Repository navigation
v0.1.5 — SLSA build provenance attestation
Patch release. Supply-chain hardening on the published Docker images;
no source-code or operator-visible behavior changes.
Added
-
SLSA build provenance attestations on every GHCR image via
actions/attest-build-provenance@v2.
Sigstore signs each image's digest with the workflow's OIDC identity,
binding the image to the exact commit + workflow run + Dockerfile that
produced it. Attestations are pushed both to the registry
(push-to-registry: true) and to the GitHub attestations API, so
consumers can verify before pulling:gh attestation verify oci://ghcr.io/jakethehoffer/ledgerly:v0.1.5 \ --repo jakethehoffer/ledgerly
A passing verification confirms the image was built by this repo's
release workflow on a tagged commit — defense against a registry
compromise substituting a backdoored image at the same tag. No
long-lived signing key is involved; the OIDC token Sigstore trusts
is minted per-workflow-run. -
README: new "Verifying the image (build provenance)" subsection
under Docker deployment with the verify command and a one-paragraph
rationale (what the attestation proves vs what it doesn't).
Notes
The v0.1.4 image was retroactively re-published with an attestation via
workflow_dispatch after the workflow change landed; gh attestation verify against v0.1.4 also passes.