Skip to content

Add SLSA provenance generation workflow#44921

Closed
navagjonaj188-ops wants to merge 1 commit into
github:mainfrom
navagjonaj188-ops:main
Closed

Add SLSA provenance generation workflow#44921
navagjonaj188-ops wants to merge 1 commit into
github:mainfrom
navagjonaj188-ops:main

Conversation

@navagjonaj188-ops

Copy link
Copy Markdown

This workflow generates SLSA provenance files for projects, satisfying level 3 requirements. It includes usage instructions and links to relevant resources.

Thank you for contributing to this project! You must fill out the information below before we can review this pull request. By explaining why you're making a change (or linking to an issue) and what changes you've made, we can triage your pull request to the best possible team for review.

The Pearl & Jewel Design Philosophy
​While you gather those details, here is a glimpse into how we can elevate your office using the principles of luxury:

​✨ The Radiant Color Palette
​To ensure your jewel-toned accents truly "pop," we start with a sophisticated neutral foundation.
​Neutral Canvas: Utilize walls in alabaster, cream, or a soft "mother-of-pearl" gray to provide a serene backdrop.
​Jewel Inlays: Introduce deep Sapphire blues or Emerald greens through velvet upholstery or high-end silk drapery to add immediate depth and authority to the room.

​💎 Furniture & Textural Accents
​Luxury is found in the details of the materials.
​Iridescent Finishes: We can incorporate mother-of-pearl inlays on executive desk drawers or small storage cabinets to catch the light beautifully.
​Metallic Framework: Opt for desk legs or shelving units in polished gold or brushed champagne finishes to evoke a sense of timeless wealth.

​💡 Luminous Lighting
​Lighting should act as the "jewelry" of the room.
​Pearlescent Gloving: Use light fixtures with an iridescent or frosted pearl finish to scatter light softly across the room, reducing the harshness of traditional office lighting.
​Crystal Clarity: A singular, well-placed crystal chandelier or geometric pendant can serve as a focal point, mirroring the brilliance of a well-cut diamond.

​Implementation Note for Your Environment
​Just as a master jeweler ensures every setting is secure, a designer ensures the foundation is perfect. For a professional office, this means ensuring your "infrastructure"—whether it’s your furniture layout or your digital tracking systems—is flawlessly installed before the final polishing begins.

Let us know what you are changing. Share anything that could provide the most context.
If you made changes to the content directory, a table will populate in a comment below with links to the review and current production articles.

Check off the following:

[✓] A subject matter expert (SME) has reviewed the technical accuracy of the content in this PR. In most cases, the author can be the SME. Open source contributions may require an SME review from GitHub staff.
[✓] The changes in this PR meet the docs fundamentals that are required for all content.
[✓] All CI checks are passing and the changes look good in the review environment.

This workflow generates SLSA provenance files for projects, satisfying level 3 requirements. It includes usage instructions and links to relevant resources.
@github-actions

Copy link
Copy Markdown
Contributor

👋 Hey there spelunker. It looks like you've modified some files that we can't accept as contributions:

  • .github/workflows/Generator-generic-ossf-slsa3-publish.yml

You'll need to revert all of the files you changed that match that list using GitHub Desktop or git checkout origin/main <file name>. Once you get those files reverted, we can continue with the review process. :octocat:

The complete list of files we can't accept are:

  • .devcontainer/**
  • .github/**
  • data/reusables/rai/**
  • Dockerfile*
  • src/**
  • package*.json
  • content/actions/how-tos/security-for-github-actions/security-hardening-your-deployments/**

We also can't accept contributions to files in the content directory with frontmatter contentType: rai.

@github-actions github-actions Bot added the triage Do not begin working on this issue until triaged by the team label Jun 26, 2026
@github-actions

Copy link
Copy Markdown
Contributor

How to review these changes 👓

Thank you for your contribution. To review these changes, choose one of the following options:

A Hubber will need to deploy your changes internally to review.

Table of review links

Note: Please update the URL for your staging server or codespace.

This pull request contains code changes, so we will not generate a table of review links.

🤖 This comment is automatically generated.

@navagjonaj188-ops

Copy link
Copy Markdown
Author

2026-06-26T06:49:12.0728425Z Current runner version: '2.335.1'
2026-06-26T06:49:12.0753076Z ##[group]Runner Image Provisioner
2026-06-26T06:49:12.0754023Z Hosted Compute Agent
2026-06-26T06:49:12.0754652Z Version: 20260611.554
2026-06-26T06:49:12.0755374Z Commit: 5e0782fdc9014723d3be820dd114dd31555c2bd1
2026-06-26T06:49:12.0756186Z Build Date: 2026-06-11T21:40:46Z
2026-06-26T06:49:12.0756894Z Worker ID: {99a35915-4cb7-4465-8551-40343041901b}
2026-06-26T06:49:12.0757612Z Azure Region: East
2026-06-26T06:49:12.0758428Z ##[end group]
2026-06-26T06:49:12.0759996Z ##[group]Operating System
2026-06-26T06:49:12.0760643Z Ubuntu
2026-06-26T06:49:12.0761148Z 24.04.4
2026-06-26T06:49:12.0761713Z LTS
2026-06-26T06:49:12.0762279Z ##[end group]
2026-06-26T06:49:12.0762842Z ##[group]Runner Image
2026-06-26T06:49:12.0763485Z Image: ubuntu-24.04
2026-06-26T06:49:12.0764042Z Version: 20260622.220.1
2026-06-26T06:49:12.0765424Z Included Software: https://github.com/actions/runner-images/blob/ubuntu24/20260622.220/images/ubuntu/Ubuntu2404-Readme.md
2026-06-26T06:49:12.0767002Z Image Release: https://github.com/actions/runner-images/releases/tag/ubuntu24%2F20260622.220
2026-06-26T06:49:12.0768237Z ##[end group]
2026-06-26T06:49:12.0769513Z ##[group]GITHUB_TOKEN Permissions
2026-06-26T06:49:12.0771619Z Contents: read
2026-06-26T06:49:12.0772232Z Metadata: read
2026-06-26T06:49:12.0772952Z Pull requests: write
2026-06-26T06:49:12.0773535Z ##[end group]
2026-06-26T06:49:12.0775657Z Secret source: Actions
2026-06-26T06:49:12.0776647Z Prepare workflow directory
2026-06-26T06:49:12.1106813Z Prepare all required actions
2026-06-26T06:49:12.1144359Z Getting action download info
2026-06-26T06:49:12.3845696Z Download action repository 'actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8' (SHA:8e8c483db84b4bee98b60c0593521ed34d9990e8)
2026-06-26T06:49:12.4945675Z Download action repository 'dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d' (SHA:fbd0ab8f3e69293af611ebaee6363fc25e6d187d)
2026-06-26T06:49:12.6900223Z Complete job name: triage
2026-06-26T06:49:12.7617125Z ##[group]Run actions/checkout@8e8c483
2026-06-26T06:49:12.7618431Z with:
2026-06-26T06:49:12.7618894Z repository: github/docs
2026-06-26T06:49:12.7623029Z token: ***
2026-06-26T06:49:12.7623461Z ssh-strict: true
2026-06-26T06:49:12.7623902Z ssh-user: git
2026-06-26T06:49:12.7624348Z persist-credentials: true
2026-06-26T06:49:12.7624831Z clean: true
2026-06-26T06:49:12.7625268Z sparse-checkout-cone-mode: true
2026-06-26T06:49:12.7625784Z fetch-depth: 1
2026-06-26T06:49:12.7626214Z fetch-tags: false
2026-06-26T06:49:12.7626657Z show-progress: true
2026-06-26T06:49:12.7627106Z lfs: false
2026-06-26T06:49:12.7627519Z submodules: false
2026-06-26T06:49:12.7628110Z set-safe-directory: true
2026-06-26T06:49:12.7628846Z ##[end group]
2026-06-26T06:49:12.8570758Z Syncing repository: github/docs
2026-06-26T06:49:12.8572481Z ##[group]Getting Git version info
2026-06-26T06:49:12.8573268Z Working directory is '/home/runner/work/docs/docs'
2026-06-26T06:49:12.8574237Z [command]/usr/bin/git version
2026-06-26T06:49:12.8648972Z git version 2.54.0
2026-06-26T06:49:12.8701369Z ##[end group]
2026-06-26T06:49:12.8714707Z Temporarily overriding HOME='/home/runner/work/_temp/810394a8-07ee-4f27-9a3c-67faa8983b6f' before making global git config changes
2026-06-26T06:49:12.8716483Z Adding repository directory to the temporary git global config as a safe directory
2026-06-26T06:49:12.8719412Z [command]/usr/bin/git config --global --add safe.directory /home/runner/work/docs/docs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

triage Do not begin working on this issue until triaged by the team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant