File tree 3 files changed +9
-9
lines changed
3 files changed +9
-9
lines changed Original file line number Diff line number Diff line change @@ -20,11 +20,11 @@ jobs:
20
20
- name : Checkout
21
21
uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
22
22
- name : Setup Cosign
23
- uses : sigstore/cosign-installer@c56c2d3e59e4281cc41dea2217323ba5694b171e # v3.8.0
23
+ uses : sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a # v3.8.1
24
24
- name : Setup Timoni
25
25
uses : ./actions/setup
26
26
- name : Login to GHCR
27
- uses : docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3 .0
27
+ uses : docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4 .0
28
28
with :
29
29
registry : ghcr.io
30
30
username : ${{ github.actor }}
Original file line number Diff line number Diff line change 31
31
uses : anchore/sbom-action/download-syft@f325610c9f50a54015d37c8d16cb3b0e2c8f4de0 # v0.18.0
32
32
- name : Run GoReleaser
33
33
id : run-goreleaser
34
- uses : goreleaser/goreleaser-action@9ed2f89a662bf1735a48bc8557fd212fa902bebf # v6.1.0
34
+ uses : goreleaser/goreleaser-action@90a3faa9d0182683851fbfa97ca1a2cb983bfca3 # v6.2.1
35
35
with :
36
36
version : latest
37
37
args : release --skip=validate
@@ -64,11 +64,11 @@ jobs:
64
64
- name : Checkout
65
65
uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
66
66
- name : Setup Cosign
67
- uses : sigstore/cosign-installer@c56c2d3e59e4281cc41dea2217323ba5694b171e # v3.8.0
67
+ uses : sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a # v3.8.1
68
68
- name : Setup Timoni
69
69
uses : ./actions/setup
70
70
- name : Login to GHCR
71
- uses : docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3 .0
71
+ uses : docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4 .0
72
72
with :
73
73
registry : ghcr.io
74
74
username : ${{ github.actor }}
@@ -113,7 +113,7 @@ jobs:
113
113
actions : read # To read the workflow path.
114
114
id-token : write # To sign the provenance.
115
115
contents : write # To add assets to a release.
116
- uses : slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v2.0 .0
116
+ uses : slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v2.1 .0
117
117
with :
118
118
provenance-name : " timoni_${{ needs.goreleaser.outputs.version }}_provenance.intoto.jsonl"
119
119
base64-subjects : " ${{ needs.goreleaser.outputs.hashes }}"
Original file line number Diff line number Diff line change @@ -28,10 +28,10 @@ jobs:
28
28
**/go.sum
29
29
**/go.mod
30
30
- name : Init
31
- uses : github/codeql-action/init@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3.28.9
31
+ uses : github/codeql-action/init@6bb031afdd8eb862ea3fc1848194185e076637e5 # v3.28.11
32
32
with :
33
33
languages : go
34
34
- name : Build
35
- uses : github/codeql-action/autobuild@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3.28.9
35
+ uses : github/codeql-action/autobuild@6bb031afdd8eb862ea3fc1848194185e076637e5 # v3.28.11
36
36
- name : Analyze
37
- uses : github/codeql-action/analyze@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3.28.9
37
+ uses : github/codeql-action/analyze@6bb031afdd8eb862ea3fc1848194185e076637e5 # v3.28.11
You can’t perform that action at this time.
0 commit comments