Skip to content

feat(ci): add publish-src workflow for test image - #23

Merged
jmgilman merged 8 commits into
masterfrom
feat/publish-src-workflow
Jan 24, 2026
Merged

jmgilman merged 8 commits into
masterfrom
feat/publish-src-workflow

Conversation

@jmgilman

@jmgilman jmgilman commented Jan 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add GitHub Actions workflow that publishes repository contents as a blob archive
  • Target: ghcr.io/meigma/blob-cli/src:latest
  • Features: Sigstore keyless signing, SLSA provenance attestation, policy-based verification

Implementation

Uses actions/attest-build-provenance with push-to-registry: true to generate SLSA provenance attestations discoverable via OCI Referrers API.

Workflow steps:

  1. Build and Push: Pushes source archive with Sigstore keyless signing
  2. Generate Attestation: Creates SLSA provenance via actions/attest-build-provenance
  3. Verify: Verifies archive using blob verify --policy .github/policies/src-image.yaml

Policy verification:

The policy verifies:

  • Signature: Must be from publish-src.yml@refs/heads/master (GitHub Actions OIDC)
  • SLSA Provenance: Must be from meigma/blob-cli repository on refs/heads/master branch

Test plan

  • Workflow runs successfully with SLSA attestation (tested with PR trigger)
  • blob verify works with policy file
  • Trigger set to push: branches: [master]
  • Full verification (signature + provenance) will run on first merge to master

Note: Signature verification can only be fully tested on master because the OIDC identity includes the git ref.

🤖 Generated with Claude Code

Add a GitHub Actions workflow that publishes the repository contents
as a blob archive to ghcr.io/meigma/blob-cli/src:latest on merge to
master.

Features:
- Sigstore keyless signing
- SLSA provenance generation via slsa-github-generator
- Self-verification against policy file

The workflow enables consumers to test blob CLI operations against
a known-good signed and attested archive.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@kusari-inspector

kusari-inspector Bot commented Jan 24, 2026 •

Copy link
Copy Markdown

Kusari Inspector

Kusari Analysis Results:

Proceed with these changes

✅ No Flagged Issues Detected
All values appear to be within acceptable risk parameters.

Both dependency and code analyses recommend proceeding. No dependency vulnerabilities were detected. The code analysis identified 3 high-severity permission issues, but these are best practice violations rather than critical exploitable vulnerabilities. The risk is significantly mitigated because the workflow only triggers on pushes to the master branch, meaning only maintainers with write access can execute it. No secrets exposure, critical code vulnerabilities, or dependency issues were found. While the excessive permissions should be addressed by moving them from workflow-level to job-level scope to follow the principle of least privilege, they do not pose an immediate security threat that would block the PR. The attack surface is controlled and limited to trusted maintainers.

Note

View full detailed analysis result for more information on the output and the checks that were run.


@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: b9facb0, performed at: 2026-01-24T05:18:03Z

Found this helpful? Give it a 👍 or 👎 reaction!


permissions:
contents: read
packages: write

@kusari-inspector kusari-inspector Bot Jan 24, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Issue: The packages:write permission is granted at workflow level, making it available to all jobs. This should be scoped to only the build-and-push job that requires it for publishing packages.

Recommended Code Changes:

Remove packages:write from workflow-level permissions and add it to the build-and-push job:

At workflow level (line 10-14), change to:
permissions:
  contents: read

In the build-and-push job, add:
jobs:
  build-and-push:
    name: Build and Push
    runs-on: ubuntu-latest
    permissions:
      contents: read
      packages: write
      id-token: write
      attestations: write

Comment thread .github/workflows/publish-src.yml Outdated
permissions:
contents: read
packages: write
id-token: write # Required for Sigstore keyless signing and SLSA

@kusari-inspector kusari-inspector Bot Jan 24, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Issue: The id-token:write permission at workflow level allows pull requests to request identity tokens. This should be scoped to only the provenance job that requires it for SLSA attestation signing.

Recommended Code Changes:

Remove id-token:write from workflow-level permissions. Add it only to the provenance job:

At workflow level:
permissions:
  contents: read

In provenance job:
provenance:
  name: Generate SLSA Provenance
  needs: [build-and-push]
  permissions:
    actions: read
    id-token: write
    packages: write

Comment thread .github/workflows/publish-src.yml Outdated
name: Publish Source Archive

on:
pull_request:

@kusari-inspector kusari-inspector Bot Jan 24, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Issue: The workflow triggers on pull_request events with write permissions, allowing untrusted code from external contributors to execute with elevated permissions. Publishing and signing operations should never run on pull requests from untrusted sources.

Recommended Code Changes:

Change the workflow trigger from pull_request to push events only:

on:
  push:
    branches: [master]

The Sigstore identity includes the full workflow path with ref suffix,
e.g., .../publish-src.yml@refs/heads/master. Update pattern to match.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@kusari-inspector

Copy link
Copy Markdown

Kusari PR Analysis rerun based on - 1a0ff00 performed at: 2026-01-24T04:48:01Z - link to updated analysis

The CLI's YAML policy format for signature.keyless.identity uses exact
string matching via sigstore.WithIdentity, which doesn't support the
pattern matching needed for GitHub Actions workflow identity verification.

Switch to SLSA provenance verification only, which properly handles
GitHub Actions workflow matching. The SLSA attestation is itself signed,
maintaining supply chain security.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@kusari-inspector

Copy link
Copy Markdown

Kusari PR Analysis rerun based on - 79991ba performed at: 2026-01-24T04:53:37Z - link to updated analysis

@kusari-inspector

Copy link
Copy Markdown

Kusari PR Analysis rerun based on - 5af8985 performed at: 2026-01-24T04:59:12Z - link to updated analysis

Comment thread .github/workflows/publish-src.yml Outdated
actions: read
id-token: write
packages: write
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_container_slsa3.yml@v2.1.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Issue: The SLSA generator action is pinned to a tag (@v2.1.0) rather than a commit hash. While this is common practice and lower risk for official actions, your policy requires hash-based pinning for supply chain security. Consider pinning to the specific commit hash that corresponds to v2.1.0.

Recommended Code Changes:

Pin to commit hash instead of tag. Find the commit hash for v2.1.0 and use:

uses: slsa-framework/slsa-github-generator/.github/workflows/generator_container_slsa3.yml@[commit-hash]

The SLSA GitHub generator stores attestations using tag-based approach
(sha256-<digest>.att tags) rather than the OCI Referrers API. The blob
CLI currently only discovers attestations via referrers.

Switch to manual attestation verification using oras until tag-based
attestation discovery is added to the blob library.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@kusari-inspector

Copy link
Copy Markdown

Kusari PR Analysis rerun based on - 2661430 performed at: 2026-01-24T05:02:46Z - link to updated analysis

Replace slsa-github-generator with actions/attest-build-provenance which
pushes attestations to the registry using OCI referrers API. This allows
the blob library to discover and verify attestations properly.

Changes:
- Use attest-build-provenance with push-to-registry: true
- Add attestations: write permission
- Simplify verify step to use blob verify with policy
- Update policy to verify SLSA provenance only
- Use go-version-file for consistency

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@kusari-inspector

Copy link
Copy Markdown

Kusari PR Analysis rerun based on - 5013b12 performed at: 2026-01-24T05:15:56Z - link to updated analysis

permissions:
contents: read
packages: write
id-token: write # Required for Sigstore keyless signing

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Issue: The id-token:write permission at workflow level allows all jobs to request identity tokens. This should be scoped to only jobs that perform signing operations.

Recommended Code Changes:

Move id-token:write from workflow-level to job-level permissions. Remove it from line 13 at workflow level and add it only to jobs that require Sigstore signing (such as build-and-push or provenance jobs).

contents: read
packages: write
id-token: write # Required for Sigstore keyless signing
attestations: write # Required for GitHub attestations

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Issue: The attestations:write permission at workflow level allows all jobs to create attestations. This should be scoped to only the jobs that generate attestations.

Recommended Code Changes:

Move attestations:write from workflow-level to job-level permissions. Remove it from line 14 at workflow level and add it only to jobs that create GitHub attestations (such as build-and-push or provenance jobs).

Testing complete - workflow successfully builds, signs, and verifies
the source archive with SLSA provenance.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@kusari-inspector

Copy link
Copy Markdown

Kusari PR Analysis rerun based on - b9facb0 performed at: 2026-01-24T05:18:45Z - link to updated analysis

The policy now verifies:
1. Sigstore signature: Must be from the publish-src workflow on master
2. SLSA provenance: Must be from meigma/blob-cli on master branch

This ensures the source archive was built by the official CI workflow
from the master branch.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@jmgilman
jmgilman merged commit b96d513 into master Jan 24, 2026
7 checks passed
@jmgilman
jmgilman deleted the feat/publish-src-workflow branch January 24, 2026 05:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant