Skip to content

ci: verify immutable release receipts without admin permissions - #4

Merged
wakemeup0 merged 1 commit into
mainfrom
ci/verify-release-receipt
Sep 11, 2026
Merged

wakemeup0 merged 1 commit into
mainfrom
ci/verify-release-receipt

Conversation

@wakemeup0

Copy link
Copy Markdown
Contributor

Fix

The first v0.2.0 publication reached signing, attestation and draft upload, then the job token received HTTP 403 from the repository-administration immutable-settings API. Query the published release's immutable state through the release API instead, and verify its signed GitHub release receipt. Keep all source, signature, attestation and individual asset checks.

Verification

  • actionlint passed.
  • All seven signatures, fourteen attestations and fourteen immutable asset digests were verified for the existing v0.2.0 assets before/after operator publication.
  • The published release API returns immutable=true; gh release verify v0.2.0 succeeds.
  • No assets were rebuilt or replaced during recovery.

@wakemeup0
wakemeup0 merged commit 983abb4 into main Sep 11, 2026
7 checks passed
@wakemeup0
wakemeup0 deleted the ci/verify-release-receipt branch September 11, 2026 21:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant