Repository navigation
Tags: alberti42/Volume-Control
Tags
Attest build provenance for the release ZIP The release carried a Developer ID signature, Apple notarization and a Sparkle EdDSA signature. They show who signed the app and that it was not modified afterwards, but none ties the ZIP to a commit or to a CI run: a ZIP signed locally with the same certificate looks the same. Add actions/attest@v4 after notarization. It records a signed SLSA provenance statement, logged in Sigstore, that VolumeControl.zip (by its SHA-256) was built by this workflow from this commit and tag. The job gets the id-token, attestations and artifact-metadata permissions the action needs. publish-release.yml signs the ZIP for Sparkle without changing the file, so the attestation stays valid for the file users download. Verify with: gh attestation verify VolumeControl.zip --repo alberti42/Volume-Control
PreviousNext