Conversation
Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 1 to 4. - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](actions/attest-build-provenance@v1...v4) --- updated-dependencies: - dependency-name: actions/attest-build-provenance dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Container ImagesThe following container images have been built for this PR:
Images expire after 7 days. |
CI StatusAll CI checks pass. This PR changes This is a straightforward GitHub Actions dependency bump. No code changes, no Go/Python impact. No merge conflicts despite being open since March. Safe to merge. Note: this is a 3-major-version jump (v1 → v4), but |
Automated Dependabot PR ReviewChecks performed:1. go.mod completeness: N/A — GitHub Actions dependency, no go.mod changes. 2. CI status: ✅ All relevant checks passed. Build images were built and pushed successfully. 3. K8s version check: N/A — not a k8s dependency. 4. Workflow completeness check: ✅ 5. Library assessment: This is a major version bump (v1 → v4):
The action interface is backward-compatible. Note: this PR has been open for over 30 days; a rebase may be needed before merging. Safe to merge. Recommended to merge (consider |
|
@dependabot rebase |
|
Sorry, only users with push access can use that command. |
Bumps actions/attest-build-provenance from 1 to 4.
Release notes
Sourced from actions/attest-build-provenance's releases.
... (truncated)
Commits
a2bbfa2bump actions/attest from 4.0.0 to 4.1.0 (#838)0856891update RELEASE.md docs (#836)e4d4f7cprepare v4 release (#835)02a49bdBump github/codeql-action in the actions-minor group (#824)7c757dfBump the npm-development group with 2 updates (#825)c44148eBump github/codeql-action in the actions-minor group (#818)3234352Bump@types/nodefrom 25.0.10 to 25.2.0 in the npm-development group (#819)18db129Bump tar from 7.5.6 to 7.5.7 (#816)90fadfaBump@actions/corefrom 2.0.1 to 2.0.2 in the npm-production group (#799)57db8baBump the npm-development group across 1 directory with 3 updates (#808)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)