Skip to content

Release - Supply-chain hardening (sign + SBOM + provenance + attest) #187

Description

@eminwux

Context

Release-pipeline supply-chain work is currently spread across 6 issues
(#55, #57, #58, #59, #61, #63), all priority:C, that describe one coherent
goal: ship signed, attested, SBOM-bearing release artifacts. They depend on
each other (sign → SBOM → attest), so tracking them as siblings has
inflated the backlog without adding clarity.

Consolidating into a single tracking issue.

Proposal

Phased delivery, each phase a landable PR:

Acceptance criteria

  • Each phase ships independently and verifiably (cosign verify, syft inspect, slsa-verifier).
  • Release-page README documents how downstream consumers verify each artifact.
  • Existing make release flow continues to work without manual signing steps.

Notes

Replaces #55, #57, #58, #59, #61, #63. #56 (SHA256SUMS generation) stays
separate as the gating prerequisite — it can land before this epic begins.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions