Skip to content

Feature: pass Signed-Releases with GitHub immutable release process #4823

@Kielek

Description

@Kielek

Is your feature request related to a problem? Please describe.
GitHub supports immutable releases. See https://github.blog/changelog/2025-08-26-releases-now-support-immutability-in-public-preview/

Describe the solution you'd like
It will be great to have passing score for Signed-Releases when it is enabled for latest 30 (as for other cases) builds

Describe alternatives you've considered
Implementing SALS for each repository https://github.com/slsa-framework/slsa-github-generator?tab=readme-ov-file#build-your-own-builder seems to be much more expensive.

Additional context
Moving forward with https://scorecard.dev/viewer/?uri=github.com/open-telemetry/opentelemetry-dotnet-contrib

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions