ci: add provenance action to check for downgrades in provenance
This commit is contained in:
parent
1fd9292cdc
commit
2d37e49970
1 changed files with 23 additions and 0 deletions
23
.github/workflows/provenance.yml
vendored
Normal file
23
.github/workflows/provenance.yml
vendored
Normal file
|
|
@ -0,0 +1,23 @@
|
||||||
|
|
||||||
|
name: ci
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- main
|
||||||
|
pull_request:
|
||||||
|
branches:
|
||||||
|
- main
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
jobs:
|
||||||
|
check-provenance:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
- name: Check provenance downgrades
|
||||||
|
uses: danielroe/provenance-action@a5a718233ca12eff67651fcf29a030bbbd5b3ca1 # v0.1.0
|
||||||
|
with:
|
||||||
|
fail-on-provenance-change: true
|
||||||
Loading…
Reference in a new issue