Skip to content

feat(ci): attest build provenance - #55

Merged
hyperpolymath merged 1 commit into
mainfrom
feat/attest-build-provenance
Jun 25, 2026
Merged

feat(ci): attest build provenance#55
hyperpolymath merged 1 commit into
mainfrom
feat/attest-build-provenance

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Adds GitHub native build-provenance attestation to the container publish (id-token+attestations perms, digest captured from build-push, attest-build-provenance binds the pushed image). Part of the estate artifact-attestation rollout; mirrors the proven exemplar. Verify: gh attest verify oci://: --repo .

🤖 Generated with Claude Code

Adds actions/attest-build-provenance@v2 (SHA-pinned) after the container
build-push step, with id-token+attestations job permissions and the image
digest captured via the build-push step id. Additive only.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@hyperpolymath
hyperpolymath merged commit cf1b608 into main Jun 25, 2026
10 of 19 checks passed
@hyperpolymath
hyperpolymath deleted the feat/attest-build-provenance branch June 25, 2026 08:40
hyperpolymath added a commit that referenced this pull request Jun 26, 2026
## Why

Follow-up to #50. Two more services were still built and pushed (now
also with build-provenance attestations from #55) under odds-and-sods,
mis-attributing their GHCR packages:

- **`oikos`** → belongs to **`hyperpolymath/oikosbot`**; the package
should be relinked there.
- **`claim-forge`** → part of a private system; it must not be published
as a public OPSM package (its source `services/claim-forge/` is also
public in this repo — see "open items").

`docker/metadata-action` injects `org.opencontainers.image.source` from
the repo running the build, so anything built here links to
odds-and-sods regardless of where it really belongs.

## What

Removes `oikos` and `claim-forge` from the `trust-pipeline-images` build
matrix. **`cerro-torre`** is now the only service still built here —
flagged in-file pending confirmation it has no upstream/private home of
its own.

This is self-contained: `trust-pipeline-e2e.yml` *pulls* these images
(it doesn't depend on the build job), so trimming the matrix doesn't
break e2e.

## Manual GHCR steps (API can't do these)

- `oikos`: Package → settings → unlink (🗑) → relink to `oikosbot`.
- `claim-forge`: delete the public package (and decide on the public
source — see below).

## Open items / follow-ups

- **claim-forge privacy** — `services/claim-forge/` is a real 229-line
public Rust service in this public repo. If it's meant to be private,
the *source* needs removing too, not just the package.
- **cerro-torre** — confirm whether it's OPSM-native (keep building) or
someone else's/private (remove).
- **Deletion coupling** — `oikos`/`claim-forge`/`cicd-hyper-a` are still
referenced by `trust-pipeline-e2e.yml`, `selur-compose.yml` and OPSM
core. Deleting the `claim-forge`/`cicd-hyper-a` packages needs a
separate pass to strip those references first, or e2e CI will fail to
pull them.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01J88oVkzkSn8DyHx3zxKeXS

---
_Generated by [Claude
Code](https://claude.ai/code/session_01J88oVkzkSn8DyHx3zxKeXS)_

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant