ci(.github)[SEC-1084]: SLSA supply chain security controls#7479
ci(.github)[SEC-1084]: SLSA supply chain security controls#7479jackkav merged 2 commits intoKong:developfrom
Conversation
|
@jackkav / @filfreire An |
.github/workflows/release-build.yml
Outdated
| runs-on: ${{ matrix.os }} | ||
| env: | ||
| INSO_PACKAGE_NAME: insomnia-inso | ||
| INSO_PACKAGE_WS_PATH: ./packages/insomnia-inso/ |
There was a problem hiding this comment.
WS_PATH isn't very clear what WS means, just _PATH would be clearer.
There was a problem hiding this comment.
Also the amount of indirection here makes the scripts hard to read.
There was a problem hiding this comment.
i have removed the INSO_PACKAGE_WS_PATH and INSO_PACKAGE_ARIFACTS_PATH variables and replaced with ./packages/<env.ISNO_PACKAGE_NAME>/<path>
|
Signatures for container image signing are published to:
@jackkav LMK if the alpha and beta tags are considered for external use and the signatures must be publicly verifiable? In this case, i can point to |
|
lets merge this when we have a spare hour or two to test an alpha and fix any issues. |
* ci(.github)[SEC-1084]: SLSA supply chain security controls * fix gh review comments
* ci(.github)[SEC-1084]: SLSA supply chain security controls * fix gh review comments
New
insomniaandinso-cliusing tag:core@<tag>alpha|beta)alpha|betatagspackage-lock.jsonreleasebranches