upcloud-cli icon indicating copy to clipboard operation
upcloud-cli copied to clipboard

chore(ci): use reusable workflow to attest build provenance

Open scop opened this issue 1 week ago • 0 comments

For SLSA level 3.

Refs

  • https://docs.github.com/en/actions/how-tos/secure-your-work/use-artifact-attestations/increase-security-rating
  • https://github.blog/enterprise-software/devsecops/enhance-build-security-and-reach-slsa-level-3-with-github-artifact-attestations/#achieving-slsa-level-3-compliance-with-github-artifact-attestations

Closes https://github.com/UpCloudLtd/upcloud-cli/issues/426

scop avatar Jan 02 '26 11:01 scop