]> git.ipfire.org Git - thirdparty/pdns.git/commitdiff
Post provenance data to the public transparency log for private repos 14504/head
authorRemi Gacogne <remi.gacogne@powerdns.com>
Thu, 18 Jul 2024 11:56:45 +0000 (13:56 +0200)
committerRemi Gacogne <remi.gacogne@powerdns.com>
Thu, 18 Jul 2024 11:56:45 +0000 (13:56 +0200)
We are OK with making private repository names discoverable via the
public Rekor API server.

.github/workflows/build-packages.yml

index d6b69a16c41b48675e1a0eb26d092d85c72d3710..6ece22db86901a1793e2e668b278bc21a1eddbf4 100644 (file)
@@ -195,6 +195,7 @@ jobs:
       base64-subjects: "${{ needs.build.outputs[format('pkghashes-{0}-{1}', matrix.os, matrix.architecture)] }}"
       upload-assets: false
       provenance-name: "${{ inputs.product }}-${{ needs.build.outputs.version }}-${{ matrix.os }}-${{ matrix.architecture }}.intoto.jsonl"
+      private-repository: true
 
   provenance-src:
     needs: build
@@ -208,6 +209,7 @@ jobs:
       base64-subjects: "${{ needs.build.outputs.srchashes }}"
       upload-assets: false
       provenance-name: "${{ inputs.product }}-${{ needs.build.outputs.version }}-src.intoto.jsonl"
+      private-repository: true
 
   upload-provenance:
     needs: [prepare, build, provenance-src, provenance-pkgs]