Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Correlate GHA provenance attestation with GitHub API #11

Open
2 tasks
trishankatdatadog opened this issue Jul 25, 2023 · 0 comments
Open
2 tasks

Correlate GHA provenance attestation with GitHub API #11

trishankatdatadog opened this issue Jul 25, 2023 · 0 comments
Assignees

Comments

@trishankatdatadog
Copy link
Owner

trishankatdatadog commented Jul 25, 2023

Check whether the GitHub Actions run actually exists and matches the recorded provenance metadata on Sigstore and NPM.

  • Check whether GHA was used.
  • Check whether the expected GitHub source code repository was used.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: Todo
Development

No branches or pull requests

3 participants