG}-image.sigstore.json" "cordon-${TAG}-image.intoto.jsonl"