-
-
Notifications
You must be signed in to change notification settings - Fork 8k
Open
Milestone
Description
Please add SLSA provenance to your releases.
It is easy to do on on Github, for example:
https://github.com/slsa-framework/slsa-github-generator/blob/main/internal/builders/generic/README.md#provenance-for-goreleaser
https://goreleaser.com/blog/slsa-generation-for-your-artifacts/#slsa-github-generator
Background info:
https://docs.sigstore.dev/signing/overview/
agriyakhetarpal