Skip to content

Conversation

@nicklasl
Copy link
Member

@nicklasl nicklasl commented Dec 4, 2025

Summary

  • Adds comprehensive documentation to SECURITY.md about binary provenance and supply chain security
  • Documents how to verify WASM binary attestations
  • Provides instructions for verifying provider packages (Java, JavaScript, Go)
  • Explains deterministic builds and WASM synchronization

Context

This PR contains only the documentation changes that describe the provenance implementation. The actual provenance implementation is in a separate PR and should be merged first.

Test plan

  • Merge the provenance implementation PR
  • Verify that gh attestation verify works with a released WASM binary
  • Verify the documentation instructions are accurate
  • Merge this PR

🤖 Generated with Claude Code

Add comprehensive documentation for verifying WASM binary attestations
and provider package provenance.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <[email protected]>
@nicklasl nicklasl closed this Dec 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants