mirror of
https://github.com/maxgoedjen/secretive.git
synced 2025-08-26 15:10:57 +00:00
Add attestation info to readme (#620)
* Update README.md * Enhance README with attestation visibility details * Update README to clarify build process and attestations
This commit is contained in:
parent
2355d3f989
commit
bd096c3012
@ -49,7 +49,7 @@ There's a [FAQ here](FAQ.md).
|
||||
|
||||
### Auditable Build Process
|
||||
|
||||
Builds are produced by GitHub Actions with an auditable build and release generation process. Each build has a "Document SHAs" step, which will output SHA checksums for the build produced by the GitHub Action, so you can verify that the source code for a given build corresponds to any given release.
|
||||
Builds are produced by GitHub Actions with an auditable build and release generation process. Starting with Secretive 3.0, builds are attested using [GitHub Artifact Attestation](https://docs.github.com/en/actions/concepts/security/artifact-attestations). Attestations are viewable in the build log for a build, and also on the [main attestation page](https://github.com/maxgoedjen/secretive/attestations).
|
||||
|
||||
### A Note Around Code Signing and Keychains
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user