Skip to content

Fix release archive attestation paths - #657

Merged
JamieMagee merged 1 commit into
mainfrom
fix-release-archive-attestation-paths
Sep 11, 2026
Merged

JamieMagee merged 1 commit into
mainfrom
fix-release-archive-attestation-paths

Conversation

@JamieMagee

Copy link
Copy Markdown
Member

The release action writes archives under cmd/dependabot/, but the attestation patterns point at the repository root. Add the directory prefix to both archive paths.

@JamieMagee
JamieMagee requested review from a team as code owners September 11, 2026 04:30

@jeffwidman jeffwidman left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤔 Why didn't we catch this previously?

How would we catch this in the future? Is the problem that we never added a client that tries to verify the attestations?

@JamieMagee
JamieMagee added this pull request to the merge queue Sep 11, 2026
@JamieMagee
JamieMagee removed this pull request from the merge queue due to a manual request Sep 11, 2026
@JamieMagee
JamieMagee added this pull request to the merge queue Sep 11, 2026
@JamieMagee

Copy link
Copy Markdown
Member Author

Even if we verified this later, I think the attestation would pass. We would need to verify the file exists to prevent this in the future, or ask actions/attest-build-provenance to do so.

Merged via the queue into main with commit 4e708b9 Sep 11, 2026
107 checks passed
@JamieMagee
JamieMagee deleted the fix-release-archive-attestation-paths branch September 11, 2026 05:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants