[ruff] Add attestions for release artifacts and Docker images
by shaanmajid
·
Feb 06, 2026 at 19:12 UTC
·
scan-c3abccdad59d08fc
Get this automatically on every PR
Install the Axiomo GitHub App to get Signals as check runs and PR comments on every pull request.
Risk level: High (55%)
Add attestations for release artifacts and Docker images
.github/workflows/release.yml updates include attestation permissions
.github/workflows/build-docker.yml updates include attestation permissions
Commands are noted in PR description, but not verifiable from diff
First-time contributor to this repository. unfamiliar with 3 files.
Focus on 1 critical file(s)
.github/workflows/build-docker.yml
+59
Modifies ci_config code; 59 lines changed; Configuration
.github/workflows/release.yml
+15
Modifies ci_config code; Configuration
dist-workspace.toml
+10
Configuration
16
minutes to review
medium
effort level
none
staleness risk
Prioritize for security-sensitive review
Insufficient evidence (CI/tests) to evaluate
.github/workflows/build-docker.yml
Requires security review for ci_config changes
Why is ci_passing missing? Consider adding this check.
Why is tests_passing missing? Consider adding this check.
.github/workflows/build-docker.yml
Critical file: Modifies ci_config code; 59 lines changed; Configuration
.github/workflows/build-docker.yml
CI configuration changed - verify build/deploy behavior
First contribution - consider welcoming and providing extra context