Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: use tag for the builder in the release workflow #788

Merged
merged 1 commit into from
Jul 11, 2024

Commits on Jul 11, 2024

  1. fix: use tag for builder

    The slsa-github-generator's workflow ref needs to be pinned by tag, not by hash.
    
    Fixes this error
    
     - https://github.com/slsa-framework/slsa-verifier/actions/runs/9893912259/job/27330429383#step:4:17
    
    ```
    Verifying slsa-verifier-linux-arm64 using slsa-verifier-linux-arm64.intoto.jsonl
    Verified signature against tlog entry index 110869188 at URL: https://rekor.sigstore.dev/api/v1/log/entries/24296fb24b8ad77aa9a66ae8969e055f85c9ec9e0ebbe52e4947cd33cf7b84af120088fe641b8e84
    Verifying artifact slsa-verifier-linux-arm64: FAILED: invalid ref: "c747fe7769adf3656dc7d588b161cb614d7abfee": unexpected ref type: ""
    
    FAILED: SLSA verification failed: invalid ref: "c747fe7769adf3656dc7d588b161cb614d7abfee": unexpected ref type: ""
    ```
    
    Signed-off-by: Ramon Petgrave <32398091+ramonpetgrave64@users.noreply.github.com>
    ramonpetgrave64 authored Jul 11, 2024
    Configuration menu
    Copy the full SHA
    153d639 View commit details
    Browse the repository at this point in the history