Skip to content

Docs: document vg attest-actions local/offline expectations #260

Description

@vibgrate-team

Context

vg attest-actions sits next to supply-chain attestation workflows. Users coming from cosign-style verify flows expect clear docs on what runs on-device, what (if anything) needs network, and how failures should be worded when signatures or materials are missing in air-gapped environments.

What to do

  1. Document the command’s purpose, inputs/outputs, and local-first boundaries.
  2. Include a minimal try-it snippet with vg (happy path + one honest failure: missing attestation / unreadable material).
  3. Explicitly state: no secrets in examples; do not print tokens/credentials in error paths.

Acceptance

  • Docs cover local vs any optional remote steps without overselling offline guarantees
  • Actionable error examples (what failed + what to check)
  • DCO; examples use vg

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentation

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions