From 337d8c52c594d11d7259f0fe5af25216e268db13 Mon Sep 17 00:00:00 2001 From: Vishal Reddy Gurrala Date: Sat, 3 Aug 2024 16:55:25 -0500 Subject: [PATCH] Update release job to generate artifacts attestation Signed-off-by: Vishal Reddy Gurrala --- .github/workflows/release.yml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 2abf24e90..35b41e433 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -17,6 +17,8 @@ env: permissions: # added using https://github.com/step-security/secure-workflows contents: read + id-token: write + attestations: write jobs: check: @@ -131,6 +133,10 @@ jobs: with: name: release-tars-${{env.PLATFORM_CLEAN}} path: src/github.com/containerd/containerd/releases/*.tar.gz* + - name: Attest Artifacts + uses: actions/attest-build-provenance@v1 + with: + subject-path: src/github.com/containerd/containerd/releases/release-tars-${{env.PLATFORM_CLEAN}}.tar.gz* release: name: Create containerd Release