Skip to content

Conversation

@applejag
Copy link
Contributor

Adds build attestation on your release artifacts, which helps with supply-chain security (doesn't fully solve the problem, but it helps). Adds it for both the binary and the tarball/zipfile.

Attestation can be used to confirm that a binary comes from your GitHub Action build workflow, and has not snuck in some other way. Tools like https://mise.jdx.dev/ has built-in support for attensation verification.

@orsinium orsinium merged commit 317057b into firefly-zero:main Jan 20, 2026
@applejag applejag deleted the feature/attestation branch January 20, 2026 08:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants