How to Add Build Provenance With attest-build-provenance
actions/attest-build-provenance produces a signed SLSA provenance statement binding an artifact to the build that made it.
After building, pass the artifact path or image digest to actions/attest-build-provenance. It signs a SLSA provenance predicate with the workflow OIDC identity and stores it as a GitHub artifact attestation.
Steps
- Grant
id-token: writeandattestations: writeto the job. - Build the artifact or push the image and capture its digest.
- Call
actions/attest-build-provenancewithsubject-pathorsubject-digest.
Workflow
.github/workflows/ci.yml
jobs:
build:
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
attestations: write
steps:
- uses: actions/checkout@v4
- run: make build
- uses: actions/attest-build-provenance@v1
with:
subject-path: 'dist/app.tar.gz'Gotchas
- The job needs both
id-token: writeandattestations: write, or the attestation call fails. - For images, prefer
subject-digestplussubject-nameso the attestation binds to the exact digest.
Frequently asked questions
How do I add Build Provenance With attest-build-provenance?
After building, pass the artifact path or image digest to actions/attest-build-provenance. It signs a SLSA provenance predicate with the workflow OIDC identity and stores it as a GitHub artifact attestation.
Related guides
How to Build a Rust Binary for Multiple Targets in GitHub ActionsCross-build a Rust binary for several platform targets in GitHub Actions with a matrix, using cross or rustup…
How to Build and Cache a Dev Container in GitHub ActionsBuild a dev container in GitHub Actions with the devcontainers CLI and cache its layers so repeated CI runs r…
How to Close Stale Issues Automatically in GitHub ActionsMark and close inactive issues and pull requests on a schedule in GitHub Actions with the stale action, warni…