13
13
outputs :
14
14
new-tag : ${{ steps.ccv.outputs.new-tag }}
15
15
steps :
16
- - uses : actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
16
+ - uses : actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
17
17
with :
18
18
fetch-depth : 0
19
19
- name : Bump tag if necessary
33
33
if : needs.release-tag.outputs.new-tag == 'true'
34
34
runs-on : ubuntu-latest
35
35
steps :
36
- - uses : actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
36
+ - uses : actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
37
37
with :
38
38
fetch-depth : 0
39
39
- uses : actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
64
64
GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
65
65
GITHUB_SBOM_PATH : ./sbom.spdx.json
66
66
# attest archives
67
- - uses : actions/attest-build-provenance@49df96e17e918a15956db358890b08e61c704919 # v1.2.0
67
+ - uses : actions/attest-build-provenance@bdd51370e0416ac948727f861e03c2f05d32d78e # v1.3.2
68
68
with :
69
69
subject-path : " dist/*.tar.gz"
70
70
# parse artifacts to the format required for image attestation
@@ -87,17 +87,17 @@ jobs:
87
87
env:
88
88
ARTIFACTS: ${{steps.goreleaser.outputs.artifacts}}
89
89
# attest images
90
- - uses : actions/attest-build-provenance@49df96e17e918a15956db358890b08e61c704919 # v1.2.0
90
+ - uses : actions/attest-build-provenance@bdd51370e0416ac948727f861e03c2f05d32d78e # v1.3.2
91
91
with :
92
92
subject-digest : ${{steps.image_metadata_ssh_portal.outputs.digest}}
93
93
subject-name : ${{steps.image_metadata_ssh_portal.outputs.name}}
94
94
push-to-registry : true
95
- - uses : actions/attest-build-provenance@49df96e17e918a15956db358890b08e61c704919 # v1.2.0
95
+ - uses : actions/attest-build-provenance@bdd51370e0416ac948727f861e03c2f05d32d78e # v1.3.2
96
96
with :
97
97
subject-digest : ${{steps.image_metadata_ssh_portal_api.outputs.digest}}
98
98
subject-name : ${{steps.image_metadata_ssh_portal_api.outputs.name}}
99
99
push-to-registry : true
100
- - uses : actions/attest-build-provenance@49df96e17e918a15956db358890b08e61c704919 # v1.2.0
100
+ - uses : actions/attest-build-provenance@bdd51370e0416ac948727f861e03c2f05d32d78e # v1.3.2
101
101
with :
102
102
subject-digest : ${{steps.image_metadata_ssh_token.outputs.digest}}
103
103
subject-name : ${{steps.image_metadata_ssh_token.outputs.name}}
0 commit comments