Skip to content

[DEFER] Add release signing and provenance attestations #33

@mark-e-deyoung

Description

@mark-e-deyoung

Summary

Add artifact signing and provenance attestations for release outputs.

Scope

  • Sign published GHCR images (keyless/OIDC preferred).
  • Produce verifiable provenance attestations for released images/binaries.
  • Publish verification guidance for downstream consumers.

Acceptance criteria

  • Release artifacts are signed and verifiable.
  • Provenance attestation is generated and published with release outputs.
  • Verification steps are documented in project docs.

Notes

Deferred to keep current release workflow complexity manageable while SBOM rollout stabilizes.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions