Skip to content

v0.13.0 release failed provenance validation #978

@imjasonh

Description

@imjasonh

The release workflow failed during verification: https://github.com/ko-build/ko/actions/runs/4386793516/jobs/7681560335

Looking at the release artifacts, here: https://github.com/ko-build/ko/releases/tag/v0.13.0

There's a multiple.intoto.jsonl uploaded by the provenance generation workflow, but the verification step seems to be looking for attestation.intoto.jsonl. Please let me know if this is a bug on ko's end, or if this is a misconfiguration, or a bug in the SLSA provenance generation.

cc @laurentsimon @ianlewis

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions