Build and attest with GitHub Actions
The reusable workflow turns an allowed GitHub commit into immutable artifact evidence. GitHub OpenID Connect (OIDC) gives Liskov a short-lived statement of repository, ref, commit, and workflow identity. You do not store a Liskov bearer token or spend-capable credential in GitHub.
The moving v1 release is live. The production acceptance recorded for this
contract used v1.2.2; callers should use @v1 to receive compatible v1 fixes.
Security-sensitive callers may instead pin the reviewed commit
cbca2cde077df0cfd6be894519c6f8e4915e386a and update it deliberately.
Add the caller workflow
name: Build Liskov Application
on:
push:
branches: [main]
workflow_dispatch:
permissions:
contents: read
id-token: write
jobs:
artifact:
uses: proof-computer/liskov-github-actions/.github/workflows/acurast-app.yml@v1
with:
app-id: status-worker
working-directory: .
entrypoint: app.cjs
authored-manifest-path: .liskov/application-manifest.json
Use the same Application ID, repository, ref, workflow path, and manifest path
as the manifest's builder block. In a monorepo, set working-directory to the
directory containing package.json and pnpm-lock.yaml.
The default IPFS proxy requires no repository secret. A custom proxy may use
ACURAST_IPFS_URL and ACURAST_IPFS_API_KEY; those authorize upload to that
proxy, not Acurast spend or Liskov policy publication.
What runs
The called workflow:
- checks out the triggering commit;
- installs the requested pnpm and Node.js versions;
- runs
pnpm install --frozen-lockfile,typecheck,test, andbuild; - packages the entrypoint and requested extra files;
- uploads the bundle to the Acurast IPFS proxy without spending; and
- attests the CID, SHA-256 digest, manifest digests, and GitHub OIDC identity to Liskov.
The Attest artifact pin step reports Liskov's deterministic
artifact-version-id. Record that ID for publication.
Verify the run
Open the GitHub Actions run and confirm:
- the workflow came from the allowed branch and exact commit;
- install, typecheck, tests, and build passed;
- the pinned CID and digest are present;
- artifact attestation succeeded; and
- an artifact-version ID was returned.
Then compare that evidence in Liskov:
proof liskov application artifact-pin list status-worker --json
This advanced read is safe. The workflow does not import or publish your manifest, select a deployment schedule, reserve Service Credits, or register an Acurast job. Continue with Validate, import, and publish.
Encrypted JavaScript release boundary
Encrypted JavaScript payload execution is production-verified with Actions
v1.3.2 and runtime SDK 0.3.30: the released workflow encrypted, pinned and
attested the module, and a processor obtained its managed key, loaded it and
reported application completion. General customer availability still requires
the registered V5 source-publication release in the
capability matrix.
The encrypted JavaScript recipe records the exact inputs, module contract, paused key setup and verification steps. It uses the existing managed Lockbox boundary and does not grant a build workflow publication or spending authority. See Trust and data boundaries before making a private-code claim; Cargo image and cache confidentiality remains separate.