-
-
Notifications
You must be signed in to change notification settings - Fork 860
40 lines (38 loc) · 1.29 KB
/
Copy pathslsa-provenance.yml
File metadata and controls
40 lines (38 loc) · 1.29 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
name: SLSA Provenance
on:
release:
types: [published]
permissions:
contents: read
jobs:
provenance:
runs-on: ubuntu-latest
permissions:
contents: write
id-token: write
attestations: write
steps:
- uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
with:
egress-policy: audit
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
ref: ${{ github.event.release.tag_name }}
persist-credentials: false
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: 22
- run: npm ci --ignore-scripts
- run: npm run build
- id: attest
uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1
with:
subject-path: 'dist/purify.js,dist/purify.min.js,dist/purify.cjs.js,dist/purify.es.mjs'
- name: Upload provenance to release
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
BUNDLE_PATH: ${{ steps.attest.outputs.bundle-path }}
TAG: ${{ github.event.release.tag_name }}
run: |
cp "$BUNDLE_PATH" "${TAG}.intoto.jsonl"
gh release upload "$TAG" "${TAG}.intoto.jsonl" --clobber