Add SLSA provenance to your releases
Open
- Dominant language
- Java
- Stars
- 11.5k
- Forks
- 402
- Avg merge
- 1d 15h
- Merged PRs (30d)
- 20
Description
Could you look into adding [SLSA provenance](https://slsa.dev/) to your releases ?
Contributor guide
Research direction
Start by reviewing how this repository currently produces and publishes releases, then compare that process with the SLSA provenance requirements linked in the issue. Done means releases include verifiable SLSA provenance, with the release process documenting how it is generated and attached.
Written by the indexing model from the issue text.
Assessment
- Domain
- release, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100