Skip to content

v0.1.5 — SLSA build provenance attestation

Choose a tag to compare

@jakethehoffer jakethehoffer released this 18 May 20:45
· 98 commits to master since this release

Patch release. Supply-chain hardening on the published Docker images;
no source-code or operator-visible behavior changes.

Added

  • SLSA build provenance attestations on every GHCR image via
    actions/attest-build-provenance@v2.
    Sigstore signs each image's digest with the workflow's OIDC identity,
    binding the image to the exact commit + workflow run + Dockerfile that
    produced it. Attestations are pushed both to the registry
    (push-to-registry: true) and to the GitHub attestations API, so
    consumers can verify before pulling:

    gh attestation verify oci://ghcr.io/jakethehoffer/ledgerly:v0.1.5 \
      --repo jakethehoffer/ledgerly

    A passing verification confirms the image was built by this repo's
    release workflow on a tagged commit — defense against a registry
    compromise substituting a backdoored image at the same tag. No
    long-lived signing key is involved; the OIDC token Sigstore trusts
    is minted per-workflow-run.

  • README: new "Verifying the image (build provenance)" subsection
    under Docker deployment with the verify command and a one-paragraph
    rationale (what the attestation proves vs what it doesn't).

Notes

The v0.1.4 image was retroactively re-published with an attestation via
workflow_dispatch after the workflow change landed; gh attestation verify against v0.1.4 also passes.