ci: attest release artifacts - #21
Conversation
|
Warning Review limit reached
Next review available in: 25 minutes Limit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?Wait for the limit to reset, then comment An organization admin can change what happens after included review limits in Billing. How do review limits work?CodeRabbit enforces per-developer PR review limits within each organization. For paid Pro and Pro+ reviews, CodeRabbit uses a developer's included PR review attempts over the past 7 days to set the current hourly allowance. At typical activity levels, the full plan allowance applies. Higher sustained activity can lower the allowance until earlier attempts leave the 7-day window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
This PR enhances the release pipeline by generating GitHub Artifact Attestations (signed build provenance) for each produced release archive, and updates documentation to recommend an installation method that can verify those attestations when present.
Changes:
- Add minimal job-scoped permissions required for OIDC-based artifact attestation in the release build job.
- Generate build provenance attestations for each platform-specific release archive via
actions/attest. - Document installation via
miseas the recommended approach, noting attestation verification support.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| README.md | Adds “mise” installation instructions and notes attestation verification. |
| .github/workflows/release.yml | Adds job permissions and an attestation step for built release archives. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Summary
actions/attestValidation
actionlintoxfmt --check .zizmor .github/workflows/git diff --checkmise use -g github:sou1118/typdiffin an isolated temporary environment and rantypdiff --help