lefilou20contact-ai/Attest Build Provenance
Generate provenance attestations for build artifacts
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Stale
- License
- None
Inputs
| name | description | required | default |
|---|---|---|---|
| subject-path | Path to the artifact serving as the subject of the attestation. Must specify exactly one of "subject-path", "subject-digest", or "subject-checksums". May contain a glob pattern or list of paths (total subject count cannot exceed 1024). | no | — |
| subject-digest | Digest of the subject for which provenance will be generated. Must be in the form "algorithm:hex_digest" (e.g. "sha256:abc123..."). Must specify exactly one of "subject-path", "subject-digest", or "subject-checksums". | no | — |
| subject-name | Subject name as it should appear in the attestation. Required when identifying the subject with the "subject-digest" input. | — | — |
| subject-checksums | Path to checksums file containing digest and name of subjects for attestation. Must specify exactly one of "subject-path", "subject-digest", or "subject-checksums". | no | — |
| predicate-type | URI identifying the type of the predicate. Required when using "predicate" or "predicate-path" for custom attestations. | no | — |
| predicate | String containing the value for the attestation predicate. String length cannot exceed 16MB. Must supply exactly one of "predicate-path" or "predicate" when creating custom attestations. | no | — |
| predicate-path | Path to the file which contains the content for the attestation predicate. File size cannot exceed 16MB. Must supply exactly one of "predicate-path" or "predicate" when creating custom attestations. | no | — |
| push-to-registry | Whether to push the provenance statement to the image registry. Requires that the "subject-name" parameter specify the fully-qualified image name and that the "subject-digest" parameter be specified. Defaults to false. | no | false |
| create-storage-record | Whether to create a storage record for the artifact. Requires that push-to-registry is set to true. Defaults to true. | no | true |
| show-summary | Whether to attach a list of generated attestations to the workflow run summary page. Defaults to true. | no | true |
| github-token | The GitHub token used to make authenticated API requests. | no | ${{ github.token }} |
Outputs
| name | description |
|---|---|
| bundle-path | The path to the file containing the attestation bundle. |
| attestation-id | The ID of the attestation. |
| attestation-url | The URL for the attestation summary. |
| storage-record-ids | GitHub IDs for the storage records |