Skip to content

Commit 125a27b

Browse files
authored
Merge pull request #157 from dorssel/attestation
Add artifact attestation for build provenance
2 parents 28645ea + 7fedcd4 commit 125a27b

1 file changed

Lines changed: 10 additions & 1 deletion

File tree

.github/workflows/dotnet.yml

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,8 @@ permissions:
1818
issues: read
1919
checks: write
2020
pull-requests: write
21+
id-token: write
22+
attestations: write
2123

2224
jobs:
2325
build:
@@ -61,14 +63,21 @@ jobs:
6163
dotnet pack --configuration Release --no-build
6264
6365
- name: Upload Package Artifact
66+
id: upload
6467
uses: actions/upload-artifact@v6
6568
with:
66-
name: nuget-package
69+
name: artifacts
6770
path: |
6871
**/*.nupkg
6972
**/*.snupkg
7073
retention-days: 14
7174
75+
- name: Build Attestation
76+
uses: actions/attest-build-provenance@v3
77+
with:
78+
subject-name: artifacts.zip
79+
subject-digest: sha256:${{ steps.upload.outputs.artifact-digest }}
80+
7281
- name: Upload test results to Codecov
7382
if: ${{ !cancelled() }}
7483
uses: codecov/codecov-action@v5

0 commit comments

Comments
 (0)