Repository navigation
feat(ci): add publish-src workflow for test image - #23
Conversation
Add a GitHub Actions workflow that publishes the repository contents as a blob archive to ghcr.io/meigma/blob-cli/src:latest on merge to master. Features: - Sigstore keyless signing - SLSA provenance generation via slsa-github-generator - Self-verification against policy file The workflow enables consumers to test blob CLI operations against a known-good signed and attested archive. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Kusari Analysis Results:
Both dependency and code analyses recommend proceeding. No dependency vulnerabilities were detected. The code analysis identified 3 high-severity permission issues, but these are best practice violations rather than critical exploitable vulnerabilities. The risk is significantly mitigated because the workflow only triggers on pushes to the master branch, meaning only maintainers with write access can execute it. No secrets exposure, critical code vulnerabilities, or dependency issues were found. While the excessive permissions should be addressed by moving them from workflow-level to job-level scope to follow the principle of least privilege, they do not pose an immediate security threat that would block the PR. The attack surface is controlled and limited to trusted maintainers. Note View full detailed analysis result for more information on the output and the checks that were run.
Found this helpful? Give it a 👍 or 👎 reaction! |
|
|
||
| permissions: | ||
| contents: read | ||
| packages: write |
There was a problem hiding this comment.
Issue: The packages:write permission is granted at workflow level, making it available to all jobs. This should be scoped to only the build-and-push job that requires it for publishing packages.
Recommended Code Changes:
Remove packages:write from workflow-level permissions and add it to the build-and-push job:
At workflow level (line 10-14), change to:
permissions:
contents: read
In the build-and-push job, add:
jobs:
build-and-push:
name: Build and Push
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
id-token: write
attestations: write
| permissions: | ||
| contents: read | ||
| packages: write | ||
| id-token: write # Required for Sigstore keyless signing and SLSA |
There was a problem hiding this comment.
Issue: The id-token:write permission at workflow level allows pull requests to request identity tokens. This should be scoped to only the provenance job that requires it for SLSA attestation signing.
Recommended Code Changes:
Remove id-token:write from workflow-level permissions. Add it only to the provenance job:
At workflow level:
permissions:
contents: read
In provenance job:
provenance:
name: Generate SLSA Provenance
needs: [build-and-push]
permissions:
actions: read
id-token: write
packages: write
| name: Publish Source Archive | ||
|
|
||
| on: | ||
| pull_request: |
There was a problem hiding this comment.
Issue: The workflow triggers on pull_request events with write permissions, allowing untrusted code from external contributors to execute with elevated permissions. Publishing and signing operations should never run on pull requests from untrusted sources.
Recommended Code Changes:
Change the workflow trigger from pull_request to push events only:
on:
push:
branches: [master]
The Sigstore identity includes the full workflow path with ref suffix, e.g., .../publish-src.yml@refs/heads/master. Update pattern to match. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
|
Kusari PR Analysis rerun based on - 1a0ff00 performed at: 2026-01-24T04:48:01Z - link to updated analysis |
The CLI's YAML policy format for signature.keyless.identity uses exact string matching via sigstore.WithIdentity, which doesn't support the pattern matching needed for GitHub Actions workflow identity verification. Switch to SLSA provenance verification only, which properly handles GitHub Actions workflow matching. The SLSA attestation is itself signed, maintaining supply chain security. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
|
Kusari PR Analysis rerun based on - 79991ba performed at: 2026-01-24T04:53:37Z - link to updated analysis |
|
Kusari PR Analysis rerun based on - 5af8985 performed at: 2026-01-24T04:59:12Z - link to updated analysis |
| actions: read | ||
| id-token: write | ||
| packages: write | ||
| uses: slsa-framework/slsa-github-generator/.github/workflows/generator_container_slsa3.yml@v2.1.0 |
There was a problem hiding this comment.
Issue: The SLSA generator action is pinned to a tag (@v2.1.0) rather than a commit hash. While this is common practice and lower risk for official actions, your policy requires hash-based pinning for supply chain security. Consider pinning to the specific commit hash that corresponds to v2.1.0.
Recommended Code Changes:
Pin to commit hash instead of tag. Find the commit hash for v2.1.0 and use:
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_container_slsa3.yml@[commit-hash]
The SLSA GitHub generator stores attestations using tag-based approach (sha256-<digest>.att tags) rather than the OCI Referrers API. The blob CLI currently only discovers attestations via referrers. Switch to manual attestation verification using oras until tag-based attestation discovery is added to the blob library. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
|
Kusari PR Analysis rerun based on - 2661430 performed at: 2026-01-24T05:02:46Z - link to updated analysis |
Replace slsa-github-generator with actions/attest-build-provenance which pushes attestations to the registry using OCI referrers API. This allows the blob library to discover and verify attestations properly. Changes: - Use attest-build-provenance with push-to-registry: true - Add attestations: write permission - Simplify verify step to use blob verify with policy - Update policy to verify SLSA provenance only - Use go-version-file for consistency Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
|
Kusari PR Analysis rerun based on - 5013b12 performed at: 2026-01-24T05:15:56Z - link to updated analysis |
| permissions: | ||
| contents: read | ||
| packages: write | ||
| id-token: write # Required for Sigstore keyless signing |
There was a problem hiding this comment.
Issue: The id-token:write permission at workflow level allows all jobs to request identity tokens. This should be scoped to only jobs that perform signing operations.
Recommended Code Changes:
Move id-token:write from workflow-level to job-level permissions. Remove it from line 13 at workflow level and add it only to jobs that require Sigstore signing (such as build-and-push or provenance jobs).
| contents: read | ||
| packages: write | ||
| id-token: write # Required for Sigstore keyless signing | ||
| attestations: write # Required for GitHub attestations |
There was a problem hiding this comment.
Issue: The attestations:write permission at workflow level allows all jobs to create attestations. This should be scoped to only the jobs that generate attestations.
Recommended Code Changes:
Move attestations:write from workflow-level to job-level permissions. Remove it from line 14 at workflow level and add it only to jobs that create GitHub attestations (such as build-and-push or provenance jobs).
Testing complete - workflow successfully builds, signs, and verifies the source archive with SLSA provenance. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
|
Kusari PR Analysis rerun based on - b9facb0 performed at: 2026-01-24T05:18:45Z - link to updated analysis |
The policy now verifies: 1. Sigstore signature: Must be from the publish-src workflow on master 2. SLSA provenance: Must be from meigma/blob-cli on master branch This ensures the source archive was built by the official CI workflow from the master branch. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Summary
ghcr.io/meigma/blob-cli/src:latestImplementation
Uses
actions/attest-build-provenancewithpush-to-registry: trueto generate SLSA provenance attestations discoverable via OCI Referrers API.Workflow steps:
actions/attest-build-provenanceblob verify --policy .github/policies/src-image.yamlPolicy verification:
The policy verifies:
publish-src.yml@refs/heads/master(GitHub Actions OIDC)meigma/blob-clirepository onrefs/heads/masterbranchTest plan
blob verifyworks with policy filepush: branches: [master]🤖 Generated with Claude Code