Skip to content
slsa-frameworkPublic

About

Stores the GitHub Actions used by the SLSA Source Tool

Resources

Stars

4 stars

Watchers

1 watching

Forks

Latest commit

 

History

89 Commits

Folders and files

Repository files navigation

SLSA actions

GitHub Actions for producing and verifying SLSA attestations.

Action Purpose
attest/actions Watches a GitHub Actions run and attests the artifacts it produced, with slsa-attester. Use it through the attest_actions.yml reusable workflow, which signs with this repository's trusted identity
slsa_with_provenance Generates SLSA source provenance for a push, with the SLSA Source Tool
store_note, get_note Store and read attestations in the commit's git notes
install/verifier Installs slsa-verifier, verified against its own release provenance
verify/build Verifies a SLSA build provenance attestation and the artifacts it is about
verify/source Verifies a SLSA source provenance attestation, from a file or a commit's git note
verify/vsa Verifies a SLSA Verification Summary Attestation and the verifier that issued it

Every action is a composite action: pin it by commit SHA, pass inputs through with:, and see each action's README for its inputs and outputs.

About

Stores the GitHub Actions used by the SLSA Source Tool

Resources

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages