Visitar URL original
Support uploading attestations to Github's attestations page · Issue #183 · docker/github-builder · GitHub
Skip to content

Support uploading attestations to Github's attestations page #183

Description

@SteveHawk

Description

It seems like attestations aren't uploaded to Github's attestations page. It would be nice for github-builder to support it.

(#100 also mentioned this feature)

Activity

  1. crazy-max commented on Apr 27, 2026

    @crazy-max
    Member

    I checked with GitHub about this. The current state is that uploading the BuildKit-generated provenance bundles we publish today is not supported by the GitHub attestations API in the way this issue needs.

    The important details are:

    • The create an attestation endpoint is not currently a generic upload path for arbitrary SLSA provenance bundles that should show up like GitHub-generated artifact attestations.
    • When the predicate type is https://slsa.dev/provenance/v1, GitHub applies special provenance validation. That validation currently expects a specific shape, including GitHub Actions provenance with buildType set to https://actions.github.io/buildtypes/workflow/v1.
    • The BuildKit provenance we generate is valid SLSA provenance, but it doesn't match GitHub's current stricter parser/validator. The concrete mismatch called out was BuildKit extension fields such as buildkit_completeness and buildkit_metadata. Those extension fields are allowed by the SLSA v1.1 spec, so this is partly a GitHub-side validation limitation.
    • Even if GitHub relaxes the parser to better match the SLSA spec, accepting provenance with a non-GitHub-Actions buildType is a larger product/system question on their side.

    So for github-builder, this is currently blocked upstream. We should not try to paper over it locally by rewriting the provenance or changing the predicate type, because that would either produce misleading provenance or stop being the SLSA provenance we actually want to publish.

    For now the practical path is to keep publishing the sigstore bundles as release assets and revisit this when GitHub supports uploading externally generated SLSA provenance, especially provenance generated by BuildKit/cosign rather than actions/attest-build-provenance.

    cc @colinhemmings @tonistiigi

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions