{"repo":"johnbillion/action-wordpress-plugin-attestation","free":true,"listed":false,"github":"https://github.com/johnbillion/action-wordpress-plugin-attestation","clone":"git clone https://github.com/johnbillion/action-wordpress-plugin-attestation.git","description":"GitHub Action to generate an attestation for the build provenance of a plugin zip file on wordpress.org","language":null,"stars":47,"topics":["supply-chain-security","wordpress","github-actions","slsa"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"WordPress Plugin Attestation Do you use GitHub Actions to deploy your plugin to the wordpress.org plugin directory? Add this action to your deployment workflow to generate a build provenance attestation of the plugin zip file on wordpress.org and therefore harden the supply chain security of your plugin. This action integrates well with the WordPress Plugin Deploy action, but it can work with any workflow which deploys your plugin. What is this and why should I use it? Artifact attestations enable you to increase the supply chain security of your builds by establishing where and how your software was built. Source: GitHub Docs This action generates an artifact attestation for the zip file that is served by the plugin directory for each release of your plugin. This can subsequently be used by consumers to verify that a given version of your plugin actually originated from your user account on GitHub. There is not much tooling for the verification aspect at the moment — other than the gh attestation verify command — but this ultimately facilitates verifying that a plugin release came from its trusted author rather than an unwanted entity, for example somebody who stole your SVN password, hacked into wordpress.org, or performed a hostile plugin takeover. Usage Within the GitHub Actions workflow which deploys your plugin to the plugin directory: 1. Ensure that at least the following permissions are set: 2. Add the following step to your workflow so it runs after your plugin has b","default_branch":null,"files":null,"tree":[],"storefront":"/r/johnbillion","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/johnbillion/action-wordpress-plugin-attestation/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}