Kungfu UNGFU™Developer Platform

Back to Buildchain homeaction / action:github-artifact-attestation

GitHub Artifact Attestation Evidence

Buildchain action page.

GitHub Artifact Attestation Evidence

This internal Buildchain action validates one downloaded Linux release artifact against its platform manifest and Release Passport, writes the custom predicate consumed by actions/attest, and finalizes the retained v1 evidence document.

Consumers should call .github/workflows/github-artifact-attestation.yml; they should not call this action directly. The action parses data files only. It never checks out or executes consumer source or the downloaded subject.

Page metadata

Route
/actions/github-artifact-attestation/
Category
action
Source path
actions/github-artifact-attestation/README.md
Package
@kungfu-tech/buildchain@3.0.6-alpha.0
Digest
sha256:5d18b6cb88a311e660d5895b3264b1a3e3813d00c43a1655a0a9f5ddd5b51895