Skip to content

Commit 30d0be3

Browse files
authored
docs: Add maintenance status for slsa-verifier (#898)
Signed-off-by: Hayden <8418760+Hayden-IO@users.noreply.github.com>
1 parent aaf98fd commit 30d0be3

1 file changed

Lines changed: 8 additions & 0 deletions

File tree

README.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,14 @@
88

99
<img align="right" src="https://slsa.dev/images/logo-mono.svg" width="140" height="140">
1010

11+
> This project is **no longer actively maintained**.
12+
> We are working on guidance and simpler tooling to replace it.
13+
14+
> If you are verifying attestations for GitHub Actions, we suggest generating them with
15+
> [GitHub artifact attestations](https://docs.github.com/en/actions/concepts/security/artifact-attestations),
16+
> a built-in solution for generating SLSA provenance on GitHub, and verifying them
17+
> with [`gh attestation verify`](https://cli.github.com/manual/gh_attestation_verify).
18+
1119
<!-- markdown-toc --bullets="-" -i README.md -->
1220

1321
<!-- toc -->

0 commit comments

Comments
 (0)