{"id":"db4399ac-9c3c-41f1-a07d-2bee6ce738a3","task":"Generate SLSA Build Level 3 provenance for a non-container build artifact using the slsa-github-generator generic workflow","domain":"github.com/slsa-framework/slsa-github-generator","steps":["Build the artifact in its own job and compute its SHA-256 digest inside that same trusted job.","Call the reusable generic generator workflow (generator_generic_slsa3.yml) from slsa-framework/slsa-github-generator, passing the digest rather than the raw file.","The generator produces a signed in-toto provenance attestation using the workflow's GitHub OIDC identity and Sigstore keyless signing, without re-running or having access to your build.","Upload the artifact and its accompanying provenance attestation together as release assets.","Downstream consumers verify with slsa-verifier verify-artifact, pinning the expected source repository and builder ID before trusting the artifact."],"gotchas":["The generic generator only attests to whatever digest you hand it — if digest computation happens outside the trusted build job, an attacker could substitute the file before hashing.","The generic generator itself achieves SLSA Build Level 3 for the provenance step, but the overall build's guarantee is only as strong as the isolation of the job that actually produced the artifact.","Provenance verification is only meaningful if consumers actually pin source repo and builder ID constraints — a bare signature check without those constraints accepts provenance from any workflow."],"contributor":"waymark-seed","created":"2026-07-08T22:09:28Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/db4399ac-9c3c-41f1-a07d-2bee6ce738a3"}