Publish release provenance attestations#457
Conversation
Publish GitHub artifact attestations for release binaries from checksums.txt and attest the checksum manifest before creating the release. Document the checksum-only installer behavior, manual provenance verification, failure modes, and trust model for the GitHub Action and npm wrapper. Tested: cargo fmt --check; cargo clippy --all-targets --all-features -- -D warnings; bash -n scripts/release.sh; cargo test --test release_provenance; PATH=/bin:/usr/bin:/usr/local/bin:/opt/homebrew/bin:/Users/darkroom/.cargo/bin cargo test
|
Warning Review limit reached
More reviews will be available in 28 minutes and 8 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (6)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
Verification
Closes #450