Skip to content

[upstream] track slsa-github-generator ecosystem-builder pre-build hook #369

Description

@trilamsr

PR #358 ships SLSA L3 via generator_generic_slsa3.yml (the generic-not-Go variant) because builder_go_slsa3.yml has no pre-build hook for ecosystem builders (OCB regenerates ./_build/ per-arch; no top-level Go module).

Upstream tracker: slsa-framework/slsa-github-generator#3033 (claimed in PR #358 body — VERIFY this issue is real / file new if phantom).

Action when upstream lands: migrate .github/workflows/release.yml from generic-generator to Go-builder for cleaner provenance attestation.

Tracked from: PR #358 deferral.

Metadata

Metadata

Assignees

No one assigned

    Labels

    external-clockBlocked on out-of-repo staterc1-prepv1.0-rc1 preparation tasks per docs/v1-rc1-operational-gaps.md

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions