-
Notifications
You must be signed in to change notification settings - Fork 17
Open
Labels
enhancementNew feature or requestNew feature or request
Description
Please could you consider adding SLSA3 provenance to your builds. Github provide multiple tools to help with this, e.g.:
https://github.blog/changelog/2024-06-25-artifact-attestations-is-generally-available/
https://github.blog/enterprise-software/devsecops/enhance-build-security-and-reach-slsa-level-3-with-github-artifact-attestations/
Also some third-party links:
https://github.com/slsa-framework/slsa-github-generator/blob/main/internal/builders/go/README.md
https://goreleaser.com/blog/slsa-generation-for-your-artifacts/
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request