Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider to make SLSA releases #307

Open
AtomicFS opened this issue Aug 6, 2024 · 3 comments
Open

Consider to make SLSA releases #307

AtomicFS opened this issue Aug 6, 2024 · 3 comments
Labels
feature New feature or request github_actions Pull requests that update GitHub Actions code

Comments

@AtomicFS
Copy link
Collaborator

AtomicFS commented Aug 6, 2024

Look into slsa-framework/slsa-github-generator

@AtomicFS AtomicFS added feature New feature or request github_actions Pull requests that update GitHub Actions code labels Aug 6, 2024
@MDr164
Copy link
Collaborator

MDr164 commented Aug 22, 2024

I already have a full SLSA based release pipeline I built some time ago if you want to look into this. As far as I know GitHub also plans integrating this more closely into GitHub Releases by default at some point.

@AtomicFS
Copy link
Collaborator Author

Yeah, I would love to take a look.

GitHub plans a lot of things, question is when. I have seen plenty of issues and suggestions talked about for years and never actually getting in.

Great example are issues / pull requests mentioned in #145. They are functional pull requests, everyone agrees they are good and needed features and yet that have not been merged for over a year now. So I do not have high hopes for SLSA to become integrated anytime soon.

@MDr164
Copy link
Collaborator

MDr164 commented Aug 22, 2024

Fair, this is the workflow I have written previously and been using in a few repositories already: https://github.com/MDr164/CI-Testing/blob/master/.github/workflows/release.yml

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature New feature or request github_actions Pull requests that update GitHub Actions code
Projects
None yet
Development

No branches or pull requests

2 participants