Skip to content

SLSA Verification failed with --source-tag at v1.4.3 #632

Description

@suzuki-shunsuke

SLSA Verification failed with --source-tag.

https://github.com/google/osv-scanner/releases/tag/v1.4.3

$ slsa-verifier verify-artifact --provenance-path multiple.intoto.jsonl osv-scanner_1.4.3_darwin_arm64 --source-uri=github.com/google/osv-scanner --source-tag v1.4.3
Verified signature against tlog entry index 46958093 at URL: https://rekor.sigstore.dev/api/v1/log/entries/24296fb24b8ad77a578bd1cfcad81368e4524e0ed934b939d91026a9b41ee64e53177ba71dee1b2d
Verifying artifact osv-scanner_1.4.3_darwin_arm64: FAILED: expected tag 'refs/tags/v1.4.3', got '': tag used to generate the binary does not match provenance

FAILED: SLSA verification failed: expected tag 'refs/tags/v1.4.3', got '': tag used to generate the binary does not match provenance

How to reproduce

Download multiple.intoto.jsonl and asset from GitHub Releases.

curl -LqO https://github.com/google/osv-scanner/releases/download/v1.4.3/multiple.intoto.jsonl
curl -LqO https://github.com/google/osv-scanner/releases/download/v1.4.3/osv-scanner_1.4.3_darwin_arm64

Install slsa-verifier.

$ slsa-verifier version
  ____    _       ____       _             __     __  _____   ____    ___   _____   ___   _____   ____
 / ___|  | |     / ___|     / \            \ \   / / | ____| |  _ \  |_ _| |  ___| |_ _| | ____| |  _ \
 \___ \  | |     \___ \    / _ \    _____   \ \ / /  |  _|   | |_) |  | |  | |_     | |  |  _|   | |_) |
  ___) | | |___   ___) |  / ___ \  |_____|   \ V /   | |___  |  _ <   | |  |  _|    | |  | |___  |  _ <
 |____/  |_____| |____/  /_/   \_\            \_/    |_____| |_| \_\ |___| |_|     |___| |_____| |_| \_\
slsa-verifier: Verify SLSA provenance for Github Actions

GitVersion:    2.0.3
GitCommit:     38829fa7d9491108bc3a86a6160fb2d53ddc3506
GitTreeState:  clean
BuildDate:     2023-03-11T03:02:01
GoVersion:     go1.18.10
Compiler:      gc
Platform:      darwin/arm64

Without --source-tag, slsa-verifier succeeded.

$ slsa-verifier verify-artifact --provenance-path multiple.intoto.jsonl osv-scanner_1.4.3_darwin_arm64 --source-uri=github.com/google/osv-scanner 
Verified signature against tlog entry index 46958093 at URL: https://rekor.sigstore.dev/api/v1/log/entries/24296fb24b8ad77a578bd1cfcad81368e4524e0ed934b939d91026a9b41ee64e53177ba71dee1b2d
Verified build using builder https://github.com/slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@refs/tags/v1.9.0 at commit 6316373e47d7e3e4b4fd3630c4bbc10987738de6
Verifying artifact osv-scanner_1.4.3_darwin_arm64: PASSED

PASSED: Verified SLSA provenance

However, slsa-verifier failed with --source-tag

$ slsa-verifier verify-artifact --provenance-path multiple.intoto.jsonl osv-scanner_1.4.3_darwin_arm64 --source-uri=github.com/google/osv-scanner --source-tag v1.4.3
Verified signature against tlog entry index 46958093 at URL: https://rekor.sigstore.dev/api/v1/log/entries/24296fb24b8ad77a578bd1cfcad81368e4524e0ed934b939d91026a9b41ee64e53177ba71dee1b2d
Verifying artifact osv-scanner_1.4.3_darwin_arm64: FAILED: expected tag 'refs/tags/v1.4.3', got '': tag used to generate the binary does not match provenance

FAILED: SLSA verification failed: expected tag 'refs/tags/v1.4.3', got '': tag used to generate the binary does not match provenance

Cause

cf948ee

The event of .github/workflows/goreleaser.yml was changed from push event to workflow_dispatch event.
But to verify SLSA Provenance with --source-tag, the workflow must be triggered by push event.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions