From ddf0a7ca97566e48d15522d0fc31b010c911c3a4 Mon Sep 17 00:00:00 2001 From: userdocs <16525024+userdocs@users.noreply.github.com> Date: Thu, 3 Oct 2024 02:32:40 +0100 Subject: [PATCH] docs --- docs/astro.config.mjs | 4 ++++ .../src/content/docs/artifact-attestations.mdx | 18 ++++++++++++++++++ 2 files changed, 22 insertions(+) create mode 100644 docs/src/content/docs/artifact-attestations.mdx diff --git a/docs/astro.config.mjs b/docs/astro.config.mjs index 4b46d0e9..e95bb967 100644 --- a/docs/astro.config.mjs +++ b/docs/astro.config.mjs @@ -103,6 +103,10 @@ export default defineConfig({ label: "Systemd", link: "/systemd", }, + { + label: "Github - Artifact Attestations", + link: "/artifact-attestations", + }, { label: "Github actions", link: "/github-actions", diff --git a/docs/src/content/docs/artifact-attestations.mdx b/docs/src/content/docs/artifact-attestations.mdx new file mode 100644 index 00000000..fb06618e --- /dev/null +++ b/docs/src/content/docs/artifact-attestations.mdx @@ -0,0 +1,18 @@ +--- +title: artifact attestations +description: artifact attestations +--- + +import { Advanced, Charts, Details, Modal, Steps, Tabs, TabItem, Card, CardGrid, LinkCard, Aside, Icon } from "/src/components/global.jsx" + +From releases after the 03/10/2024 you can use the `artifact_attestations` to verify the provenance of the build. + +https://docs.github.com/en/actions/security-for-github-actions/using-artifact-attestations/using-artifact-attestations-to-establish-provenance-for-builds + +Using `gh` cli you can use this command to verify the provenance of the build: + +For example, using the `x86_64-qbittorrent-nox` build: + +```bash +gh attestation verify x86_64-qbittorrent-nox -o userdocs +```