-
Notifications
You must be signed in to change notification settings - Fork 25
Open
Labels
documentationImprovements or additions to documentationImprovements or additions to documentationsecurityRelated to repo or code securityRelated to repo or code security
Description
A new section of the README should be added to document provenance status. It should include links to the source commit, build workflow and sigstore log entry. Doing so will improve security posture against supply chain attacks and align ourselves with modern security best practices.
Ideally, we create an automation that runs after a successful release to update these values automatically
Example:
Provenance (SLSA)
Built and published from GitHub Actions with npm provenance.
- Source commit: link to commit
- Build workflow: link to workflow run
- Sigstore Transparency Log: link to log entry
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
documentationImprovements or additions to documentationImprovements or additions to documentationsecurityRelated to repo or code securityRelated to repo or code security
Type
Projects
Status
Backlog