Skip to content

chore(ci): cargo-auditable + SLSA L2 + osv-scanner#179

Open
forkwright wants to merge 1 commit into
mainfrom
chore/supply-mm-508-507-akroasis
Open

chore(ci): cargo-auditable + SLSA L2 + osv-scanner#179
forkwright wants to merge 1 commit into
mainfrom
chore/supply-mm-508-507-akroasis

Conversation

@forkwright

Copy link
Copy Markdown
Owner

Closes kanon#507
Closes kanon#508

- Add attestations: write, id-token: write permissions to release.yml
- Install cargo-auditable and switch to cargo auditable build / cross auditable build
- Add per-binary CycloneDX + SPDX SBOM generation via anchore/sbom-action
- Add SLSA L2 binary provenance + SBOM attestation via actions/attest-build-provenance and actions/attest-sbom
- Upload .intoto.jsonl attestation bundles as release assets
- Create Cross.toml with cargo-auditable pre-build for aarch64 cross-compilation
- Add osv-scanner reusable workflow job to security.yml
- Create osv-scanner.toml waiver list (empty, matching current advisory state)

Closes kanon#507
Closes kanon#508

Gate-Passed: kanon-0.1.5 full
@forkwright forkwright force-pushed the chore/supply-mm-508-507-akroasis branch from 71dd72f to 156d08f Compare June 25, 2026 13:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant