Skip to content

Commit 34a45ca

Browse files
committed
Publish attestation as release artifact
Signed-off-by: Austin Vazquez <macedonv@amazon.com> (cherry picked from commit 3961dc9) Signed-off-by: Austin Vazquez <macedonv@amazon.com>
1 parent b4cab35 commit 34a45ca

File tree

1 file changed

+8
-4
lines changed

1 file changed

+8
-4
lines changed

.github/workflows/release.yml

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -147,6 +147,13 @@ jobs:
147147
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4.1.8
148148
with:
149149
path: builds
150+
- name: Attest Artifacts
151+
id: attest
152+
uses: actions/attest-build-provenance@ef244123eb79f2f7a7e75d99086184180e6d0018 # v1.4.4
153+
with:
154+
subject-path: ./builds/release-tars-**/*.tar.gz
155+
- name: Rename attestation artifact
156+
run: mv ${{ steps.attest.outputs.bundle-path }} containerd-${{ needs.check.outputs.stringver }}-attestation.intoto.jsonl
150157
- name: Create Release
151158
uses: softprops/action-gh-release@e7a8f85e1c67a31e6ed99a94b41bd0b71bbee6b8 # v2.0.9
152159
with:
@@ -158,8 +165,5 @@ jobs:
158165
body_path: ./builds/containerd-release-notes/release-notes.md
159166
files: |
160167
builds/release-tars-**/*
168+
containerd-*-attestation.intoto.jsonl
161169
make_latest: true
162-
- name: Attest Artifacts
163-
uses: actions/attest-build-provenance@1c608d11d69870c2092266b3f9a6f3abbf17002c # v1.4.3
164-
with:
165-
subject-path: ./builds/release-tars-**/*.tar.gz

0 commit comments

Comments
 (0)