Skip to content

Commit fae64fa

Browse files
committed
Add SLSA level 3 builder
1 parent e210bbe commit fae64fa

4 files changed

Lines changed: 60 additions & 143 deletions

File tree

.github/workflows/publish.yml

Lines changed: 51 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -11,11 +11,14 @@ permissions:
1111
id-token: "write"
1212

1313
jobs:
14-
publish:
15-
name: "Publish"
14+
15+
build:
16+
name: "Build"
1617
runs-on: "ubuntu-latest"
1718
environment:
1819
name: "publish"
20+
outputs:
21+
hashes: ${{ steps.hash.outputs.hashes }}
1922

2023
steps:
2124
- name: "Checkout repository"
@@ -31,41 +34,63 @@ jobs:
3134
python -m pip install -r requirements/publish.txt
3235
3336
- name: "Build dists"
37+
# Uses 'SOURCE_DATE_EPOCH' for build reproducibility.
3438
run: |
3539
SOURCE_DATE_EPOCH=$(git log -1 --pretty=%ct) \
3640
python -m build
3741
38-
- name: "Sign dists"
42+
# Create hashes of all the built distributables.
43+
# This is the input for "subject" of the SLSA builder.
44+
- name: "Generate hashes"
45+
id: hash
3946
run: |
40-
mkdir -p sigstore-artifacts/
41-
42-
for dist in dist/*; do
43-
dist_name=$(basename "${dist}")
47+
cd dist && echo "::set-output name=hashes::$(sha256sum * | base64 -w0)"
4448
45-
# Sign the dists and then verify them immediately
46-
# with the generated artifacts.
47-
python -m \
48-
sigstore sign "${dist}" \
49-
--output-signature sigstore-artifacts/"${dist_name}.sig" \
50-
--output-certificate sigstore-artifacts/"${dist_name}.crt"
49+
- name: "Upload dists"
50+
uses: "actions/upload-artifact@3cea5372237819ed00197afe530f5a7ea3e805c8"
51+
with:
52+
name: "dist"
53+
path: "dist/"
54+
if-no-files-found: error
55+
retention-days: 5
5156

52-
python -m \
53-
sigstore verify "${dist}" \
54-
--cert "sigstore-artifacts/${dist_name}.crt" \
55-
--signature "sigstore-artifacts/${dist_name}.sig" \
56-
--cert-oidc-issuer https://token.actions.githubusercontent.com
57+
provenance:
58+
needs: ["build"]
59+
uses: "slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v1.2.0"
60+
permissions:
61+
actions: read
62+
id-token: write
63+
# contents: write is only needed to upload the
64+
# attestation to the GitHub release.
65+
contents: write
66+
with:
67+
base64-subjects: "${{ needs.build.outputs.hashes }}"
68+
attestation-name: "artifacts.intoto.jsonl"
69+
upload-assets: true
5770

58-
done
71+
publish:
72+
name: "Publish"
73+
if: startsWith(github.ref, 'refs/tags/')
74+
needs: ["build", "provenance"]
75+
runs-on: "ubuntu-latest"
5976

60-
- name: "Upload artifacts"
61-
uses: "actions/upload-artifact@3cea5372237819ed00197afe530f5a7ea3e805c8"
77+
# Now that we've built and attested to the distributables
78+
# provenance we can upload them to PyPI and add to the GitHub release.
79+
steps:
80+
- name: "Download dists"
81+
uses: "actions/download-artifact@fb598a63ae348fa914e94cd0ff38f362e927b741"
6282
with:
63-
name: "sigstore-artifacts"
64-
path: "sigstore-artifacts/*"
65-
if-no-files-found: "error"
83+
name: "dist"
84+
path: "dist/"
6685

67-
- name: "Publish to PyPI"
68-
uses: "pypa/gh-action-pypi-publish@717ba43cfbb0387f6ce311b169a825772f54d295"
86+
- name: "Publish dists to PyPI"
87+
uses: "pypa/gh-action-pypi-publish@37f50c210e3d2f9450da2cd423303d6a14a6e29f"
6988
with:
7089
user: __token__
7190
password: ${{ secrets.PYPI_TOKEN }}
91+
92+
- name: "Upload dists to GitHub Release"
93+
env:
94+
GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}"
95+
run: |
96+
gh release upload ${{ github.ref_name }} dist/* --repo ${{ github.repository }}

