From a56ef0009a7838a611da107e3a669c03317667cd Mon Sep 17 00:00:00 2001 From: "Adolfo Garcia Veytia (puerco)" Date: Mon, 5 Oct 2026 00:52:14 +0200 Subject: [PATCH] Attest releases with a released attester The provenance job built the attester from the tip of this repository, unpinned and unverified. Run the released one instead, verified against its own provenance before it runs, as the verifier's release workflow does. Each release is attested by the one before it. Signed-off-by: Adolfo Garcia Veytia (puerco) --- .github/workflows/release.yaml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 62c2f9c..bf2ce95 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -77,6 +77,11 @@ jobs: watch-jobs: release collect-artifacts: false release: ${{ needs.release.outputs.tag_name }} + # Run a released, provenance-verified attester rather than building + # the tip of this repository, which is unpinned and unverified. The + # attester attesting a release is therefore always the previous one. + build-from-source: false + version: v0.1.0-rc.3 # Publish the provenance to the release. The installer action verifies the # downloaded binaries against this file, so it must land on the release as