Skip to content

CICD: Add SLSA build attestation to release workflow #3563

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
wants to merge 1 commit into from

Conversation

eliheady
Copy link
Contributor

@eliheady eliheady commented May 4, 2025

This adds a new workflow job to the release drafter workflow that calls the generic SLSA builder in the SLSA Framework project.

The draft_release job is modified to include a new step to generate sha256 digests according to the expected input of the SLSA builder.

The release assets will include a new file called multiple.intoto.jsonl that can be used to verify the build artifacts against the recorded digests. This is what it will look like on the releases page:

Screenshot 2025-05-04 at 7 36 30 AM

This was tested in a private fork because I didn't want to introduce any confusion around DNSControl releases in the public Rekor logs. I will give read access to interested reviewers.

Example artifacts are attached. Manual verification steps:

checksums.txt
multiple.intoto.jsonl.txt

Note the attestation document has been renamed just for attaching to this issue, GitHub blocks jsonl (?)

slsa-verifier verify-artifact \
  --provenance-path multiple.intoto.jsonl.txt \
  --source-uri github.com/eliheady/nodnsctrlo \
  --source-tag v4.19.0-slsa checksums.txt
Verified build using builder "https://github.com/slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@refs/tags/v2.1.0" at commit 12d7c7f89c902899a290dd9c6bbe3d37cb78ba97
Verifying artifact checksums.txt: PASSED

PASSED: SLSA verification passed

Release changelog section

  • CICD: Add SLSA build attestation to release workflow

@eliheady eliheady marked this pull request as ready for review May 4, 2025 15:04
@eliheady
Copy link
Contributor Author

eliheady commented May 4, 2025

This resolves #3468

@tlimoncelli
Copy link
Contributor

I don't know much about SLSA but know that this kind of thing is important. Thanks for the PR!

I'd like advice on how to bring this into production.

@eliheady
Copy link
Contributor Author

eliheady commented May 5, 2025

Full transparency, I'm not a GHA or SLSA expert. But there wasn't much to it. I merged something (nearly the same as) this PR into main to make the workflow changes take effect, then pushed a new tag which triggers the normal release flow. The attestation step runs after the build is finished and sha256 digests produced at the end of the draft_release job.

I don't think it is necessary to follow the way I did it -- it could be tested before including it in a real release. Since this is not a new workflow, I believe as long as the workflow changes are included in the tag that the release is built from you could experiment without an official release. For instance, I guess you could create a v0.0.0-test-slsa tag from this commit, which should trigger the release workflow because its tag pattern would match. The draft release that gets created should have the multiple.intoto.jsonl document attached once the slsa job runs.

I'll try out that test procedure to make sure I am not wasting your time :)

@eliheady eliheady force-pushed the elih-slsa-provenance branch from da12da1 to 06ecb5c Compare May 5, 2025 15:55
* add SLSA generator call after release step

* add SLSA info and verification doc

* add SLSA badge to Readme

* Fix attestation doc filename, limit digest generation to files below dist/
@eliheady eliheady force-pushed the elih-slsa-provenance branch from 06ecb5c to 643b8be Compare May 5, 2025 17:20
@eliheady
Copy link
Contributor Author

eliheady commented May 5, 2025

I confirmed the test plan I loosely outlined does work to initiate the modified workflow. This could be used if you want to test the revised release steps and confirm the attestation document is produced as expected.

git tag v0.0.0-test-slsa 643b8be7dfa85ec984a521cc17f25da6c1dc0f13
git push --tags

643b8be is the rebased squashed commit I just pushed to this PR branch.

Then review GH Actions for new workflow stages:
Screenshot 2025-05-05 at 1 25 22 PM

Then you could cancel or let it finish and review the attestation document as desired. If you let it run, the SLSA builder in the called workflow will submit the attestation to the public Rekor log, so there will be a history and signed digests associated with the unpublished release. I don't think that should matter, I just wanted to point it out.

@eliheady
Copy link
Contributor Author

eliheady commented May 5, 2025

well, I apologize for the noise here. That test run in the private fork failed during the called SLSA workflow. I am investigating. I probably missed something when I was rebasing on the upstream main.

@eliheady
Copy link
Contributor Author

eliheady commented May 5, 2025

https://github.com/eliheady/nodnsctrlo/actions/runs/14842598300 is a successful test release of this PR (plus the required one-line change for running against a private repo). I am leaving that test fork private because I'm not comfortable producing builds and a public release alongside the official releases of the project.

As mentioned in 3468, this change doesn't produce SLSA attestation for the container images. I intend to make further changes to include that (if possible) in the same release workflow. If you'd prefer to wait to merge this until the docker images are also covered, it's fine with me to move this to draft status or sit on it. Also ok by me to have this merged when you are inclined to do so, with or without the container portion. I will work on it sometime this week either way.

I appreciate you taking the time to consider this Tom!

@tlimoncelli
Copy link
Contributor

I ran it as v0.0.0... and it created a separate release. Is that intended? I'd rather have it as part of the main release.

screencapture_2025-05-05_15 49 07

The json is:

{
  "mediaType": "application/vnd.dev.sigstore.bundle.v0.3+json",
  "verificationMaterial": {
    "certificate": {
      "rawBytes": "MIIHSzCCBtKgAwIBAgIUbzsIoXqjU1dNbF4wodHOAL0qUuYwCgYIKoZIzj0EAwMwNzEVMBMGA1UEChMMc2lnc3RvcmUuZGV2MR4wHAYDVQQDExVzaWdzdG9yZS1pbnRlcm1lZGlhdGUwHhcNMjUwNTA1MTkyNzE1WhcNMjUwNTA1MTkzNzE1WjAAMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEc69rNe/nQVpSn++6QumSKn/D7zB+d0Ghl5tSPqypRWas9MRhZHyd2eCDNBKSxt8q+PWvBNf2Q99OB1iSz6oMwKOCBfEwggXtMA4GA1UdDwEB/wQEAwIHgDATBgNVHSUEDDAKBggrBgEFBQcDAzAdBgNVHQ4EFgQUJAehuvDJY9cwo383KYV+sxvc/nowHwYDVR0jBBgwFoAU39Ppz1YkEZb5qNjpKFWixi4YZD8wgYQGA1UdEQEB/wR6MHiGdmh0dHBzOi8vZ2l0aHViLmNvbS9zbHNhLWZyYW1ld29yay9zbHNhLWdpdGh1Yi1nZW5lcmF0b3IvLmdpdGh1Yi93b3JrZmxvd3MvZ2VuZXJhdG9yX2dlbmVyaWNfc2xzYTMueW1sQHJlZnMvdGFncy92Mi4xLjAwOQYKKwYBBAGDvzABAQQraHR0cHM6Ly90b2tlbi5hY3Rpb25zLmdpdGh1YnVzZXJjb250ZW50LmNvbTASBgorBgEEAYO/MAECBARwdXNoMDYGCisGAQQBg78wAQMEKDY0M2I4YmU3ZGZhODVlYzk4NGE1MjFjYzE3ZjI1ZGE2YzFkYzBmMTMwLQYKKwYBBAGDvzABBAQfUkVMRUFTRTogTWFrZSByZWxlYXNlIGNhbmRpZGF0ZTAmBgorBgEEAYO/MAEFBBhTdGFja0V4Y2hhbmdlL2Ruc2NvbnRyb2wwKAYKKwYBBAGDvzABBgQacmVmcy90YWdzL3YwLjAuMC10ZXN0LXNsc2EwOwYKKwYBBAGDvzABCAQtDCtodHRwczovL3Rva2VuLmFjdGlvbnMuZ2l0aHVidXNlcmNvbnRlbnQuY29tMIGGBgorBgEEAYO/MAEJBHgMdmh0dHBzOi8vZ2l0aHViLmNvbS9zbHNhLWZyYW1ld29yay9zbHNhLWdpdGh1Yi1nZW5lcmF0b3IvLmdpdGh1Yi93b3JrZmxvd3MvZ2VuZXJhdG9yX2dlbmVyaWNfc2xzYTMueW1sQHJlZnMvdGFncy92Mi4xLjAwOAYKKwYBBAGDvzABCgQqDChmN2RkOGM1NGMyMDY3YmFmYzEyY2E3YTU1NTk1ZDVlZTliNzUyMDRhMB0GCisGAQQBg78wAQsEDwwNZ2l0aHViLWhvc3RlZDA7BgorBgEEAYO/MAEMBC0MK2h0dHBzOi8vZ2l0aHViLmNvbS9TdGFja0V4Y2hhbmdlL2Ruc2NvbnRyb2wwOAYKKwYBBAGDvzABDQQqDCg2NDNiOGJlN2RmYTg1ZWM5ODRhNTIxY2MxN2YyNWRhNmMxZGMwZjEzMCoGCisGAQQBg78wAQ4EHAwacmVmcy90YWdzL3YwLjAuMC10ZXN0LXNsc2EwGAYKKwYBBAGDvzABDwQKDAg2Njk2MzcxNjAwBgorBgEEAYO/MAEQBCIMIGh0dHBzOi8vZ2l0aHViLmNvbS9TdGFja0V4Y2hhbmdlMBcGCisGAQQBg78wAREECQwHMTM5MzE3MTB6BgorBgEEAYO/MAESBGwMamh0dHBzOi8vZ2l0aHViLmNvbS9TdGFja0V4Y2hhbmdlL2Ruc2NvbnRyb2wvLmdpdGh1Yi93b3JrZmxvd3MvcmVsZWFzZV9kcmFmdC55bWxAcmVmcy90YWdzL3YwLjAuMC10ZXN0LXNsc2EwOAYKKwYBBAGDvzABEwQqDCg2NDNiOGJlN2RmYTg1ZWM5ODRhNTIxY2MxN2YyNWRhNmMxZGMwZjEzMBQGCisGAQQBg78wARQEBgwEcHVzaDBfBgorBgEEAYO/MAEVBFEMT2h0dHBzOi8vZ2l0aHViLmNvbS9TdGFja0V4Y2hhbmdlL2Ruc2NvbnRyb2wvYWN0aW9ucy9ydW5zLzE0ODQ0MzUxMzgxL2F0dGVtcHRzLzEwFgYKKwYBBAGDvzABFgQIDAZwdWJsaWMwgYoGCisGAQQB1nkCBAIEfAR6AHgAdgDdPTBqxscRMmMZHhyZZzcCokpeuN48rf+HinKALynujgAAAZah6rRWAAAEAwBHMEUCIQCsMW3Nhjihc954uxQ9rCzx+zV4b5vtEJBfonKwDVqh+wIgPT6/lmpTJYU6kj3clfwuiUDVQl7KvYRETkxC97ePclowCgYIKoZIzj0EAwMDZwAwZAIwCqYerCfR8QMwPpNoPKs2y3Iya9FWb8toiE3duO0GsBVBS9kc1/eVjtC2ie+Oa+FmAjAce8OoKd+t3ABiwNzM/dP2kyM07m4yiG6VX6rlfzLRG9TnknFVpfEmVIUWKwsjrYA="
    },
    "tlogEntries": [
      {
        "logIndex": "207027270",
        "logId": {
          "keyId": "wNI9atQGlz+VWfO6LRygH4QUfY/8W4RFwiT5i5WRgB0="
        },
        "kindVersion": {
          "kind": "dsse",
          "version": "0.0.1"
        },
        "integratedTime": "1746473235",
        "inclusionPromise": {
          "signedEntryTimestamp": "MEYCIQDIe++MahjKO5aZTvx3wtg7LdMxzac1Bwgml8PWHZvyzQIhAN1z57FBJfDaifWz5iXJE/n1i/GjaEW4LrC8wN53LZBl"
        },
        "inclusionProof": {
          "logIndex": "85123008",
          "rootHash": "yJ2yjwJzo2aDerhBkeLmT5oeooBnpVMw5HL6wz8FgeE=",