LICENSE

Lines changed: 4 additions & 114 deletions
Original file line numberDiff line numberDiff line change
@@ -1,117 +1,7 @@
1-
CC0 1.0 Universal
1+
This is free and unencumbered software released into the public domain.
22

3-
Statement of Purpose
3+
Anyone is free to copy, modify, publish, use, compile, sell, or distribute this software, either in source code form or as a compiled binary, for any purpose, commercial or non-commercial, and by any means.
44

5-
The laws of most jurisdictions throughout the world automatically confer
6-
exclusive Copyright and Related Rights (defined below) upon the creator and
7-
subsequent owner(s) (each and all, an "owner") of an original work of
8-
authorship and/or a database (each, a "Work").
9-
10-
Certain owners wish to permanently relinquish those rights to a Work for the
11-
purpose of contributing to a commons of creative, cultural and scientific
12-
works ("Commons") that the public can reliably and without fear of later
13-
claims of infringement build upon, modify, incorporate in other works, reuse
14-
and redistribute as freely as possible in any form whatsoever and for any
15-
purposes, including without limitation commercial purposes. These owners may
16-
contribute to the Commons to promote the ideal of a free culture and the
17-
further production of creative, cultural and scientific works, or to gain
18-
reputation or greater distribution for their Work in part through the use and
19-
efforts of others.
20-
21-
For these and/or other purposes and motivations, and without any expectation
22-
of additional consideration or compensation, the person associating CC0 with a
23-
Work (the "Affirmer"), to the extent that he or she is an owner of Copyright
24-
and Related Rights in the Work, voluntarily elects to apply CC0 to the Work
25-
and publicly distribute the Work under its terms, with knowledge of his or her
26-
Copyright and Related Rights in the Work and the meaning and intended legal
27-
effect of CC0 on those rights.
28-
29-
1. Copyright and Related Rights. A Work made available under CC0 may be
30-
protected by copyright and related or neighboring rights ("Copyright and
31-
Related Rights"). Copyright and Related Rights include, but are not limited
32-
to, the following:
33-
34-
i. the right to reproduce, adapt, distribute, perform, display, communicate,
35-
and translate a Work;
36-
37-
ii. moral rights retained by the original author(s) and/or performer(s);
38-
39-
iii. publicity and privacy rights pertaining to a person's image or likeness
40-
depicted in a Work;
41-
42-
iv. rights protecting against unfair competition in regards to a Work,
43-
subject to the limitations in paragraph 4(a), below;
44-
45-
v. rights protecting the extraction, dissemination, use and reuse of data in
46-
a Work;
47-
48-
vi. database rights (such as those arising under Directive 96/9/EC of the
49-
European Parliament and of the Council of 11 March 1996 on the legal
50-
protection of databases, and under any national implementation thereof,
51-
including any amended or successor version of such directive); and
52-
53-
vii. other similar, equivalent or corresponding rights throughout the world
54-
based on applicable law or treaty, and any national implementations thereof.
55-
56-
2. Waiver. To the greatest extent permitted by, but not in contravention of,
57-
applicable law, Affirmer hereby overtly, fully, permanently, irrevocably and
58-
unconditionally waives, abandons, and surrenders all of Affirmer's Copyright
59-
and Related Rights and associated claims and causes of action, whether now
60-
known or unknown (including existing as well as future claims and causes of
61-
action), in the Work (i) in all territories worldwide, (ii) for the maximum
62-
duration provided by applicable law or treaty (including future time
63-
extensions), (iii) in any current or future medium and for any number of
64-
copies, and (iv) for any purpose whatsoever, including without limitation
65-
commercial, advertising or promotional purposes (the "Waiver"). Affirmer makes
66-
the Waiver for the benefit of each member of the public at large and to the
67-
detriment of Affirmer's heirs and successors, fully intending that such Waiver
68-
shall not be subject to revocation, rescission, cancellation, termination, or
69-
any other legal or equitable action to disrupt the quiet enjoyment of the Work
70-
