diff --git a/README.md b/README.md index 7d9f72b..62ec24c 100644 --- a/README.md +++ b/README.md @@ -19,6 +19,9 @@ initiated. Attestations can be verified using the [`attestation` command in the GitHub CLI][5]. +See [Using artifact attestations to establish provenance for builds][9] +for more information on artifact attestations. + ## Usage Within the GitHub Actions workflow which builds some artifact you would like to @@ -207,3 +210,4 @@ jobs: https://github.com/sigstore/protobuf-specs/blob/main/protos/sigstore_bundle.proto [7]: https://jsonlines.org/ [8]: https://github.com/actions/toolkit/tree/main/packages/glob#patterns +[9]: https://docs.github.com/en/actions/security-guides/using-artifact-attestations-to-establish-provenance-for-builds