Description
Add SLSA provenance generation to the release workflow using GitHub Attestations.
Why
Provides cryptographic proof of how and when artifacts were built, improving supply-chain security.
Status
Deferred — single-maintainer project with low supply-chain risk. Revisit when:
- The project has external contributors
- WinInspect is being distributed as a binary
- A conformance/compliance requirement emerges
References
Description
Add SLSA provenance generation to the release workflow using GitHub Attestations.
Why
Provides cryptographic proof of how and when artifacts were built, improving supply-chain security.
Status
Deferred — single-maintainer project with low supply-chain risk. Revisit when:
References