← Back to context

Comment by nailer

1 hour ago

> Every release is built from its tag by GitHub Actions and carries a build provenance attestation.

Huh cool. They're doing curl | bash properly.

That doesn't seem to do much in the `curl | bash` setting, given that you're not verifying the attestation in that case. You still need to download it separately and run `gh attestation verify` first.

(Note that the attestation does not appear to cover the shell script either, it only covers the script's final payload. The shell script is also referenced via `main`, so it's mutable even if the underlying payload is properly attested. That's not good!)