From bc4c4792695e2467f4f4d3866ecad57f60e924dd Mon Sep 17 00:00:00 2001 From: Raphanus Lo Date: Mon, 13 Jan 2025 16:42:16 +0800 Subject: [PATCH] feat(ci): add provenance for SLSA3 Signed-off-by: Raphanus Lo --- .github/workflows/build.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index e19a53e4..1434f041 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -97,6 +97,7 @@ jobs: tags: longhornio/longhorn-cli:${{ env.branch }}-head file: package/Dockerfile sbom: true + provenance: mode=max - name: docker-publish-with-tag if: ${{ startsWith(github.ref, 'refs/tags/') }} @@ -107,4 +108,5 @@ jobs: platforms: linux/amd64,linux/arm64 tags: longhornio/longhorn-cli:${{ github.ref_name }} file: package/Dockerfile - sbom: true \ No newline at end of file + sbom: true + provenance: mode=max