🔥 3-day streak
GitHub Actions (GH-200)52 / 142
Question 52 of 142

Your team ships a container image built in a GitHub Actions workflow, and your security team now requires cryptographically verifiable provenance (SLSA build metadata) tied to the build. You want to generate this attestation directly in the workflow using GitHub's native tooling, with the least additional infrastructure. Which combination of workflow configuration correctly produces a signed provenance attestation for the built artifact?

Reviewed for accuracy · Report an issueNext question