Skip to main content
View Markdown ↗

Copy this page

Select and copy the Markdown below, then paste it into your LLM.

aflock-ai/cilock-action reference

Source of truth: cilock-action/action.yml.

The CI/lock GitHub Action wraps a command (or another GitHub Action) and produces signed attestations. It downloads its own variant of the cilock binary at runtime from the cilock-action releases.

- uses: aflock-ai/[email protected]   # pin to an exact tag or commit SHA
  with:
    step: build
    command: "go build -o myapp ./cmd/myapp"

Latest release: v1.0.4 — bundles a CI/lock built from rookery main with govulncheck, inclusion-proof, secretscan, slsa, and the PR #153 atomic-rename trace fix. Pin to the exact tag (or commit SHA) — never a moving major-version ref.

Multi-step chain via step names

CI/lock's policy language lets you declare relationships between attested steps. By giving each cilock-action invocation a distinct step: name and declaring artifactsFrom in the verification policy, the verifier enforces that step N's materials match step N-1's products byte-for-byte. This is how CI/lock's own release pipeline chains vendor-cilock-deps → release-build — see Verify the cilock binary.

# Step 1 — vendor
- uses: aflock-ai/[email protected]
  with:
    step: vendor-deps        # ← policy declares this step
    command: go mod vendor
    outfile: dist/vendor.attestation.json

# Step 2 — build, references step 1 via artifactsFrom in your policy
- uses: aflock-ai/[email protected]
  with:
    step: app-build
    command: go build -mod=vendor -o app ./cmd/app
    outfile: dist/build.attestation.json
    trace: "true"            # ← required for the hermetic / network-egress Rego

Required permissions

For keyless Sigstore signing (the default), the workflow needs:

permissions:
  id-token: write   # for OIDC token to Fulcio
  contents: read    # standard checkout

Add packages: write if you push container images, etc.

Inputs

Core

One of command or action-ref is required.

InputDefaultDescription
step(required)Step name for the attestation.
command(none)Shell command to run.
action-ref(none)GitHub Action to wrap (owner/repo@ref or docker://image).
action-inputs(none)JSON map of inputs to pass to the wrapped action.
action-env(none)Additional env vars for the wrapped action (KEY=VALUE per line).

Binary

InputDefaultDescription
versionmatches action tagcilock-action release version to download.
cilock-binary-url(none)Custom URL for a pre-built cilock binary.
cilock-args(none)Additional raw args passed through to CI/lock.

Attestation

InputDefaultDescription
attestationsenvironment git githubSpace-separated attestor list (the shim translates to the comma-separated form the cilock CLI expects).
outfile(none)Output file for signed envelope.
workingdir(none)Working directory.
tracefalseEnable command tracing.
hashessha256Hash algorithms.

TestifySec platform

InputDefaultDescription
platform-urlhttps://platform.testifysec.comAll service URLs are derived from this. Self-hosted customers override.

Archivista

Derived from platform-url if not explicitly set.

InputDefaultDescription
enable-archivistatrueStore attestations in Archivista.
archivista-serverderived from platform-urlArchivista server URL.

Sigstore / Fulcio

Derived from platform-url if not explicitly set.

InputDefaultDescription
enable-sigstoretrueEnable Sigstore/Fulcio signing.
fulcio-urlderived from platform-urlFulcio server URL.
fulcio-oidc-client-idsigstoreFulcio OIDC client ID.
fulcio-oidc-issuerhttps://token.actions.githubusercontent.comFulcio OIDC issuer URL.
fulcio-use-httptrueUse HTTP/REST API for Fulcio (works behind any reverse proxy).

File signer

InputDefaultDescription
key(none)Path to signing key.
certificate(none)Path to signing certificate.
intermediates(none)Comma-separated paths to intermediate certificates.

KMS

InputDefaultDescription
kms-aws-profile(none)AWS profile for KMS signing.
kms-gcp-credentials-file(none)GCP credentials file for KMS signing.
kms-ref(none)KMS key reference URI (awskms://..., gcpkms://..., azurekms://..., hashivault://...).

Vault

InputDefaultDescription
vault-url(none)HashiCorp Vault URL.
vault-token(none)HashiCorp Vault token.

Timestamps

InputDefaultDescription
timestamp-serversderived from platform-urlSpace-separated TSA URLs.

Environment filtering

InputDefaultDescription
env-add-sensitive-key(none)Comma-separated additional sensitive env var keys.
env-filter-sensitive-varsfalseFilter (remove) sensitive vars instead of obfuscating.

Material / Product

InputDefaultDescription
product-include-glob*Glob for product file inclusion.
product-exclude-glob(none)Glob for product file exclusion.

Attestor exports

InputDefaultDescription
attestor-sbom-exportfalseExport SBOM as a separate attestation.
attestor-slsa-exportfalseExport SLSA provenance as a separate attestation.

Builder

InputDefaultDescription
builder-manifest(none)Path to a rookery-builder manifest for a custom binary.
builder-preset(none)Builder preset: minimal, cicd, all.

Outputs

OutputDescription
git_oidGitOID of the stored attestation.
attestation_filePath to the attestation output.

Runtime

runs:
  using: "node20"
  main: "shim/index.js"

The shim/index.js Node entry point downloads the variant binary from https://github.com/aflock-ai/cilock-action/releases/{latest/download | download/<tag>} and invokes it with the constructed args.

SLSA Build L3: the provenance workflow

When cilock runs inside your build job, the provenance it signs can reach SLSA Build L2 at most. The job's own steps could forge it. For L3, add a second job. It calls the reusable provenance.yml workflow, runs none of your code, and signs SLSA v1 provenance with its own Fulcio identity:

  provenance:
    needs: build
    permissions: { id-token: write }
    uses: aflock-ai/cilock-action/.github/workflows/provenance.yml@<40-hex commit>
    with: { subjects: "${{ needs.build.outputs.subjects }}" }
  • Pin by commit, never by tag. The verifier requires the certificate's Build Signer URI to name the pinned commit, so a tag pin is refused.
  • subjects is one <name>=sha256:<hex> per line. Your build job outputs it, for example with echo "subjects=app=sha256:$(sha256sum dist/app | cut -d' ' -f1)" >> "$GITHUB_OUTPUT". The build job must also run cilock in the same workflow run: a subject is accepted only if that run's build collection carries it.
  • Triggers: the workflow signs only for push, release and workflow_dispatch. Any other event, fork pull requests and pull_request_target included, fails the job.
  • Signer: the platform's Fulcio and timestamp authority by default (platform-url). Set public-sigstore: true to use public Sigstore instead.

Verify with the built-in L3 policy. There is no -p:

cilock verify ./dist/app --slsa-level 3 \
  --slsa-builder-digest <the same commit> --slsa-source-repo <owner>/<repo> \
  -a provenance.json -a build.json --vsa-outfile vsa.json

--slsa-level 3 exits 0 only if all of these hold:

  • the provenance's signing certificate names provenance.yml at that commit, a GitHub-hosted runner, a writer-only trigger, and your repository;
  • builder.id, repository, commit and run in the statement equal that certificate's extensions;
  • buildType and externalParameters are what provenance.yml writes;
  • the artifact is among the subjects, and a build collection from the same run, repository and commit carries it.

--format json lists each requirement that failed. The VSA states SLSA_BUILD_LEVEL_3 only on a pass. Add --slsa-roots public-sigstore with --slsa-public-sigstore-ca-roots and --slsa-public-sigstore-timestamp-servers to accept public Sigstore signatures.

Status: this needs a cilock-action commit that contains provenance.yml and a cilock release that has --slsa-level. Neither is published yet.

Worked examples

The action ships example workflows in examples/github/:

  • Wrapping another GitHub Action (e.g. docker/build-push-action)
  • Wrapping a shell command
  • Multi-step pipeline with downstream verification

The full end-to-end walkthrough lives in the GitHub Actions tutorial.

Reference generated from the product documentation. Match commands and support details to your installed release.