Skip to content

ci(moss): (2/4) add PyPI SLSA provenance and SBOM attestations - #5602

Open
chiajunglien wants to merge 1 commit into
mainfrom
emma/moss-pr2-pypi-attestations
Open

chiajunglien wants to merge 1 commit into
mainfrom
emma/moss-pr2-pypi-attestations

Conversation

@chiajunglien

Copy link
Copy Markdown
Collaborator

Description

PR 2 of 4: PyPI SLSA Provenance & Attestations (split from #5582 per review feedback; depends on #5601).

This PR attaches signed SLSA build provenance and SPDX SBOM attestations to MaxText PyPI releases:

  • .github/workflows/pypi_release.yml:
    • Grants attestations: write permission to publish_maxtext_to_pypi.
    • Downloads the maxtext-wheel-sbom artifact (sbom/maxtext-wheel.spdx.json) generated by build_package.yml (introduced in ci(moss): (1/4) add SPDX SBOM generation and Syft setup #5601).
    • Signs SLSA build provenance for dist/*.whl via actions/attest-build-provenance@v2.2.3.
    • Signs the SPDX SBOM attestation for dist/*.whl via actions/attest-sbom@v2.2.0.
    • Enables attestations: true on pypa/gh-action-pypi-publish.
  • .github/workflows/release_pipeline.yml:
    • Grants attestations: write permission to the caller job publish_to_pypi.

Tests

  • Validated workflow syntax and security rules via yamllint, codespell, and zizmor.

Checklist

Before submitting this PR, please make sure (put X in square brackets):

  • I have performed a self-review of my code. For an optional AI review, add the gemini-review label.
  • I have necessary comments in my code, particularly in hard-to-understand areas.
  • I have run end-to-end tests tests and provided workload links above if applicable.
  • I have made or will make corresponding changes to the doc if needed, including adding new documentation pages to the relevant Table of Contents (toctree directive) as explained in our documentation.

Signed-off-by: EmmaLien <emmalien@google.com>
@gemini-code-assist

Copy link
Copy Markdown

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

@codecov

codecov Bot commented Oct 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@chiajunglien chiajunglien changed the title ci(moss): add PyPI SLSA provenance and SBOM attestations ci(moss): (2/4) add PyPI SLSA provenance and SBOM attestations Oct 8, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants