anchore / anchore/syft

Adding GitHub attestations

Open Beginner friendly
#5,149 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement release
Dominant language
Go
Stars
9.6k
Forks
962
Avg merge
23h 27m
Merged PRs (30d)
48

Description

**What would you like to be added**:

GitHub attestations using `actions/attest`

**Why is this needed**:

Tool installers, such as Mise, check GH attestations automatically before trusting a release checksum.

**Additional context**:

It is an additive change that does not introduce risk. It's very simple to add to an existing GH release workflow.

P.S. Thank you!

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by inspecting the repository's existing GitHub release workflow and how release checksums are produced. Add GitHub attestations for the release artifacts using actions/attest, then verify that a release produces attestations that tool installers can validate.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd, release, security
Issue type
Feature
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
68/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.