diff --git a/content/homebrew-build-provenance.md b/content/homebrew-build-provenance.md index bb49433..b406ec1 100644 --- a/content/homebrew-build-provenance.md +++ b/content/homebrew-build-provenance.md @@ -16,6 +16,8 @@ attest to all bottles built in the official [Homebrew] CI. This follows last year's [npm provenance] feature, making Homebrew the second major packaging ecosystem to adopt Sigstore! +![](/images/brew-verify.png) + In other words, going forwards, each bottle built by Homebrew will come with a cryptographically verifiable statement binding the bottleā€™s content to the specific workflow and other build-time metadata that produced it. diff --git a/static/images/brew-verify.png b/static/images/brew-verify.png new file mode 100644 index 0000000..bb9b634 Binary files /dev/null and b/static/images/brew-verify.png differ