Skip to content

Support artifact attestations verification#1606

Merged
taiki-e merged 1 commit intomainfrom
dev/attestation
Mar 20, 2026
Merged

Support artifact attestations verification#1606
taiki-e merged 1 commit intomainfrom
dev/attestation

Conversation

@taiki-e
Copy link
Owner

@taiki-e taiki-e commented Mar 20, 2026

This supports artifact attestations verification for biome, cargo-cyclonedx, cargo-hack, cargo-llvm-cov, cargo-minimal-versions, cargo-no-dev-deps, martin, parse-changelog, parse-dockerfile, prek, uv, wasmtime, zizmor, and zola.

In addition to the above, I have also set up artifact attestations verification for trivy and wash, but since there are no stable releases with artifact attestations for these yet. (There are only two releases with artifact attestations for these: one compromised and then removed release from trivy, and one pre-release from wash. ... As I sometime mentioned before e.g., in #1, this kind of automated signing is unable to prevent attack via account hijacking for accounts that can trigger the automation.)

I commented out the etag-based skip in codegen and verified all releases that have artifact attestations locally.

Related: #237

@taiki-e taiki-e merged commit 8418e9f into main Mar 20, 2026
81 checks passed
@taiki-e taiki-e deleted the dev/attestation branch March 20, 2026 19:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant