Skip to content

Add minimal GitHub build attestation workflow#28

Draft
joy7758 wants to merge 13 commits intomainfrom
feature/minimal-build-attestation-20260423
Draft

Add minimal GitHub build attestation workflow#28
joy7758 wants to merge 13 commits intomainfrom
feature/minimal-build-attestation-20260423

Conversation

@joy7758
Copy link
Copy Markdown
Owner

@joy7758 joy7758 commented Apr 23, 2026

Summary

  • add a standalone Build + Attest GitHub Actions workflow for Python distribution artifacts
  • build dist/*, upload them as the python-dist workflow artifact, and generate GitHub artifact attestations via actions/attest@v4
  • add a short docs note describing scope, verification path, and plan limitations
  • add one minimal README link so the path is discoverable

Boundary

This adds a minimal upstream build provenance path only.
It does not change AEP schema, bundle/receipt/summary semantics, CLI, or runtime evidence behavior.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant