Skip to content

feat: tag-triggered publish pipeline with attestations - #11

Merged
jmgilman merged 2 commits into
masterfrom
session-007/phase-4-publishing
Apr 23, 2026
Merged

jmgilman merged 2 commits into
masterfrom
session-007/phase-4-publishing

Conversation

@jmgilman

Copy link
Copy Markdown
Contributor

Summary

  • Adds the four-part publishing pipeline: release.yml (tag entrypoint with verify → release → finalize jobs), reusable-release.yml (trusted builder), plus codeql.yml, dependency-review.yml, scorecard.yml for continuous security.
  • Build provenance and SBOM attestations are pushed to GitHub's Attestations API via actions/attest@v4 (subject-checksums form for provenance, SPDX predicate form for SBOM). Only the Lambda zip ships as a release asset — no Cosign, checksum, or SBOM files are attached.
  • Extends .github/dependabot.yml to cover gomod; existing github-actions + npm(docs) blocks unchanged.
  • README gains a Verification section with gh attestation verify commands (online, SBOM-specific, and offline/air-gapped forms). New docs/docs/explanation/release-architecture.md documents the pipeline design and the rationale for the attestation-only verification channel.

Design rationale

Aligns with the refreshed publishing skill: separation of versioning from publication, trusted reusable builder (SLSA L3 signer identity distinct from caller), attestations-as-API-records rather than release-asset bundles. The tag entrypoint preflights release-please's draft release via scripts/wait-for-draft-release.sh and only un-drafts via scripts/publish-draft-release.sh after the reusable build succeeds, so any failure leaves the release invisible.

No Cosign step — GitHub Artifact Attestations is already a Sigstore keyless flow under the hood; adding cosign sign-blob would duplicate the signature and add a second key-management surface.

Test plan

  • actionlint .github/workflows/*.yml passes
  • python3 yaml.safe_load parses every new workflow and dependabot config
  • bash -n syntax-checks on both scripts
  • moon run broker:check passes (unit + build)
  • moon run docs:build passes with the new explanation doc
  • Tag workflow's real acceptance test: after this PR merges, merging release-please PR chore(master): release 1.0.0 #9 produces v1.0.0; release.yml must complete and gh attestation verify must succeed against the published zip. Fix forward via v1.0.1 if any step fails (tags are immutable).

🤖 Generated with Claude Code

Stands up Phase 4 publishing: a four-part workflow (tag entrypoint +
reusable trusted builder + draft finalizer + continuous security) that
turns a release-please tag into a GitHub Release carrying just the
Lambda zip. Build provenance and SBOM are persisted to GitHub's
Attestations API via actions/attest; no Cosign, checksum, or SBOM
material is attached to the release.

Adds codeql.yml, dependency-review.yml, scorecard.yml, and extends
dependabot.yml to cover gomod. Documents verification in README and the
pipeline architecture under docs/.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

The `dependency-review` action fails on this repo with "Dependency review
is not supported on this repository" despite dependency graph being on
at the repo level. Looks like an org/feature-level gate we need to
investigate separately; removing to unblock the publish pipeline.

CodeQL + Scorecard still ship in this PR, so Phase 4's continuous
security baseline is still covered.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@jmgilman
jmgilman merged commit c51372f into master Apr 23, 2026
4 checks passed
@jmgilman
jmgilman deleted the session-007/phase-4-publishing branch April 23, 2026 03:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants