slsa-github-generator icon indicating copy to clipboard operation
slsa-github-generator copied to clipboard

Language-agnostic SLSA provenance generation for Github Actions

Results 279 slsa-github-generator issues
Sort by recently updated
recently updated
newest added
trafficstars

Currently the `directory` input checks that it's a sub-directory of `GITHUB_WORKSPACE` but it should also allow `/tmp` and `RUNNER_TEMP` to be used as well.

type:feature
area:nodejs

We also need to update the doc @AdamKorcz assigning to you.

area:BYOB
area:gradle
area:maven

**Is your feature request related to a problem? Please describe.** No, this is not a feature request related to a problem. **Describe the solution you'd like** I'd like to highlight...

type:question
type:discussion
area:container

See https://github.com/slsa-framework/slsa-github-generator/issues/2508 Do we want to store on Maven central to avoid checking out this repo? Can we verify provenance for it if we pull it from Maven central?

area:BYOB

Address the comments @ianlewis left on https://github.com/slsa-framework/slsa-github-generator/commit/ffbc1e5a1af0e70584a8aad5a3529b627fa03b32

type:feature
area:maven

This issue tracks the development of builders for the Gradle and Maven eco systems. I suggest the builders are added to the slsa-github-generator project in the same manner as the...

type:feature
area:gradle
area:maven

The current Action https://github.com/slsa-framework/slsa-github-generator/blob/main/actions/gradle/publish/action.yml - checkout the repo https://github.com/slsa-framework/slsa-github-generator/blob/main/actions/gradle/publish/action.yml#L37, which should not be necessary - expects the attestations to be in a specific folder https://github.com/slsa-framework/slsa-github-generator/blob/main/actions/gradle/publish/action.yml#L59 - don't download the provenance...

type:feature
area:gradle

Currently, the BYOB framework does not allow configuration of the build environment beyond what is set within each respective builder. However, many different repos on Github configure the build environment...

type:feature
area:BYOB

Other builders use gitCommit.

type:feature
area:container-based

Currently not verified. No security implications afaict. The Action is run in its own VM

type:feature
area:BYOB