Skip to content

Conversation

xiangyisss
Copy link
Collaborator

@xiangyisss xiangyisss commented Jul 25, 2025

This PR has packaging + attestations but no traditional signing. This is the intended design - GitHub Attestations replace GPG signing with a more modern, keyless approach using Sigstore infrastructure.

✅ Packaging - helm package charts/exivity -d .cr-release-packages
✅ Attestations - actions/attest-build-provenance@v1 with subject-path
❌ Traditional Signing - No GPG signing (intentionally removed)

Note: This workflow does NOT include traditional GPG signing (helm package --sign).
https://docs.github.com/en/actions/concepts/security/artifact-attestations#how-github-generates-artifact-attestations

CLOSE-EXVT-5947

@xiangyisss xiangyisss requested a review from linuxluigi July 25, 2025 12:05
@xiangyisss xiangyisss changed the title feat: enhance chart release workflow with packaging and attestation s… feat: Implement GitHub Artifact Attestations for Helm Chart Signing Jul 25, 2025
@xiangyisss xiangyisss self-assigned this Jul 25, 2025
@xiangyisss xiangyisss force-pushed the feat/github-artifact-attestations branch from da5584e to 4ed1ad8 Compare July 25, 2025 13:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant