Skip to content

release: prefer actions/attest-build-provenance to cosign#335

Merged
thepwagner merged 2 commits intomainfrom
no-cosign-just-gh
Mar 10, 2025
Merged

release: prefer actions/attest-build-provenance to cosign#335
thepwagner merged 2 commits intomainfrom
no-cosign-just-gh

Conversation

@thepwagner
Copy link
Contributor

Replace custom cosign scripts with GitHub's provenance actions.

This means releases won't attach .sig and .pem files any more, they will be stored as GitHub attestations.

@thepwagner thepwagner requested a review from a team as a code owner March 6, 2025 16:03
@thepwagner thepwagner requested a review from cdenyar March 6, 2025 16:03
@thepwagner thepwagner self-assigned this Mar 6, 2025
cdenyar
cdenyar previously approved these changes Mar 10, 2025
@thepwagner
Copy link
Contributor Author

I've disabled Dismiss stale pull request approvals when new commits are pushed.
I think that was intended to maximize scorecard results 📈 , but it is annoying.

I'm not going to bother a reviewer for that change (this will further impact our scorecard result 📉 ).

@thepwagner thepwagner merged commit c6d29f8 into main Mar 10, 2025
3 checks passed
@thepwagner thepwagner deleted the no-cosign-just-gh branch March 10, 2025 17:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants