Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(security): Add provenance #671

Merged
merged 1 commit into from Apr 3, 2024
Merged

Conversation

AaronDewes
Copy link
Contributor

This help increase trust in the builds on NPM by showing they were indeed generated from the same source code as this repository contains.

Copy link
Contributor

github-actions bot commented Apr 3, 2024

👋 Hi! Thank you for this contribution! Just to let you know, our GitHub SDK team does a round of issue and PR reviews twice a week, every Monday and Friday! We have a process in place for prioritizing and responding to your input. Because you are a part of this community please feel free to comment, add to, or pick up any issues/PRs that are labled with Status: Up for grabs. You & others like you are the reason all of this works! So thank you & happy coding! 🚀

@wolfy1339 wolfy1339 added the Type: Maintenance Any dependency, housekeeping, and clean up Issue or PR label Apr 3, 2024
@wolfy1339
Copy link
Member

I think it would be wise to backport this for 5.x releases as well, as that is what is used be Probot

@wolfy1339 wolfy1339 merged commit 1c2bd25 into octokit:main Apr 3, 2024
9 checks passed
Copy link
Contributor

github-actions bot commented Apr 3, 2024

🎉 This PR is included in version 6.1.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@AaronDewes
Copy link
Contributor Author

I think it would be wise to backport this for 5.x releases as well, as that is what is used be Probot

I don't think that's necessary, provenance is not that important, and hopefully, we'll be able to update Probot soon.

wolfy1339 pushed a commit that referenced this pull request Apr 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
released Type: Maintenance Any dependency, housekeeping, and clean up Issue or PR
Projects
Archived in project
Development

Successfully merging this pull request may close these issues.

None yet

2 participants