Skip to content

Conversation

@puerco
Copy link
Collaborator

@puerco puerco commented Jan 13, 2026

This PR adds support for pushing from sourcetool natively, eliminating the need to call git from the source actions workflow and also adding the capability to push to github's attestation store.

More importantly, this change will allow us to drop the write permissions in the workflow as we are now able to push the signed statements to the repository's attestations storage without needing write on the code itself.

Signed-off-by: Adolfo Garcia Veytia (puerco) puerco@carabiner.dev

Signed-off-by: Adolfo Garcia Veytia (puerco) <puerco@carabiner.dev>
Signed-off-by: Adolfo Garcia Veytia (puerco) <puerco@carabiner.dev>
Signed-off-by: Adolfo Garcia Veytia (puerco) <puerco@carabiner.dev>
Signed-off-by: Adolfo Garcia Veytia (puerco) <puerco@carabiner.dev>
Signed-off-by: Adolfo Garcia Veytia (puerco) <puerco@carabiner.dev>
@puerco puerco merged commit 9b7937f into slsa-framework:main Jan 13, 2026
2 checks passed
@puerco puerco deleted the push branch January 13, 2026 19:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant