Generate SLSA build provenance in GitHub Actions
Attach signed SLSA provenance to GitHub Actions builds so release artifacts ship with verifiable supply-chain metadata.
Prerequisites
GitHub Actions, SLSA GitHub Generator
Installation
Requirements and caveats from upstream:
- [](https://github.com/aws-powertools/powertools-l...
- | Node.js projects | Node.js Builder | Builds and generates provenance for npm packages | [Beta since v1.6.0](https://github.com/slsa-framework/slsa-github-g...
Basic usage or getting-started notes:
SLSA Build level 3 and above. See some
popular projects generating provenance using this project.
tools for building a SLSA builder on GitHub using the
Source: https://github.com/slsa-framework/slsa-github-generator
Extracted from upstream docs: https://raw.githubusercontent.com/slsa-framework/slsa-github-generator/HEAD/README.md