ci: attest release artifacts - #3371
Merged
Merged
Conversation
Contributor
|
Thank you for your interest in libavif. https://github.com/actions/attest-build-provenance#usage says:
|
Contributor
Author
|
Updated — switched all three release workflows to pinned |
y-guyon
reviewed
Sep 28, 2026
wantehchang
reviewed
Sep 28, 2026
y-guyon
approved these changes
Oct 2, 2026
Contributor
Author
|
Addressed the review comments in cc042c4 and synced the branch with current main. The new CI runs are currently marked |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add GitHub/SLSA build provenance attestations for the Linux, macOS, and Windows release artifact ZIPs.
Each release workflow already builds a deterministic local ZIP and uploads that exact file to the GitHub release. This change grants the workflows the OIDC/attestation permissions they need and attests each ZIP immediately before upload.
No artifact contents, filenames, build flags, or upload paths change.
Current gap
The current v1.4.2 release publishes:
linux-artifacts.zipmacOS-artifacts.zipwindows-artifacts.zipGitHub records SHA-256 digests for all three, but the release artifacts have no GitHub provenance attestations. For example,
gh attestation verifyfor the current Linux and macOS ZIPs returns 404.Change
Each artifact workflow now:
actions/attest;The attestation action is pinned to the full commit for v4.
Validation
actionlinton all three changed workflows: PASSgit diff --check: PASS