Verify SLSA with Harness GitHub Actions
Use Harness GitHub Actions to Verify SLSA Provenance
Harness GitHub Actions provide a seamless way to integrate Harness's Software Supply Chain Security (SCS) capabilities directly into GitHub workflows. You can use this GitHub Action to perform various supply chain security tasks. The Harness GitHub Action includes multiple sub-actions, each designed for specific tasks. This document focuses on the harness/github-actions/slsa-verification sub-action, which is used to generate an SBOM and attest it if needed.
The harness/github-actions/slsa-verification verifies the SLSA provenance attestation by pulling the .att file from the configured container registry. It uses the public key from the key pair that was used for signing the attestation to perform the verification.
Requirements
Here are the prerequisites for using the GitHub Action.
Harness Account: Ensure you have a Harness account with the SCS license enabled.
Harness Account Details: Save the following Harness account details, which are required for all sub-actions. It is recommended to securely store these values using GitHub Secrets.
Key
Value Example
Description
Required
HARNESS_ACCOUNT_URL
https://example.harness.io
The URL of your Harness account.
Yes
HARNESS_ACCOUNT_ID
ppdfedDDDL_dharzdPs_JtWT7g
The unique identifier for your Harness account.
Yes
HARNESS_ORG_ID
SCS
The identifier for your Harness organization.
Yes
HARNESS_PROJECT_ID
SCS_ORG
The identifier for your Harness project within the organization.
Yes
HARNESS_API_KEY
${{ secrets.SCS_API_KEY }}
The API key for authenticating with Harness. Create an API key using a Service Account (recommended) or a Personal Account , and then add the key to GitHub Actions Secrets with "HARNESS_API_KEY" as the key name.
Yes
VAULT_ADDR
https://myvault.example.com
The URL of your Vault
No
Security Keys: For attestation generation and verification, Key pair is required. The key should be generated using Cosign of type
ecdsa-P256. Currently, HashiCorp Vault is supported for storing and retrieving the key. Additional Key Management Services (KMS) will be supported in the future.
Usage example
- name: SLSA Verification
uses: harness/github-actions/slsa-verification@1.1.0
with:
HARNESS_ACCOUNT_URL: https://myaccount.harness.io
HARNESS_ACCOUNT_ID: my_account_id_9YpRharzPs
HARNESS_ORG_ID: my_org_id_default
HARNESS_PROJECT_ID: example_project_id
HARNESS_API_KEY: ${{ secrets.API_KEY_SAVED_AS_GH_SECRET }}
VAULT_ADDR: ${{ secrets.VAULT_URL }}
TARGET: example_image:latest
VERIFY: true
KMS_KEY: path/to/your/keyConfiguration
Make sure to include the required configurations from the Requirements section in your workflow. Below are the specific configurations for the slsa-verification sub-action.
Key
Value Example
Description
Required
TARGET
example_image:latest
The target artifact (Docker image) for which SLSA provenance verification is performed.
Yes
VERIFY
true or false
Boolean flag to determine if verification is required.
Yes
KMS_KEY
path/to/your/key
Path to the public key used for verifying the attestation.
No
Sample workflow
Here is a sample workflow using the harness/github-actions/slsa-verification
Last updated
Was this helpful?