Generate SLSA build provenance in GitHub Actions
Attach signed SLSA provenance to GitHub Actions builds so release artifacts ship with verifiable supply-chain metadata.
What it does
Generate SLSA build provenance in GitHub Actions
Attach signed SLSA provenance to GitHub Actions builds so release artifacts ship with verifiable supply-chain metadata.
Prerequisites
GitHub Actions, SLSA GitHub Generator
Installation
Requirements and caveats from upstream:
- [
](https://github.com/aws-powertools/powertools-l...
- | Node.js projects | Node.js Builder | Builds and generates provenance for npm packages | [Beta since v1.6.0](https://github.com/slsa-framework/slsa-github-g...
Basic usage or getting-started notes:
-
SLSA Build level 3 and above. See some
-
popular projects generating provenance using this project.
-
tools for building a SLSA builder on GitHub using the
-
Source: https://github.com/slsa-framework/slsa-github-generator
-
Extracted from upstream docs: https://raw.githubusercontent.com/slsa-framework/slsa-github-generator/HEAD/README.md
Documentation
Source
Capabilities
Install
Quality
deterministic score 0.45 from registry signals: · indexed on github topic:agent-skills · 8 github stars · SKILL.md body (1,568 chars)