by the public as contemplated by Affirmer's express Statement of Purpose.
71-
72-
3. Public License Fallback. Should any part of the Waiver for any reason be
73-
judged legally invalid or ineffective under applicable law, then the Waiver
74-
shall be preserved to the maximum extent permitted taking into account
75-
Affirmer's express Statement of Purpose. In addition, to the extent the Waiver
76-
is so judged Affirmer hereby grants to each affected person a royalty-free,
77-
non transferable, non sublicensable, non exclusive, irrevocable and
78-
unconditional license to exercise Affirmer's Copyright and Related Rights in
79-
the Work (i) in all territories worldwide, (ii) for the maximum duration
80-
provided by applicable law or treaty (including future time extensions), (iii)
81-
in any current or future medium and for any number of copies, and (iv) for any
82-
purpose whatsoever, including without limitation commercial, advertising or
83-
promotional purposes (the "License"). The License shall be deemed effective as
84-
of the date CC0 was applied by Affirmer to the Work. Should any part of the
85-
License for any reason be judged legally invalid or ineffective under
86-
applicable law, such partial invalidity or ineffectiveness shall not
87-
invalidate the remainder of the License, and in such case Affirmer hereby
88-
affirms that he or she will not (i) exercise any of his or her remaining
89-
Copyright and Related Rights in the Work or (ii) assert any associated claims
90-
and causes of action with respect to the Work, in either case contrary to
91-
Affirmer's express Statement of Purpose.
92-
93-
4. Limitations and Disclaimers.
94-
95-
a. No trademark or patent rights held by Affirmer are waived, abandoned,
96-
surrendered, licensed or otherwise affected by this document.
97-
98-
b. Affirmer offers the Work as-is and makes no representations or warranties
99-
of any kind concerning the Work, express, implied, statutory or otherwise,
100-
including without limitation warranties of title, merchantability, fitness
101-
for a particular purpose, non infringement, or the absence of latent or
102-
other defects, accuracy, or the present or absence of errors, whether or not
103-
discoverable, all to the greatest extent permissible under applicable law.
104-
105-
c. Affirmer disclaims responsibility for clearing rights of other persons
106-
that may apply to the Work or any use thereof, including without limitation
107-
any person's Copyright and Related Rights in the Work. Further, Affirmer
108-
disclaims responsibility for obtaining any necessary consents, permissions
109-
or other rights required for any use of the Work.
110-
111-
d. Affirmer understands and acknowledges that Creative Commons is not a
112-
party to this document and has no duty or obligation with respect to this
113-
CC0 or use of the Work.
114-
115-
For more information, please see
116-
<http://creativecommons.org/publicdomain/zero/1.0/>
5+
In jurisdictions that recognize copyright laws, the author or authors of this software dedicate any and all copyright interest in the software to the public domain. We make this dedication for the benefit of the public at large and to the detriment of our heirs and successors. We intend this dedication to be an overt act of relinquishment in perpetuity of all present and future rights to this software under copyright law.
1176

7+
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

README.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,7 @@
11
# Secure Python package template
22

3+
[![SLSA level 3](https://slsa.dev/images/gh-badge-level3.svg)](https://slsa.dev)
4+
35
Template for a Python package with a secure
46
project host and package repository configuration.
57

@@ -10,9 +12,9 @@ The goals of this project are to:
1012
- Automated publishing to PyPI
1113
- Code quality and vulnerability scanning
1214
- Build reproducibility
13-
- Signed releases
15+
- Releases with provenance attestation
1416
- Obtain a perfect rating from [OpenSSF Scorecard](https://github.com/ossf/scorecard)
15-
- Integrate with [Sigstore](https://www.sigstore.dev/) for signed releases
17+
- [SLSA Level 3](https://slsa.dev) using GitHub OIDC
1618

1719
## Creating the GitHub repository
1820

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
__version__: str = "0.2.0"
1+
__version__: str = "0.3.0"

0 commit comments

Comments
 (0)