Skip to content

Security: Release artifact provenance for c4z (and HACS) — SLSA attestation + checksums #46

Description

@caidurbin

What to build

Give the non-PyPI release artifacts the provenance the PyPI lane gets from PEP 740. There's no index-side attestation story for .c4z or the HACS GitHub release, so attach SLSA build provenance (actions/attest-build-provenance) and publish a checksum for the .c4z artifact, letting consumers verify it was built by this repo's workflow. Evaluate doing the same for the HACS release.

Acceptance criteria

  • .c4z release publishes a SLSA build-provenance attestation and a checksum
  • Verification steps documented for consumers
  • Decision recorded on whether/how to apply the same to the HACS release

Blocked by

None - can start immediately

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestready-for-agentFully specified, ready for an AFK agent

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions