Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

feat(action): attestation/verify-chain - Verify attestation chain

Open
#26 2 comments 0 reactions 1 assignee View on GitHub

@aRustyDev is already working on this.

Since Jan 27, 2026.

Assessment

This issue has not been assessed yet.

Description

enhancement new-action

Parent Epic

Part of #22 (Atomic Release Pipeline Actions)

Priority

P1 - Security validation used by W5, W6

Description

Create a composite action that verifies all attestations in a chain.

Iterates through an attestation map and verifies each attestation is valid and was created by the expected repository.

Inputs

Input Required Default Description
attestation-map Yes - JSON object of check_name → attestation_id
repository No github.repository Repository in owner/repo format
token No github.token GitHub token for API access

Outputs

Output Description
verified "true" if all attestations valid
total Total number of attestations checked
passed Number that passed verification
failed Number that failed verification

Usage Example

- uses: arustydev/gha/actions/attestation/verify-chain@v1
  id: verify
  with:
    attestation-map: ${{ steps.extract.outputs.map }}

- run: |
    if [[ "${{ steps.verify.outputs.verified }}" != "true" ]]; then
      echo "Attestation chain verification failed!"
      exit 1
    fi

Source Reference

helm-charts/.github/scripts/attestation-lib.sh:

  • verify_attestation_chain() (lines 195-248)

Implementation Notes

  • Try OCI bundle verification first, fall back to API
  • Report detailed results for each attestation
  • Fail fast on critical errors, continue on verification failures
Dominant language
Shell
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from aRustyDev/gh

All issues in aRustyDev/gh

Similar issues

More Shell/Bash issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.