SLSA Level 1 #93
Replies: 1 comment
-
The current plan is to implement this for docker builds. When the security agent that As a developer, no change would be required, other than adding the This experience, of automatically getting the provenance information would be similar to Google Cloud Build: https://cloud.google.com/build/docs/securing-builds/view-build-provenance In a future release, it should also be possible to push the provenance record along with the image when docker credentials have been configured (e.g. when |
Beta Was this translation helpful? Give feedback.
-
harden-runner
will generate provenance in the future. It should then be possible to meet SLSA level 1 using GitHub Actions hosted-runner when usingharden-runner
.You will then be able to view provenance of your artifacts along with the security insights.
Please share ideas/ requirements around this.
Beta Was this translation helpful? Give feedback.
All reactions