SLSA build provenance for the teecryptor image, verified by partners at pin time - #1
Merged
Merged
Conversation
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
liorbond
approved these changes
Sep 22, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
A production build now emits a keyless SLSA build provenance attestation for the
amd64 platform digest, using the workflow's OIDC token and Fulcio. No signing key.
Public Rekor, plus GitHub's public attestation API.
The job summary prints
{image_digest, source_sha}and the ready-to-rungh attestation verifycommand.Same shape as the keygen PR, adapted to this repo's multi-arch build.
Why SLSA only, and no cosign
An earlier revision signed with cosign too. Review found a blocker that this change
removes outright rather than works around:
actions/attest@v3.0.0resolves registry credentials only from theauthsobject in~/.docker/config.json. I confirmed this in the published bundle — zero occurrences ofcredHelpers,credsStoreordocker-credentialin 3.5 MB:This job authenticates with
gcloud auth configure-docker, which writes only acredHelpersentry. Withpush-to-registry: truethe attest step would have thrown onevery production build — and because it dies there, the summary step never runs, so every
build would lose the digest handoff this feature exists to produce.
push-to-registry: falsemakes the whole problem vanish. The partner reads the bundlefrom GitHub's public API, which needs no account.
The amd64 detail
This build is multi-arch. It attests
steps.manifest.outputs.amd64_digest— the platformdigest the TDX VM runs and the one partners pin. An attestation on the manifest-list
digest would never match a pin.
Main changes
actions/attest-build-provenance(SHA-pinned) after the Trivy gate, withpush-to-registry: false.if: inputs.testing != true && github.ref == 'refs/heads/main'. A testingbuild never attests: it can run from any branch, so the certificate would carry a ref
no partner accepts.
attestations: writemoved from workflow level to themergejob. At workflowlevel it also landed on
test, which runscargo test— third-party build scripts.if: always()so a failure never costs the operator the digest.SECURITY-OVERVIEW.mdrecords why the CEL cannot carry the origin proof.keys/variables.tf: the deferredimage_signaturesCEL note now says plainly thatkeyless provenance can never satisfy that attribute — it matches a public-key
fingerprint, which a keyless build does not have. Without this, a reader would try to
wire a fingerprint that does not exist.
Honest note on SHA pinning
actions/attest-build-provenanceis SHA-pinned; most other actions in this job are not,including
aquasecurity/trivy-action@master, which runs immediately before it with thesame
id-token: write. The comment now says so rather than implying the pin closes therow.
Checked before pushing
actionlintclean. Summary rendered for both paths — production prints the partner block,testing prints none. Job-level permission scoping verified by parsing the YAML. The verify
flag set exercised against a real attested public image: correct values exit 0; wrong
commit, wrong ref and wrong workflow each exit 1.