SLSA attestation updates #26382
Labels
~engineering-initiated
Engineering-initiated story, such as a bug, refactor, or contributor experience improvement.
#g-orchestration
Orchestration product group
:product
Product Design department (shows up on 🦢 Drafting board)
story
A user story defining an entire feature
Goal
Key result
It looks like we're generating attestations on some workflows that run between releases, causing a lot of extra noise on the attestations page. Definitely the attestations in generate-desktop-targets.yml can be locked down to just happen during a release, and possibly others.
The osqueryd and desktop app attestations for MacOS and Windows are only happening on the archive (zip) files, not the binaries themselves. We should attest the binaries in the archives so that users can verify the binaries on their hosts.
We're attesting the unsigned windows Orbit binary, but we need to do the signed one instead, as that's what hosts end up downloading
Context
Changes
Engineering
QA
Risk assessment
Test plan
Testing notes
Confirmation
The text was updated successfully, but these errors were encountered: