Skip to content
Latchkey

How to Add Build Provenance With attest-build-provenance

actions/attest-build-provenance produces a signed SLSA provenance statement binding an artifact to the build that made it.

After building, pass the artifact path or image digest to actions/attest-build-provenance. It signs a SLSA provenance predicate with the workflow OIDC identity and stores it as a GitHub artifact attestation.

Steps

  • Grant id-token: write and attestations: write to the job.
  • Build the artifact or push the image and capture its digest.
  • Call actions/attest-build-provenance with subject-path or subject-digest.

Workflow

.github/workflows/ci.yml
jobs:
  build:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      id-token: write
      attestations: write
    steps:
      - uses: actions/checkout@v4
      - run: make build
      - uses: actions/attest-build-provenance@v1
        with:
          subject-path: 'dist/app.tar.gz'

Gotchas

  • The job needs both id-token: write and attestations: write, or the attestation call fails.
  • For images, prefer subject-digest plus subject-name so the attestation binds to the exact digest.

Frequently asked questions

How do I add Build Provenance With attest-build-provenance?
After building, pass the artifact path or image digest to actions/attest-build-provenance. It signs a SLSA provenance predicate with the workflow OIDC identity and stores it as a GitHub artifact attestation.

Related guides

References

Run this faster and cheaper on Latchkey managed runners - self-healing included. Start free → 30-day trial · No credit card