Skip to content

feat(install): verify build provenance via gh attestation - #123

Merged
ryanlewis merged 1 commit into
mainfrom
install-attest
Aug 8, 2026
Merged

ryanlewis merged 1 commit into
mainfrom
install-attest

Conversation

@ryanlewis

Copy link
Copy Markdown
Owner

Closes the loop on the attestations shipped in #122 — the installer now consumes them.

  • install.sh runs gh attestation verify on the downloaded tarball when gh is available and logged in
  • Failed verification is fatal (refuses to install; SKIP_ATTESTATION=1 to bypass)
  • Missing attestation (releases ≤ v0.5.0, which predate ci(security): hardening — provenance, scanning, workflow lockdown #122) warns and continues
  • gh absent or logged out: notes and continues — checksum verification has already passed by then
  • README documents the automatic check and the manual gh attestation verify command

Tested against the live v0.5.0 release: warn-and-install path, skip path, and shellcheck-clean. The fatal path will be exercised for real once v0.5.1 ships with attestations.

When the GitHub CLI is present and logged in, install.sh now verifies the
downloaded tarball against the repo's build provenance attestation and
refuses to install on a failed verification. Releases before v0.5.1
predate attestations, so a missing attestation warns instead of failing.
Opt out with SKIP_ATTESTATION=1. Document verification in the README.
@ryanlewis
ryanlewis merged commit 008782b into main Aug 8, 2026
7 checks passed
@ryanlewis
ryanlewis deleted the install-attest branch August 8, 2026 21:05
ryanlewis added a commit that referenced this pull request Aug 8, 2026
Release notes for v0.5.1. Merge after #123/#124/#125 — goreleaser reads
this file at tag time (`readFile .github/releases/v0.5.1.md`), so it
must be on main before the tag is pushed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant