ci: add provenance action to check for downgrades in provenance

This commit is contained in:
Daniel Roe 2025-09-16 22:13:17 +01:00
parent 1fd9292cdc
commit 2d37e49970
No known key found for this signature in database
GPG key ID: 47C4EE3D46A3A27C

23
.github/workflows/provenance.yml vendored Normal file
View file

@ -0,0 +1,23 @@
name: ci
on:
push:
branches:
- main
pull_request:
branches:
- main
permissions:
contents: read
jobs:
check-provenance:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Check provenance downgrades
uses: danielroe/provenance-action@a5a718233ca12eff67651fcf29a030bbbd5b3ca1 # v0.1.0
with:
fail-on-provenance-change: true