          "treeSize": "85123009",
          "hashes": [
            "Fe2f15hQTgm0oPP9VzuHPXUTXPOrQTnEldP9G+eRArQ=",
            "w+qAx2hgmVb+aS/X9uiw/ByYJKT2Pxw8RwSmbnYCgek=",
            "Pb/Z333s+bObMbyjoTXfyhD6YGMCC5ePtf4nI1qdC5Y=",
            "sveCbECGAMq/SuZET1Q7/ghrZZAPygh0HKn7wXcDnnw=",
            "vpGBUZyf35w04rMXD4KOPch1szLCF3hQ1ZjRHhML5qs=",
            "BBKiC8nvnANu3P/QSPB2vaa0EaPt5hbX1fqxYJs0fIw=",
            "STRiT5znScYqqjbHUoeSCDancp9yMA1GQyruLcyC0WU=",
            "F2Bk+eQOO/Lqk4MbWWqMLxaniv0cn5DVaH8uShdTvwU=",
            "TEPT8U+UTUa2fotX22CflObssrAOIfxDI3yfjgJhOxU=",
            "0nA3rRXKCPnwIXraGuhSLUXUoR3Z/pZWazoHDwFyFpQ=",
            "wPskhmu15ftxHjrzbc1mbR7g3XCKtM52kdXHazaWvH4=",
            "++1LMuz3tIdW1/pfEfhPfXC4ot1AwDAXDcPyfibzGyc=",
            "7v8qPHNDLerpduaMx06eb/MwgoQwczTn/cYGKX/9wZ4="
          ],
          "checkpoint": {
            "envelope": "rekor.sigstore.dev - 1193050959916656506\n85123009\nyJ2yjwJzo2aDerhBkeLmT5oeooBnpVMw5HL6wz8FgeE=\n\n— rekor.sigstore.dev wNI9ajBFAiBV3DRyH5wBEWCGIvGmB3BrOdEsqEc+iUM2GVVaetCvvwIhAOhHdOcEd2XNwE6xlcOU5X50xXlzfwsmCmhalHipr8qc\n"
          }
        },
        "canonicalizedBody": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiZHNzZSIsInNwZWMiOnsiZW52ZWxvcGVIYXNoIjp7ImFsZ29yaXRobSI6InNoYTI1NiIsInZhbHVlIjoiMWYxYzBiZTkzMDk1MDI0NzRmMmMzYTEwMGQzNDJmZjc2YTQ0YjU1MDM4NzQ0NWQxOTJmYzE0NDY4MmRhZTY4OCJ9LCJwYXlsb2FkSGFzaCI6eyJhbGdvcml0aG0iOiJzaGEyNTYiLCJ2YWx1ZSI6IjBlMjMzNjIzZDFmNTcyZTU0YTc0NmQwNWYwNjNjZDJmODU2MmI4NmI2ZGM2MTQwMjkxZTA4YjUwM2I5ODliZDMifSwic2lnbmF0dXJlcyI6W3sic2lnbmF0dXJlIjoiTUVVQ0lRRFBJNHUvNFphWDFRckUwWFpJSEg1V0RrU1F2c3IxVlpPSGYxUUN6MjN2QlFJZ1M5elc1Tk1rY3RZNW16TW44UTQvUW02S3R4Y3NLMU5LR3FuZzBCMEhKNGc9IiwidmVyaWZpZXIiOiJMUzB0TFMxQ1JVZEpUaUJEUlZKVVNVWkpRMEZVUlMwdExTMHRDazFKU1VoVGVrTkRRblJMWjBGM1NVSkJaMGxWWW5welNXOVljV3BWTVdST1lrWTBkMjlrU0U5QlREQnhWWFZaZDBObldVbExiMXBKZW1vd1JVRjNUWGNLVG5wRlZrMUNUVWRCTVZWRlEyaE5UV015Ykc1ak0xSjJZMjFWZFZwSFZqSk5ValIzU0VGWlJGWlJVVVJGZUZaNllWZGtlbVJIT1hsYVV6RndZbTVTYkFwamJURnNXa2RzYUdSSFZYZElhR05PVFdwVmQwNVVRVEZOVkd0NVRucEZNVmRvWTA1TmFsVjNUbFJCTVUxVWEzcE9la1V4VjJwQlFVMUdhM2RGZDFsSUNrdHZXa2w2YWpCRFFWRlpTVXR2V2tsNmFqQkVRVkZqUkZGblFVVmpOamx5VG1VdmJsRldjRk51S3lzMlVYVnRVMHR1TDBRM2VrSXJaREJIYUd3MWRGTUtVSEY1Y0ZKWFlYTTVUVkpvV2toNVpESmxRMFJPUWt0VGVIUTRjU3RRVjNaQ1RtWXlVVGs1VDBJeGFWTjZObTlOZDB0UFEwSm1SWGRuWjFoMFRVRTBSd3BCTVZWa1JIZEZRaTkzVVVWQmQwbElaMFJCVkVKblRsWklVMVZGUkVSQlMwSm5aM0pDWjBWR1FsRmpSRUY2UVdSQ1owNVdTRkUwUlVablVWVktRV1ZvQ25WMlJFcFpPV04zYnpNNE0wdFpWaXR6ZUhaakwyNXZkMGgzV1VSV1VqQnFRa0puZDBadlFWVXpPVkJ3ZWpGWmEwVmFZalZ4VG1wd1MwWlhhWGhwTkZrS1drUTRkMmRaVVVkQk1WVmtSVkZGUWk5M1VqWk5TR2xIWkcxb01HUklRbnBQYVRoMldqSnNNR0ZJVm1sTWJVNTJZbE01ZW1KSVRtaE1WMXA1V1ZjeGJBcGtNamw1WVhrNWVtSklUbWhNVjJSd1pFZG9NVmxwTVc1YVZ6VnNZMjFHTUdJelNYWk1iV1J3WkVkb01WbHBPVE5pTTBweVdtMTRkbVF6VFhaYU1sWjFDbHBZU21oa1J6bDVXREprYkdKdFZubGhWMDVtWXpKNGVsbFVUWFZsVnpGelVVaEtiRnB1VFhaa1IwWnVZM2s1TWsxcE5IaE1ha0YzVDFGWlMwdDNXVUlLUWtGSFJIWjZRVUpCVVZGeVlVaFNNR05JVFRaTWVUa3dZakowYkdKcE5XaFpNMUp3WWpJMWVreHRaSEJrUjJneFdXNVdlbHBZU21waU1qVXdXbGMxTUFwTWJVNTJZbFJCVTBKbmIzSkNaMFZGUVZsUEwwMUJSVU5DUVZKM1pGaE9iMDFFV1VkRGFYTkhRVkZSUW1jM09IZEJVVTFGUzBSWk1FMHlTVFJaYlZVekNscEhXbWhQUkZac1dYcHJORTVIUlRGTmFrWnFXWHBGTTFwcVNURmFSMFV5V1hwR2ExbDZRbTFOVkUxM1RGRlpTMHQzV1VKQ1FVZEVkbnBCUWtKQlVXWUtWV3RXVFZKVlJsUlNWRzluVkZkR2NscFRRbmxhVjNoc1dWaE9iRWxIVG1oaWJWSndXa2RHTUZwVVFXMUNaMjl5UW1kRlJVRlpUeTlOUVVWR1FrSm9WQXBrUjBacVlUQldORmt5YUdoaWJXUnNUREpTZFdNeVRuWmlibEo1WWpKM2QwdEJXVXRMZDFsQ1FrRkhSSFo2UVVKQ1oxRmhZMjFXYldONU9UQlpWMlI2Q2t3eldYZE1ha0YxVFVNeE1GcFlUakJNV0U1ell6SkZkMDkzV1V0TGQxbENRa0ZIUkhaNlFVSkRRVkYwUkVOMGIyUklVbmRqZW05MlRETlNkbUV5Vm5VS1RHMUdhbVJIYkhaaWJrMTFXakpzTUdGSVZtbGtXRTVzWTIxT2RtSnVVbXhpYmxGMVdUSTVkRTFKUjBkQ1oyOXlRbWRGUlVGWlR5OU5RVVZLUWtoblRRcGtiV2d3WkVoQ2VrOXBPSFphTW13d1lVaFdhVXh0VG5aaVV6bDZZa2hPYUV4WFdubFpWekZzWkRJNWVXRjVPWHBpU0U1b1RGZGtjR1JIYURGWmFURnVDbHBYTld4amJVWXdZak5KZGt4dFpIQmtSMmd4V1drNU0ySXpTbkphYlhoMlpETk5kbG95Vm5WYVdFcG9aRWM1ZVZneVpHeGliVlo1WVZkT1ptTXllSG9LV1ZSTmRXVlhNWE5SU0Vwc1dtNU5kbVJIUm01amVUa3lUV2swZUV4cVFYZFBRVmxMUzNkWlFrSkJSMFIyZWtGQ1EyZFJjVVJEYUcxT01sSnJUMGROTVFwT1IwMTVUVVJaTTFsdFJtMVpla1Y1V1RKRk0xbFVWVEZPVkdzeFdrUldiRnBVYkdsT2VsVjVUVVJTYUUxQ01FZERhWE5IUVZGUlFtYzNPSGRCVVhORkNrUjNkMDVhTW13d1lVaFdhVXhYYUhaak0xSnNXa1JCTjBKbmIzSkNaMFZGUVZsUEwwMUJSVTFDUXpCTlN6Sm9NR1JJUW5wUGFUaDJXakpzTUdGSVZta0tURzFPZG1KVE9WUmtSMFpxWVRCV05Ga3lhR2hpYldSc1RESlNkV015VG5aaWJsSjVZakozZDA5QldVdExkMWxDUWtGSFJIWjZRVUpFVVZGeFJFTm5NZ3BPUkU1cFQwZEtiRTR5VW0xWlZHY3hXbGROTlU5RVVtaE9WRWw0V1RKTmVFNHlXWGxPVjFKb1RtMU5lRnBIVFhkYWFrVjZUVU52UjBOcGMwZEJVVkZDQ21jM09IZEJVVFJGU0VGM1lXTnRWbTFqZVRrd1dWZGtla3d6V1hkTWFrRjFUVU14TUZwWVRqQk1XRTV6WXpKRmQwZEJXVXRMZDFsQ1FrRkhSSFo2UVVJS1JIZFJTMFJCWnpKT2Ftc3lUWHBqZUU1cVFYZENaMjl5UW1kRlJVRlpUeTlOUVVWUlFrTkpUVWxIYURCa1NFSjZUMms0ZGxveWJEQmhTRlpwVEcxT2RncGlVemxVWkVkR2FtRXdWalJaTW1ob1ltMWtiRTFDWTBkRGFYTkhRVkZSUW1jM09IZEJVa1ZGUTFGM1NFMVVUVFZOZWtVelRWUkNOa0puYjNKQ1owVkZDa0ZaVHk5TlFVVlRRa2QzVFdGdGFEQmtTRUo2VDJrNGRsb3liREJoU0ZacFRHMU9kbUpUT1ZSa1IwWnFZVEJXTkZreWFHaGliV1JzVERKU2RXTXlUbllLWW01U2VXSXlkM1pNYldSd1pFZG9NVmxwT1ROaU0wcHlXbTE0ZG1RelRYWmpiVlp6V2xkR2VscFdPV3RqYlVadFpFTTFOV0pYZUVGamJWWnRZM2s1TUFwWlYyUjZURE5aZDB4cVFYVk5RekV3V2xoT01FeFlUbk5qTWtWM1QwRlpTMHQzV1VKQ1FVZEVkbnBCUWtWM1VYRkVRMmN5VGtST2FVOUhTbXhPTWxKdENsbFVaekZhVjAwMVQwUlNhRTVVU1hoWk1rMTRUakpaZVU1WFVtaE9iVTE0V2tkTmQxcHFSWHBOUWxGSFEybHpSMEZSVVVKbk56aDNRVkpSUlVKbmQwVUtZMGhXZW1GRVFtWkNaMjl5UW1kRlJVRlpUeTlOUVVWV1FrWkZUVlF5YURCa1NFSjZUMms0ZGxveWJEQmhTRlpwVEcxT2RtSlRPVlJrUjBacVlUQldOQXBaTW1ob1ltMWtiRXd5VW5Wak1rNTJZbTVTZVdJeWQzWlpWMDR3WVZjNWRXTjVPWGxrVnpWNlRIcEZNRTlFVVRCTmVsVjRUWHBuZUV3eVJqQmtSMVowQ21OSVVucE1la1YzUm1kWlMwdDNXVUpDUVVkRWRucEJRa1puVVVsRVFWcDNaRmRLYzJGWFRYZG5XVzlIUTJselIwRlJVVUl4Ym10RFFrRkpSV1pCVWpZS1FVaG5RV1JuUkdSUVZFSnhlSE5qVWsxdFRWcElhSGxhV25walEyOXJjR1YxVGpRNGNtWXJTR2x1UzBGTWVXNTFhbWRCUVVGYVlXZzJjbEpYUVVGQlJRcEJkMEpJVFVWVlEwbFJRM05OVnpOT2FHcHBhR001TlRSMWVGRTVja042ZUN0NlZqUmlOWFowUlVwQ1ptOXVTM2RFVm5Gb0szZEpaMUJVTmk5c2JYQlVDa3BaVlRacmFqTmpiR1ozZFdsVlJGWlJiRGRMZGxsU1JWUnJlRU01TjJWUVkyeHZkME5uV1VsTGIxcEplbW93UlVGM1RVUmFkMEYzV2tGSmQwTnhXV1VLY2tObVVqaFJUWGRRY0U1dlVFdHpNbmt6U1hsaE9VWlhZamgwYjJsRk0yUjFUekJIYzBKV1FsTTVhMk14TDJWV2FuUkRNbWxsSzA5aEswWnRRV3BCWXdwbE9FOXZTMlFyZEROQlFtbDNUbnBOTDJSUU1tdDVUVEEzYlRSNWFVYzJWbGcyY214bWVreFNSemxVYm10dVJsWndaa1Z0VmtsVlYwdDNjMnB5V1VFOUNpMHRMUzB0UlU1RUlFTkZVbFJKUmtsRFFWUkZMUzB0TFMwSyJ9XX19"
      }
    ]
  },
  "dsseEnvelope": {
    "payload": "",
    "payloadType": "application/vnd.in-toto+json",
    "signatures": [
      {
        "sig": "MEUCIQDPI4u/4ZaX1QrE0XZIHH5WDkSQvsr1VZOHf1QCz23vBQIgS9zW5NMkctY5mzMn8Q4/Qm6KtxcsK1NKGqng0B0HJ4g="
      }
    ]
  }
}

@eliheady
Copy link
Contributor Author

eliheady commented May 5, 2025

Hm. A separate release is not the intention. I have reproduced it though, and I'm afraid I just missed that it does this: in my testing I was not consistently deleting the draft releases and it seems the called workflow can reuse a release under some circumstances (that I can't characterize further at the moment). This is obviously not ready for inclusion in the project. I will do some research on this problem.

@eliheady eliheady marked this pull request as draft May 5, 2025 20:31
@tlimoncelli
Copy link
Contributor

Sounds good!

@eliheady
Copy link
Contributor Author

minor update ... I have been working on a different approach using the GitHub attest-build-provenance action, which is also SLSA level 3 compliant if implemented with a reusable workflow.

I think the SLSA builder approach in this current PR is going to be more challenging to implement correctly and has more potential to break. Both goreleaser and the SLSA framework project generator-generic-slsa3.yml create releases, making the duplicate release issue more likely.

The GitHub provenance generator might be a better long-term solution anyway because it is integrated with the GitHub platform. There is not much different for consumers of the attestations (use gh instead of slsa-verifier for local verification).

@eliheady
Copy link
Contributor Author

eliheady commented Jun 5, 2025

I'll be unable to work on DNSControl until sometime later this Summer, so I am going to close this. I don't want to discourage anyone else that wants to take it up in the meantime.

@eliheady eliheady closed this Jun 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants