Skip to content

docs: update required workflow permissions in attestations.md #5900

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Jul 12, 2025

Conversation

mroth
Copy link
Contributor

@mroth mroth commented Jul 11, 2025

This updates the documentation regarding attestations to address two issues I hit when following the docs.

  1. Adds id-token: write permissions to the Github Actions workflow. Without this, the signature will fail. See https://github.com/actions/attest-build-provenance?tab=readme-ov-file#usage for reference.
  2. Show the goreleaser configuration file checksum filename modified to match the predictable filename in the actions workflow.

@pull-request-size pull-request-size bot added the size/S Denotes a PR that changes 10-29 lines, ignoring generated files. label Jul 11, 2025
@caarlos0 caarlos0 merged commit 4901e72 into goreleaser:main Jul 12, 2025
1 check passed
@caarlos0
Copy link
Member

good catch! thanks!🙏

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
size/S Denotes a PR that changes 10-29 lines, ignoring generated files.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants