SLSA Verification failed with --source-tag.
https://github.com/google/osv-scanner/releases/tag/v1.4.3
$ slsa-verifier verify-artifact --provenance-path multiple.intoto.jsonl osv-scanner_1.4.3_darwin_arm64 --source-uri=github.com/google/osv-scanner --source-tag v1.4.3
Verified signature against tlog entry index 46958093 at URL: https://rekor.sigstore.dev/api/v1/log/entries/24296fb24b8ad77a578bd1cfcad81368e4524e0ed934b939d91026a9b41ee64e53177ba71dee1b2d
Verifying artifact osv-scanner_1.4.3_darwin_arm64: FAILED: expected tag 'refs/tags/v1.4.3', got '': tag used to generate the binary does not match provenance
FAILED: SLSA verification failed: expected tag 'refs/tags/v1.4.3', got '': tag used to generate the binary does not match provenance
How to reproduce
Download multiple.intoto.jsonl and asset from GitHub Releases.
curl -LqO https://github.com/google/osv-scanner/releases/download/v1.4.3/multiple.intoto.jsonl
curl -LqO https://github.com/google/osv-scanner/releases/download/v1.4.3/osv-scanner_1.4.3_darwin_arm64
Install slsa-verifier.
$ slsa-verifier version
____ _ ____ _ __ __ _____ ____ ___ _____ ___ _____ ____
/ ___| | | / ___| / \ \ \ / / | ____| | _ \ |_ _| | ___| |_ _| | ____| | _ \
\___ \ | | \___ \ / _ \ _____ \ \ / / | _| | |_) | | | | |_ | | | _| | |_) |
___) | | |___ ___) | / ___ \ |_____| \ V / | |___ | _ < | | | _| | | | |___ | _ <
|____/ |_____| |____/ /_/ \_\ \_/ |_____| |_| \_\ |___| |_| |___| |_____| |_| \_\
slsa-verifier: Verify SLSA provenance for Github Actions
GitVersion: 2.0.3
GitCommit: 38829fa7d9491108bc3a86a6160fb2d53ddc3506
GitTreeState: clean
BuildDate: 2023-03-11T03:02:01
GoVersion: go1.18.10
Compiler: gc
Platform: darwin/arm64
Without --source-tag, slsa-verifier succeeded.
$ slsa-verifier verify-artifact --provenance-path multiple.intoto.jsonl osv-scanner_1.4.3_darwin_arm64 --source-uri=github.com/google/osv-scanner
Verified signature against tlog entry index 46958093 at URL: https://rekor.sigstore.dev/api/v1/log/entries/24296fb24b8ad77a578bd1cfcad81368e4524e0ed934b939d91026a9b41ee64e53177ba71dee1b2d
Verified build using builder https://github.com/slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@refs/tags/v1.9.0 at commit 6316373e47d7e3e4b4fd3630c4bbc10987738de6
Verifying artifact osv-scanner_1.4.3_darwin_arm64: PASSED
PASSED: Verified SLSA provenance
However, slsa-verifier failed with --source-tag
$ slsa-verifier verify-artifact --provenance-path multiple.intoto.jsonl osv-scanner_1.4.3_darwin_arm64 --source-uri=github.com/google/osv-scanner --source-tag v1.4.3
Verified signature against tlog entry index 46958093 at URL: https://rekor.sigstore.dev/api/v1/log/entries/24296fb24b8ad77a578bd1cfcad81368e4524e0ed934b939d91026a9b41ee64e53177ba71dee1b2d
Verifying artifact osv-scanner_1.4.3_darwin_arm64: FAILED: expected tag 'refs/tags/v1.4.3', got '': tag used to generate the binary does not match provenance
FAILED: SLSA verification failed: expected tag 'refs/tags/v1.4.3', got '': tag used to generate the binary does not match provenance
Cause
cf948ee
The event of .github/workflows/goreleaser.yml was changed from push event to workflow_dispatch event.
But to verify SLSA Provenance with --source-tag, the workflow must be triggered by push event.
SLSA Verification failed with
--source-tag.https://github.com/google/osv-scanner/releases/tag/v1.4.3
How to reproduce
Download multiple.intoto.jsonl and asset from GitHub Releases.
Install slsa-verifier.
Without
--source-tag, slsa-verifier succeeded.However, slsa-verifier failed with
--source-tagCause
cf948ee
The event of
.github/workflows/goreleaser.ymlwas changed frompushevent toworkflow_dispatchevent.But to verify SLSA Provenance with
--source-tag, the workflow must be triggered bypushevent.