1313 outputs :
1414 new-tag : ${{ steps.ccv.outputs.new-tag }}
1515 steps :
16- - uses : actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
16+ - uses : actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
1717 with :
1818 fetch-depth : 0
1919 - name : Bump tag if necessary
3232 if : needs.release-tag.outputs.new-tag == 'true'
3333 runs-on : ubuntu-latest
3434 steps :
35- - uses : actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
35+ - uses : actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
3636 with :
3737 fetch-depth : 0
3838 - uses : actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2
6161 GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
6262 GITHUB_SBOM_PATH : ./sbom.spdx.json
6363 # attest archives
64- - uses : actions/attest-build-provenance@6149ea5740be74af77f260b9db67e633f6b0a9a1 # v1.4.2
64+ - uses : actions/attest-build-provenance@1c608d11d69870c2092266b3f9a6f3abbf17002c # v1.4.3
6565 with :
6666 subject-path : " dist/*.tar.gz"
6767 # parse artifacts to the format required for image attestation
@@ -78,12 +78,12 @@ jobs:
7878 env:
7979 ARTIFACTS: ${{steps.goreleaser.outputs.artifacts}}
8080 # attest images
81- - uses : actions/attest-build-provenance@6149ea5740be74af77f260b9db67e633f6b0a9a1 # v1.4.2
81+ - uses : actions/attest-build-provenance@1c608d11d69870c2092266b3f9a6f3abbf17002c # v1.4.3
8282 with :
8383 subject-digest : ${{steps.image_metadata_go_cli_github.outputs.digest}}
8484 subject-name : ${{steps.image_metadata_go_cli_github.outputs.name}}
8585 push-to-registry : true
86- - uses : actions/attest-build-provenance@6149ea5740be74af77f260b9db67e633f6b0a9a1 # v1.4.2
86+ - uses : actions/attest-build-provenance@1c608d11d69870c2092266b3f9a6f3abbf17002c # v1.4.3
8787 with :
8888 subject-digest : ${{steps.image_metadata_another_binary.outputs.digest}}
8989 subject-name : ${{steps.image_metadata_another_binary.outputs.name}}
0 commit comments