Repository navigation
Implement build provenance attestations before release creation #115
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 3 commits
Commits
Show all changes
8 commits
Select commit
Hold shift + click to select a range
accce43
Initial plan
Copilot 8f09d17
Add immutable releases support with build provenance attestations
Copilot 3fdc0bf
Fix backtick escaping in release notes generation
Copilot 920ab99
Address PR review feedback: move attestations before release, clarify…
Copilot 0e0ff40
Improve readability by breaking long sentence into two sentences
Copilot 9ef8fa1
Polish documentation for better clarity and conciseness
Copilot 6ded19b
Final wording improvement: clarify immutability as user action
Copilot a51fc51
Update documentation to reflect enabled immutability
Copilot File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,174 @@ | ||
| # Release Process | ||
|
|
||
| This document describes the release process for DedPaste, including our implementation of GitHub's Immutable Releases feature for enhanced supply chain security. | ||
|
|
||
| ## Overview | ||
|
|
||
| DedPaste uses an automated release workflow that creates immutable, cryptographically attested releases. This ensures that all release artifacts are tamper-proof and verifiable. | ||
|
|
||
| ## Automated Release Workflow | ||
|
|
||
| ### Version Bumping | ||
|
|
||
| When a pull request is merged to the `main` branch: | ||
|
|
||
| 1. **Auto Version Bump** workflow analyzes the PR: | ||
| - Checks PR labels (`major`, `minor`, `patch`) | ||
| - Analyzes commit messages for conventional commit patterns | ||
| - Determines the appropriate version bump | ||
|
|
||
| 2. Conventional commit patterns: | ||
| - `feat:` or `feat(scope):` → Minor version bump | ||
| - `fix:` or `fix(scope):` → Patch version bump | ||
| - `BREAKING CHANGE:` or `feat!:` → Major version bump | ||
|
|
||
| 3. Updates `package.json` with the new version | ||
| 4. Triggers the release workflow | ||
|
|
||
| ### Release Creation | ||
|
|
||
| The **Release with SBOM and Notes** workflow: | ||
|
|
||
| 1. **Builds the project** | ||
| - Compiles TypeScript files | ||
| - Runs tests | ||
| - Generates build artifacts | ||
|
|
||
| 2. **Generates SBOM** | ||
| - Creates a Software Bill of Materials (SBOM) in CycloneDX format | ||
| - Documents all dependencies and their versions | ||
|
|
||
| 3. **Creates release notes** | ||
| - Lists all commits since the last release | ||
| - Links to relevant pull requests | ||
| - Includes SBOM information | ||
| - Adds verification instructions | ||
|
|
||
| 4. **Publishes the release** | ||
| - Creates a GitHub release with the tag `vX.Y.Z` | ||
| - Attaches the SBOM file | ||
| - Includes detailed release notes | ||
|
|
||
| 5. **Generates build provenance attestations** 🔐 | ||
| - Creates cryptographic attestations for all release artifacts | ||
| - Signs attestations using GitHub's Sigstore integration | ||
| - Ensures artifacts are immutable and verifiable | ||
|
|
||
| 6. **Publishes to NPM** | ||
| - Publishes the package with provenance | ||
| - Uses OIDC Trusted Publishers for secure authentication | ||
|
|
||
| ## Immutable Releases 🔐 | ||
|
|
||
| ### What are Immutable Releases? | ||
|
|
||
| Immutable releases are a security feature that makes release artifacts tamper-proof: | ||
|
|
||
| - **Immutable assets**: Once published, release artifacts cannot be modified, added, or deleted | ||
| - **Protected tags**: Git tags are locked to specific commits and cannot be moved | ||
| - **Cryptographic attestations**: Each release includes signed build provenance attestations | ||
| - **Verifiable provenance**: Anyone can verify that artifacts were built by the official workflow | ||
|
|
||
| ### How We Implement It | ||
|
|
||
| Our release workflow automatically: | ||
|
|
||
| 1. **Generates build provenance attestations** for: | ||
| - SBOM file (`bom.json`) | ||
| - Build artifacts (`dist/*`) | ||
|
|
||
| 2. **Signs attestations** using GitHub's Sigstore integration | ||
| - Uses the GitHub Actions OIDC token | ||
| - Creates tamper-evident signatures | ||
| - Links artifacts to specific workflow runs and commits | ||
|
|
||
| 3. **Publishes immutable releases** | ||
| - All releases are immutable by default (enabled at repository settings) | ||
|
anoncam marked this conversation as resolved.
Outdated
|
||
| - Release artifacts cannot be modified after publication | ||
| - Tags cannot be moved or deleted | ||
|
|
||
| ### Verifying Releases | ||
|
|
||
| Anyone can verify the authenticity and integrity of our releases using the GitHub CLI: | ||
|
|
||
| ```bash | ||
| # Install GitHub CLI if needed | ||
| # See: https://cli.github.com/ | ||
|
|
||
| # Verify the SBOM file | ||
| gh attestation verify bom.json --owner anoncam --repo dedpaste | ||
|
|
||
| # Verify build artifacts | ||
| gh attestation verify <artifact-path> --owner anoncam --repo dedpaste | ||
|
|
||
| # Download and verify a release artifact | ||
| gh release download v1.24.0 --pattern "bom.json" --repo anoncam/dedpaste | ||
| gh attestation verify bom.json --owner anoncam --repo dedpaste | ||
| ``` | ||
|
|
||
| Verification confirms: | ||
| - ✅ Artifact was built by the official GitHub Actions workflow | ||
| - ✅ Artifact has not been tampered with since publication | ||
| - ✅ Artifact is linked to specific commits and workflow runs | ||
| - ✅ Build process is traceable and transparent | ||
|
|
||
| ### Benefits | ||
|
|
||
| 1. **Supply Chain Security** | ||
| - Prevents tampering with release artifacts | ||
| - Protects against malicious code injection | ||
| - Ensures artifacts match the source code | ||
|
|
||
| 2. **Transparency** | ||
| - Complete build provenance tracking | ||
| - Verifiable connection between code and artifacts | ||
| - Audit trail for all releases | ||
|
|
||
| 3. **Trust** | ||
| - Users can verify authenticity of downloads | ||
| - Cryptographic proof of origin | ||
| - Compliance with security best practices | ||
|
|
||
| ## Manual Release Process | ||
|
|
||
| If needed, maintainers can trigger a release manually: | ||
|
|
||
| 1. Go to the [Actions tab](https://github.com/anoncam/dedpaste/actions) | ||
| 2. Select "Release with SBOM and Notes" workflow | ||
| 3. Click "Run workflow" | ||
| 4. Optionally specify a version to force release | ||
|
|
||
| ## Troubleshooting | ||
|
|
||
| ### Release Already Exists | ||
|
|
||
| If a release already exists for a version, the workflow will skip creating a duplicate. Check: | ||
| - Existing releases: https://github.com/anoncam/dedpaste/releases | ||
| - Workflow logs in the Actions tab | ||
|
|
||
| ### Build Attestation Failures | ||
|
|
||
| If attestation generation fails: | ||
| - Check that `id-token: write` and `attestations: write` permissions are set | ||
| - Verify the workflow is running on a public repository | ||
| - Check GitHub Actions logs for detailed error messages | ||
|
|
||
| ### NPM Publish Failures | ||
|
|
||
| If NPM publishing fails: | ||
| - Verify the version doesn't already exist on NPM | ||
| - Check that OIDC Trusted Publishers are configured correctly | ||
| - Review npm provenance documentation | ||
|
|
||
| ## Security Considerations | ||
|
|
||
| - **Never manually modify releases**: All releases should be created by the automated workflow | ||
| - **Verify downloads**: Always verify release artifacts using `gh attestation verify` | ||
| - **Report issues**: If you find any security concerns, please report them responsibly | ||
|
|
||
| ## Additional Resources | ||
|
|
||
| - [GitHub Immutable Releases Documentation](https://docs.github.com/en/repositories/releasing-projects-on-github/creating-releases/immutable-releases) | ||
| - [GitHub Actions Artifact Attestation](https://docs.github.com/en/actions/security-guides/using-artifact-attestations-to-establish-provenance-for-builds) | ||
| - [Sigstore Documentation](https://docs.sigstore.dev/) | ||
| - [SLSA Framework](https://slsa.dev/) | ||
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.