feat(ci): attest build provenance - #55
Merged
Merged
Conversation
Adds actions/attest-build-provenance@v2 (SHA-pinned) after the container build-push step, with id-token+attestations job permissions and the image digest captured via the build-push step id. Additive only. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
hyperpolymath
added a commit
that referenced
this pull request
Jun 26, 2026
## Why Follow-up to #50. Two more services were still built and pushed (now also with build-provenance attestations from #55) under odds-and-sods, mis-attributing their GHCR packages: - **`oikos`** → belongs to **`hyperpolymath/oikosbot`**; the package should be relinked there. - **`claim-forge`** → part of a private system; it must not be published as a public OPSM package (its source `services/claim-forge/` is also public in this repo — see "open items"). `docker/metadata-action` injects `org.opencontainers.image.source` from the repo running the build, so anything built here links to odds-and-sods regardless of where it really belongs. ## What Removes `oikos` and `claim-forge` from the `trust-pipeline-images` build matrix. **`cerro-torre`** is now the only service still built here — flagged in-file pending confirmation it has no upstream/private home of its own. This is self-contained: `trust-pipeline-e2e.yml` *pulls* these images (it doesn't depend on the build job), so trimming the matrix doesn't break e2e. ## Manual GHCR steps (API can't do these) - `oikos`: Package → settings → unlink (🗑) → relink to `oikosbot`. - `claim-forge`: delete the public package (and decide on the public source — see below). ## Open items / follow-ups - **claim-forge privacy** — `services/claim-forge/` is a real 229-line public Rust service in this public repo. If it's meant to be private, the *source* needs removing too, not just the package. - **cerro-torre** — confirm whether it's OPSM-native (keep building) or someone else's/private (remove). - **Deletion coupling** — `oikos`/`claim-forge`/`cicd-hyper-a` are still referenced by `trust-pipeline-e2e.yml`, `selur-compose.yml` and OPSM core. Deleting the `claim-forge`/`cicd-hyper-a` packages needs a separate pass to strip those references first, or e2e CI will fail to pull them. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01J88oVkzkSn8DyHx3zxKeXS --- _Generated by [Claude Code](https://claude.ai/code/session_01J88oVkzkSn8DyHx3zxKeXS)_ Co-authored-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds GitHub native build-provenance attestation to the container publish (id-token+attestations perms, digest captured from build-push, attest-build-provenance binds the pushed image). Part of the estate artifact-attestation rollout; mirrors the proven exemplar. Verify: gh attest verify oci://
: --repo .
🤖 Generated with Claude Code