Skip to content

Build provenance

Build provenance #2

name: Build provenance
on:
workflow_dispatch:
release:
types: [created]
permissions:
contents: read
id-token: write
attestations: write
jobs:
provenance:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
# ==========================================================
# HIER DEIN ECHTES ARTEFAKT ERZEUGEN
# Beispiel:
# ==========================================================
- name: Create release artifact
run: |
mkdir -p dist
zip -r dist/Semantic-Gio-UI.zip . \
-x ".git/*" \
-x "dist/*"
# ==========================================================
# SLSA BUILD PROVENANCE / ATTESTATION
# ==========================================================
- name: Generate signed provenance
uses: actions/attest@v4
with:
subject-path: dist/Semantic-Gio-UI.zip
# Optional: normales GitHub Actions Artefakt
- name: Upload artifact
uses: actions/upload-artifact@v4
with:
name: Semantic-Gio-UI
path: dist/Semantic-Gio-UI.zip