Skip to content

fix(release): allow Sigstore public-good endpoints for attestation - #135

Merged
ryanlewis merged 1 commit into
mainfrom
fix-egress-sigstore
Aug 25, 2026
Merged

fix(release): allow Sigstore public-good endpoints for attestation#135
ryanlewis merged 1 commit into
mainfrom
fix-egress-sigstore

Conversation

@ryanlewis

Copy link
Copy Markdown
Owner

Fourth v0.5.3 run: goreleaser published successfully (signed + notarized), but actions/attest-build-provenance failed — public repos attest via the Sigstore public-good instance (fulcio.sigstore.dev, blocked per the harden-runner report), not fulcio.githubapp.com. Adds fulcio, rekor, and the TUF CDN.

attest-build-provenance on a public repo uses fulcio.sigstore.dev (plus
rekor and the TUF CDN), not the fulcio.githubapp.com instance that
serves private repos; the fourth v0.5.3 run published fine but failed
the attestation step on the blocked connection.
@ryanlewis
ryanlewis enabled auto-merge (squash) August 25, 2026 02:19
@ryanlewis
ryanlewis merged commit 67cde68 into main Aug 25, 2026
7 checks passed
@ryanlewis
ryanlewis deleted the fix-egress-sigstore branch August 25, 2026 02:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant