Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Unauditable build process due to expired GitHub Actions logs #571

Open
acottuli opened this issue Nov 5, 2024 · 1 comment
Open

Unauditable build process due to expired GitHub Actions logs #571

acottuli opened this issue Nov 5, 2024 · 1 comment

Comments

@acottuli
Copy link

acottuli commented Nov 5, 2024

In case you hadn't realised the GHA logs containing the SHA of the latest zip file (i.e. v2.4.1)[1] have expired[2], which means the build process is no longer auditable[3].

Unfortunately it doesn't look like there is much you can do about this other than to rebuild the binaries every 90 days[4].

[1] https://github.com/maxgoedjen/secretive/releases/
[2] https://github.com/maxgoedjen/secretive/actions/runs/7648958148/job/20842568707
[3] https://github.com/maxgoedjen/secretive/blob/main/FAQ.md#why-should-i-trust-you
[4] https://docs.github.com/en/organizations/managing-organization-settings/configuring-the-retention-period-for-github-actions-artifacts-and-logs-in-your-organization

@acottuli
Copy link
Author

acottuli commented Nov 5, 2024

As a workaround, I ended up installing the latest nightly build instead of the latest release build, but it's worth noting that the latest version on the Releases page is the only currently supported version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant