logoalt Hacker News

nailer • today at 9:11 PM • 1 reply • view on HN

> Every release is built from its tag by GitHub Actions and carries a build provenance attestation.

Huh cool. They're doing curl | bash properly.


Replies

woodruffw • today at 9:25 PM

That doesn't seem to do much in the `curl | bash` setting, given that you're not verifying the attestation in that case. You still need to download it separately and run `gh attestation verify` first.

(Note that the attestation does not appear to cover the shell script either, it only covers the script's final payload. The shell script is also referenced via `main`, so it's mutable even if the underlying payload is properly attested. That's not good!)