GitHub Artifact Attestations are generally available! #129761
Replies: 7 comments 4 replies
This comment was marked as off-topic.
This comment was marked as off-topic.
-
Hey, I just tried the attestation within my organization wich is on the 'Team' plan. I get the following error in the GitHub Actions log:
I couldn't find any information about what plan level is the minimum. So I'm asking here: What plan level do I need to use this feature with a private repository? |
Beta Was this translation helpful? Give feedback.
-
Hi - Any chance you know whether (and/or rough ballpark when) GitHub Artifact Attestations will be made available in GHES? Thank you in advance! |
Beta Was this translation helpful? Give feedback.
-
I have some feedback.
For example, tflint's checksums.txt has attestations, but we can't notice that from GitHub Releases.
So we can't notice easily that we can verify assets using attestations. |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
Is there any way to verify the branch or tag creating artifacts? For example, I want to verify the release tag which created assets. The asset https://github.com/suzuki-shunsuke/test-github-artifact-attestation/releases/tag/v0.1.0-3 I want to verify if the downloaded artifact was really created by the tag |
Beta Was this translation helpful? Give feedback.
-
❤️ ❤️ ❤️❤️ ❤️ ❤️❤️ ❤️ ❤️❤️ ❤️ ❤️ |
Beta Was this translation helpful? Give feedback.
-
Hi,
I‘m excited to announce that GitHub Artifact Attestations are now generally available!
Artifact Attestations allow you to guarantee the integrity of artifacts built inside GitHub Actions by creating and verifying signed attestations. With this release, you can now build an admission controller using GitHub‘s distribution of the Sigstore Policy Controller to validate attestations directly within your Kubernetes clusters.
👀 Want to learn more? Check out these resources:
Beta Was this translation helpful? Give feedback.
All reactions