ci(release): attach the signed tarball to each release and set up Node where Scorecard sees it - #622
Conversation
…e where Scorecard sees it OpenSSF Scorecard left Packaging and Signed-Releases without a score: - Packaging only recognizes an npm publishing job by an actions/setup-node step with the npm registry URL next to the publish command, and the job set Node up inside the composite action. The job now runs setup-node itself, with the registry URL npm's trusted publishing guide uses. - Signed-Releases needs signed assets on the release, and releases are immutable here, so nothing could be attached after release-please published them. release-please now creates a draft (with the tag forced, so the next run still finds it); a release-assets job packs the package, attests its build provenance, attaches the tarball, the Sigstore bundle, the DSSE envelope as .intoto.jsonl and the SBOM, and publishes the release. It replaces the job that kept the SBOM as a run artifact.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
commit: |
Tree-shaking report✅ No bundle size impact. All 200 exports are the same size as on the base branch (full import 1387.9 KB, gzip 293.3 KB). All exports (200)
How this is measuredEvery export is imported alone into an esbuild consumer bundle (minified, tree-shaken) built from the head and from the base of this pull request; the sizes are the resulting bundles, gzip is their gzipped size. 🔴 marks a regression: a pre-existing export that grew more than 20% and more than 256 B, or the bundle importing every pre-existing export growing more than 5%. 🟡 is growth under the threshold, 🟢 a decrease, ⚪ no change, 🆕 an export that does not exist on the base (never a regression), 🗑️ an export that was removed. An intentional increase is accepted with the |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #622 +/- ##
=========================================
Coverage 100.00% 100.00%
=========================================
Files 263 263
Lines 2656 2656
Branches 754 754
=========================================
Hits 2656 2656
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
OpenSSF Scorecard leaves two checks without a score (
-1):actions/setup-nodestep withregistry-url: https://registry.npmjs.orgin the same job as the publish command.publish-npmset Node up inside the composite action, which Scorecard does not read. The job now runssetup-nodeitself (the setup npm's trusted publishing guide shows; OIDC still takes precedence over the placeholder token), and the composite action gains asetup-node: "false"input so Node is not installed twice.draft+force-tag-creation, so the tag exists at once and the next run finds the release). A newrelease-assetsjob, replacingsbom, packs the package, attests its build provenance withactions/attest-build-provenance, attaches the tarball, the Sigstore bundle (.sigstore.json), the same DSSE envelope as.intoto.jsonland the CycloneDX SBOM, then publishes the release as latest.CONTRIBUTING and SECURITY describe the new assets and how to check a tarball with
gh attestation verify.Checked locally:
actionlintclean, zizmor with no new finding, and Scorecard built from source (--local) reports Packaging 10/10, Pinned-Dependencies 10, Token-Permissions 10, Dangerous-Workflow 10. Signed-Releases can only be measured after the next release.