Skip to content

Add SLSA Source Provenance workflow#706

Open
ppkarwasz wants to merge 2 commits into
masterfrom
feat/slsa-source
Open

Add SLSA Source Provenance workflow#706
ppkarwasz wants to merge 2 commits into
masterfrom
feat/slsa-source

Conversation

@ppkarwasz
Copy link
Copy Markdown
Member

Add a reusable workflow that generates a SLSA Source Provenance attestation for the triggering commit, and a caller that wires it up for this repository:

  • slsa-provenance-reusable.yml: signs a SLSA Provenance attestation for the commit via Sigstore (OIDC) and stores the attestation in Git Notes using slsa-framework/source-actions. Merge commits are supported.
  • slsa-provenance.yml: runs the reusable workflow on every push to a protected named reference (master, release, rel/*).

Combined with the branch and tag protection rules introduced in #705, this contributes to SLSA Source L3 compliance. The reusable workflow is also documented in .github/workflows/README.md.

Note

This PR should be evaluated once the protection rules introduced in #705 are enabled.

ppkarwasz added 2 commits May 13, 2026 00:20
Add a reusable workflow that generates a [SLSA Source Provenance](https://slsa.dev/spec/v1.2/source-requirements) attestation for the triggering commit, and a caller that wires it up for this repository:

- `slsa-provenance-reusable.yml`: signs a SLSA Provenance attestation for the commit via Sigstore (OIDC) and stores the attestation in Git Notes using [`slsa-framework/source-actions`](https://github.com/slsa-framework/source-actions). Merge commits are supported.
- `slsa-provenance.yml`: runs the reusable workflow on every push to a protected named reference (`master`, `release`, `rel/*`).

Combined with the branch and tag protection rules introduced in #705, this contributes to [SLSA Source L3](https://slsa.dev/spec/v1.2/source-requirements#source-l3) compliance. The reusable workflow is also documented in `.github/workflows/README.md`.

> [!NOTE]
> This PR should be evaluated once the protection rules introduced in #705 are enabled.
@garydgregory
Copy link
Copy Markdown
Member

Hi @ppkarwasz

Is this a replacement for the Commons Release Plugin recent proposal for SLSA?

@ppkarwasz
Copy link
Copy Markdown
Member Author

It's more of a complement:

  • Add build-attestation target commons-release-plugin#422 allows us to create Build Provenance attestations,
  • this PR allows use to create Source Provenance attestations, which give informations such as:
    • who made the commit,
    • what protections were in place,
    • possibly who reviewed the commit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants