electron
electron copied to clipboard
build: generate artifact attestions for released assets
Based on sam/limit-workflow-permissions for easier permission stuff.
- Introduces a cloning system for the
-buildsegment so that we can have two permissions sets for the same set of work (normal builds should not have the attestation capability) - Attests to every artifact we upload to github
Should test this in a nightly and then backport. I don't think this attests to our checksum file but we can figure that out later.
Notes: none
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
| Diff | Package | Supply Chain Security |
Vulnerability | Quality | Maintenance | License |
|---|---|---|---|---|---|---|
| yaml@2.8.1 |
@electron/wg-infra this PR's been in limbo for a couple of months now, does anyone have cycles to review?