🔥 3-day streak
GitHub Actions (GH-200)2 / 142
Question 2 of 142
Your organization builds a container image in CI and generates a build provenance attestation with the actions/attest-build-provenance action. Before a production deployment job pulls and runs the image, the security team requires the deployment runner to cryptographically confirm that the image was built by your organization's repository and not tampered with. Which command should the deployment job run to enforce this?
Reviewed for accuracy · Report an issueNext question