Repository navigation
ci(release): sign the archives with cosign beside their attestation #336
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
@@ -20,9 +20,9 @@ and shipped with a CycloneDX SBOM. | |||||||||||||||
|
|
||||||||||||||||
| ## Verifying what you downloaded | ||||||||||||||||
|
|
||||||||||||||||
| Every release ships three kinds of proof: a `.sha256` beside each archive, a build provenance | ||||||||||||||||
| attestation on each archive, and a CycloneDX SBOM per crate (`lfsx-server.cdx.json`, | ||||||||||||||||
| `lfsx.cdx.json`). They answer different questions. | ||||||||||||||||
| Every release ships four kinds of proof: a `.sha256` beside each archive, a build provenance | ||||||||||||||||
| attestation on each archive, a `.sigstore` signature bundle beside each archive, and a CycloneDX | ||||||||||||||||
| SBOM per crate (`lfsx-server.cdx.json`, `lfsx.cdx.json`). They answer different questions. | ||||||||||||||||
|
Comment on lines
+23
to
+25
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Nit: "every release" is not true for the bundle, as the PR body says: v1.16.x and everything before it has no
Suggested change
|
||||||||||||||||
|
|
||||||||||||||||
| The checksum proves the download survived the wire: | ||||||||||||||||
|
|
||||||||||||||||
|
|
@@ -37,6 +37,20 @@ commit, which is the claim a checksum next to the artifact it checks cannot make | |||||||||||||||
| gh attestation verify lfsx-server-x86_64-unknown-linux-musl.tar.gz --repo FerrLabs/LFSX | ||||||||||||||||
| ``` | ||||||||||||||||
|
|
||||||||||||||||
| The signature bundle says the same thing without asking GitHub. `gh attestation verify` reads | ||||||||||||||||
| GitHub's attestation store, so it needs GitHub to answer; the bundle beside the archive is checked | ||||||||||||||||
| against the public transparency log by cosign alone: | ||||||||||||||||
|
|
||||||||||||||||
| ```bash | ||||||||||||||||
| cosign verify-blob lfsx-server-x86_64-unknown-linux-musl.tar.gz \ | ||||||||||||||||
| --bundle lfsx-server-x86_64-unknown-linux-musl.tar.gz.sigstore \ | ||||||||||||||||
| --certificate-identity-regexp '^https://github.com/FerrLabs/LFSX/' \ | ||||||||||||||||
| --certificate-oidc-issuer https://token.actions.githubusercontent.com | ||||||||||||||||
| ``` | ||||||||||||||||
|
|
||||||||||||||||
| The two identity flags are the point of the check: without them cosign confirms that somebody | ||||||||||||||||
| signed the bytes, not that this repository's workflow did. | ||||||||||||||||
|
|
||||||||||||||||
| The SBOM lists every crate in the build for scanners and licence tooling, and is attested the same | ||||||||||||||||
| way. The container image is verified separately: it is signed with cosign at push and its | ||||||||||||||||
| signature and SBOM live next to it in the registry. | ||||||||||||||||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Nit: if the archive names ever move (a
taiki-e/upload-rust-binary-actionbump, anarchive:rename), every[ -f ]misses, the loop signs nothing and the step exits 0. The release then ships unsigned with a green workflow, which is the exact state this PR exists to fix. Two archives per runner is a fixed number, so assert it: