Skip to content

ci: add sigstore-sign workflow for tagged releases#5

Merged
alanwiss merged 1 commit into
mainfrom
feat/sigstore-sign
May 1, 2026
Merged

ci: add sigstore-sign workflow for tagged releases#5
alanwiss merged 1 commit into
mainfrom
feat/sigstore-sign

Conversation

@alanwiss
Copy link
Copy Markdown
Contributor

@alanwiss alanwiss commented May 1, 2026

On every v* tag push: bundles a reproducible source tarball, generates SBOM via anchore/sbom-action, signs the tarball with cosign keyless (Rekor-anchored), attaches GitHub-native build/SBOM attestations, and emits a SLSA provenance file via slsa-framework/slsa-github-generator. Mirrors moldchat's release pipeline, scoped to a Go library (source tarball as the artifact, no binary).

Signed-off-by: Alan Wiss <alan@moldchat.com>
@alanwiss alanwiss merged commit 55708a0 into main May 1, 2026
12 checks passed
@alanwiss alanwiss deleted the feat/sigstore-sign branch May 1, 2026 01:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant