Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add SLSA provenance to your releases #22108

Open
udf2457 opened this issue Apr 24, 2024 · 0 comments
Open

Add SLSA provenance to your releases #22108

udf2457 opened this issue Apr 24, 2024 · 0 comments
Labels
team-OSS Issues for the Bazel OSS team: installation, release processBazel packaging, website type: feature request untriaged

Comments

@udf2457
Copy link

udf2457 commented Apr 24, 2024

Description of the feature request:

Please add SLSA provenance to your releases.

It is easy to do on on Github:

https://github.com/slsa-framework/slsa-github-generator/blob/main/internal/builders/generic/README.md#provenance-for-goreleaser
https://goreleaser.com/blog/slsa-generation-for-your-artifacts/#slsa-github-generator

Background info:
https://docs.sigstore.dev/signing/overview/

Which category does this issue belong to?

No response

What underlying problem are you trying to solve with this feature?

Improve robustness against supply-chain attacks.

Which operating system are you running Bazel on?

No response

What is the output of bazel info release?

No response

If bazel info release returns development version or (@non-git), tell us how you built Bazel.

No response

What's the output of git remote get-url origin; git rev-parse HEAD ?

No response

Have you found anything relevant by searching the web?

No response

Any other information, logs, or outputs that you want to share?

No response

@iancha1992 iancha1992 added the team-OSS Issues for the Bazel OSS team: installation, release processBazel packaging, website label Apr 24, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
team-OSS Issues for the Bazel OSS team: installation, release processBazel packaging, website type: feature request untriaged
Projects
None yet
Development

No branches or pull requests

4 participants