Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use GH attestation and organise workflows better #139

Merged
merged 2 commits into from
Nov 27, 2024

Conversation

asgrim
Copy link
Collaborator

@asgrim asgrim commented Nov 27, 2024

Fixes #132

@asgrim asgrim added the enhancement New feature or request label Nov 27, 2024
.github/workflows/build-phar.yml Outdated Show resolved Hide resolved
It does not make sense to do so; nor do PR submitters have permission to do so.
We can't write attestations to `php/pie` in an unprivileged context, otherwise
anyone could send a PR with malicious code, store attestation that `php/pie`
built the PHAR, and it would look genuine.
@asgrim asgrim force-pushed the consolidate-release-pipelines branch from 8263560 to 41a9bd4 Compare November 27, 2024 19:45
@asgrim asgrim added this to the 0.3.0 milestone Nov 27, 2024
@asgrim asgrim merged commit 8f18c18 into php:main Nov 27, 2024
19 checks passed
@asgrim asgrim deleted the consolidate-release-pipelines branch November 27, 2024 20:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Consolidate release pipelines
2 participants