Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

More documentation not only to generate the attestation for a SBOM but also to know how to verify it #138

Open
0GiS0 opened this issue Dec 12, 2024 · 1 comment

Comments

@0GiS0
Copy link

0GiS0 commented Dec 12, 2024

Hi there 👋🏻

It would be great if there was some more documentation not only to generate the attestation for a SBOM but also to know how to verify what this action generates. Because if you are not an expert in this area it is difficult to know what to do once you launch this action.

I have been able to invoke this action for an image and for a binary but after that I don't know what to do with it 😖

Thank you so much

@bdehamer
Copy link
Collaborator

No matter what type of attestation you are generating (build provenance, SBOM, etc) you can use the gh attestation verify command to do the verification. More details in the docs: https://docs.github.com/en/actions/security-for-github-actions/using-artifact-attestations/using-artifact-attestations-to-establish-provenance-for-builds#verifying-artifact-attestations-with-the-github-cli

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants