This page covers release provenance verification. To report a vulnerability, see .github/SECURITY.md β the disclosure policy, response timelines, and supply-chain controls live there.
Each GitHub Release ships with:
coda-sbom.cdx.jsonβ CycloneDX SBOM of every Python + npm dependency (generated by syft).coda-sbom.cdx.json.cosign.bundleβ Sigstore keyless signature bundle (cert + signature + Rekor inclusion proof in one file).
To verify a release came from this repo's release workflow:
TAG=v1.0.0 # the release you downloaded
gh release download "$TAG" -p 'coda-sbom.cdx.json*'
cosign verify-blob \
--bundle coda-sbom.cdx.json.cosign.bundle \
--certificate-identity-regexp 'https://github.com/databrickslabs/coding-agents-databricks-apps/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
coda-sbom.cdx.jsonSigning uses GitHub's OIDC token β no long-lived signing keys exist. The signing identity is anchored to the workflow path + tag ref, and a public transparency-log entry is recorded in Rekor.