Skip to content

[Hardening] Supply-chain: pin Actions to SHA + SBOM/provenance #117

Description

@fabriziosalmi

Reduce CI and release supply-chain risk: pin all GitHub Actions to full commit SHAs (not floating tags), and add build provenance/SLSA attestation plus an SBOM to releases. Roadmap theme for the v0.9.x line.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions