Skip to content

feat: sign release artifacts with cosign keyless + provenance attestations - #132

Merged
jkyberneees merged 1 commit into
mainfrom
feat/artifact-signing
Sep 25, 2026
Merged

jkyberneees merged 1 commit into
mainfrom
feat/artifact-signing

Conversation

@jkyberneees

Copy link
Copy Markdown
Contributor

Port of the odek release.yml signing pattern.

  • Keeps the existing GoReleaser job; adds a sign job post-release.
  • Verifies checksums, generates an SPDX SBOM, keyless-signs every asset with cosign (pinned installer v4.1.2 / cosign v3.1.3), and attaches SLSA-shaped in-toto attestations naming the exact source commit.
  • Signs GoReleaser archives (tar.gz/zip) via gh release download/upload since GoReleaser owns the release step.

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
bodek 21ca6db Commit Preview URL

Branch Preview URL
Sep 25 2026, 07:46 AM

@jkyberneees
jkyberneees merged commit 83f2323 into main Sep 25, 2026
9 checks passed
@jkyberneees
jkyberneees deleted the feat/artifact-signing branch September 25, 2026 07:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant