Generate SLSA3 provenance for all Flux components #3994
Labels
area/ci
CI related issues and pull requests
area/security
Security related issues and pull requests
umbrella-issue
Umbrella issue for tracking progress of a larger effort
Milestone
All the GitOps Toolkit controllers and the Flux CLI should make use of the SLSA GitHub Generator at release time for generating non-forgeable SLSA provenance on GitHub that meets the provenance generation and isolation requirements for SLSA Build level 3 and above.
Generators:
generator_generic_slsa3
for the release assets (binaries, SBOMs, source code)generator_container_slsa3
for the multi-arch container images (DockerHub and GHCR)Add the SLSA3 generators to the following release workflows:
The text was updated successfully, but these errors were encountered: