Skip to content

Latest commit

Β 

History

History
27 lines (19 loc) Β· 1.19 KB

File metadata and controls

27 lines (19 loc) Β· 1.19 KB

Security

This page covers release provenance verification. To report a vulnerability, see .github/SECURITY.md β€” the disclosure policy, response timelines, and supply-chain controls live there.

Verifying release provenance

Each GitHub Release ships with:

  • coda-sbom.cdx.json β€” CycloneDX SBOM of every Python + npm dependency (generated by syft).
  • coda-sbom.cdx.json.cosign.bundle β€” Sigstore keyless signature bundle (cert + signature + Rekor inclusion proof in one file).

To verify a release came from this repo's release workflow:

TAG=v1.0.0   # the release you downloaded
gh release download "$TAG" -p 'coda-sbom.cdx.json*'

cosign verify-blob \
  --bundle coda-sbom.cdx.json.cosign.bundle \
  --certificate-identity-regexp 'https://github.com/databrickslabs/coding-agents-databricks-apps/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  coda-sbom.cdx.json

Signing uses GitHub's OIDC token β€” no long-lived signing keys exist. The signing identity is anchored to the workflow path + tag ref, and a public transparency-log entry is recorded in Rekor.