Skip to content

Commit cd7c2c3

Browse files
Upgrade: [dependabot] - bump actions/attest-build-provenance from 3.0.0 to 3.2.0 (#26)
Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 3.0.0 to 3.2.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/actions/attest-build-provenance/releases">actions/attest-build-provenance's releases</a>.</em></p> <blockquote> <h2>v3.2.0</h2> <h2>What's Changed</h2> <ul> <li>Bump <code>@​actions/core</code> from 1.11.1 to 2.0.1 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/attest-build-provenance/pull/776">actions/attest-build-provenance#776</a></li> <li>Add more documentation on Artifact Metadata Storage Records by <a href="https://github.com/malancas"><code>@​malancas</code></a> in <a href="https://redirect.github.com/actions/attest-build-provenance/pull/797">actions/attest-build-provenance#797</a></li> <li>Update actions/attest to latest version v3.2.0 by <a href="https://github.com/malancas"><code>@​malancas</code></a> in <a href="https://redirect.github.com/actions/attest-build-provenance/pull/812">actions/attest-build-provenance#812</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/attest-build-provenance/compare/v3.1.0...v3.2.0">https://github.com/actions/attest-build-provenance/compare/v3.1.0...v3.2.0</a></p> <h2>v3.1.0</h2> <h2>What's Changed</h2> <ul> <li>Prepare v3 release by <a href="https://github.com/bdehamer"><code>@​bdehamer</code></a> in <a href="https://redirect.github.com/actions/attest-build-provenance/pull/697">actions/attest-build-provenance#697</a></li> <li>Bump js-yaml from 3.14.1 to 3.14.2 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/attest-build-provenance/pull/749">actions/attest-build-provenance#749</a></li> <li>Bump tar from 7.5.1 to 7.5.2 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/attest-build-provenance/pull/753">actions/attest-build-provenance#753</a></li> <li>Bump glob from 10.4.5 to 10.5.0 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/attest-build-provenance/pull/754">actions/attest-build-provenance#754</a></li> <li>Bump <code>@​types/node</code> from 24.10.1 to 25.0.2 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/attest-build-provenance/pull/774">actions/attest-build-provenance#774</a></li> <li>Bump <code>@​actions/attest</code> from 1.6.0 to 2.0.0 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/attest-build-provenance/pull/736">actions/attest-build-provenance#736</a></li> <li>Bump <code>@​actions/attest</code> from 2.0.0 to 2.1.0 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/attest-build-provenance/pull/775">actions/attest-build-provenance#775</a></li> <li>Add support for creating artifact metadata storage records by <a href="https://github.com/malancas"><code>@​malancas</code></a> in <a href="https://redirect.github.com/actions/attest-build-provenance/pull/779">actions/attest-build-provenance#779</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/malancas"><code>@​malancas</code></a> made their first contribution in <a href="https://redirect.github.com/actions/attest-build-provenance/pull/779">actions/attest-build-provenance#779</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/attest-build-provenance/compare/v3...v3.1.0">https://github.com/actions/attest-build-provenance/compare/v3...v3.1.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/actions/attest-build-provenance/commit/96278af6caaf10aea03fd8d33a09a777ca52d62f"><code>96278af</code></a> Update actions/attest to latest version v3.2.0 (<a href="https://redirect.github.com/actions/attest-build-provenance/issues/812">#812</a>)</li> <li><a href="https://github.com/actions/attest-build-provenance/commit/6865550d0380db508fc599a58cc87c50c0bba5c5"><code>6865550</code></a> Add more documentation on Artifact Metadata Storage Records (<a href="https://redirect.github.com/actions/attest-build-provenance/issues/797">#797</a>)</li> <li><a href="https://github.com/actions/attest-build-provenance/commit/98f3aa9c27c3d6da66cf51b7d38fb7511df72d3a"><code>98f3aa9</code></a> Bump <code>@​actions/core</code> from 1.11.1 to 2.0.1 (<a href="https://redirect.github.com/actions/attest-build-provenance/issues/776">#776</a>)</li> <li><a href="https://github.com/actions/attest-build-provenance/commit/63e64444a7857c20bbda4810126aabe30ef3b047"><code>63e6444</code></a> Bump github/codeql-action in the actions-minor group (<a href="https://redirect.github.com/actions/attest-build-provenance/issues/782">#782</a>)</li> <li><a href="https://github.com/actions/attest-build-provenance/commit/3bc61afc810a5808496e2782a241fbbf5b91e8b0"><code>3bc61af</code></a> Bump the npm-development group with 2 updates (<a href="https://redirect.github.com/actions/attest-build-provenance/issues/795">#795</a>)</li> <li><a href="https://github.com/actions/attest-build-provenance/commit/405d0eac46dee8bbc8a98b540f33935742b4d7c8"><code>405d0ea</code></a> Bump the npm-development group with 3 updates (<a href="https://redirect.github.com/actions/attest-build-provenance/issues/783">#783</a>)</li> <li><a href="https://github.com/actions/attest-build-provenance/commit/00014ed6ed5efc5b1ab7f7f34a39eb55d41aa4f8"><code>00014ed</code></a> Add support for creating artifact metadata storage records (<a href="https://redirect.github.com/actions/attest-build-provenance/issues/779">#779</a>)</li> <li><a href="https://github.com/actions/attest-build-provenance/commit/8835c60c52cafa2b7f8bd4fadd525d33bf16cefe"><code>8835c60</code></a> Bump <code>@​actions/attest</code> from 2.0.0 to 2.1.0 (<a href="https://redirect.github.com/actions/attest-build-provenance/issues/775">#775</a>)</li> <li><a href="https://github.com/actions/attest-build-provenance/commit/331a7ac6b7b893a9d009fe50d4e268b659c70ae5"><code>331a7ac</code></a> Bump <code>@​types/node</code> from 24.10.1 to 25.0.2 (<a href="https://redirect.github.com/actions/attest-build-provenance/issues/774">#774</a>)</li> <li><a href="https://github.com/actions/attest-build-provenance/commit/bd4fc0326ad7a75a2ad6b8649fef9e07d1918dad"><code>bd4fc03</code></a> Bump the npm-development group with 5 updates (<a href="https://redirect.github.com/actions/attest-build-provenance/issues/773">#773</a>)</li> <li>Additional commits viewable in <a href="https://github.com/actions/attest-build-provenance/compare/977bb373ede98d70efdf65b84cb5f73e068dcc2a...96278af6caaf10aea03fd8d33a09a777ca52d62f">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/attest-build-provenance&package-manager=github_actions&previous-version=3.0.0&new-version=3.2.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent 0c0e942 commit cd7c2c3

File tree

1 file changed

+8
-8
lines changed

1 file changed

+8
-8
lines changed

.github/workflows/build_multi_arch_image.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -149,7 +149,7 @@ jobs:
149149
CONTAINER_NAME: '${{ inputs.container_name }}'
150150
ARCHITECTURE: '${{ matrix.arch }}'
151151
- name: Attest image
152-
uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a
152+
uses: actions/attest-build-provenance@96278af6caaf10aea03fd8d33a09a777ca52d62f
153153
with:
154154
subject-name: ghcr.io/nhsdigital/eps-devcontainers/${{ inputs.container_name }}
155155
subject-digest: ${{ steps.resolve_arch_digest.outputs.digest }}
@@ -173,7 +173,7 @@ jobs:
173173
CONTAINER_NAME: '${{ inputs.container_name }}'
174174
ARCHITECTURE: '${{ matrix.arch }}'
175175
- name: Attest github actions image
176-
uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a
176+
uses: actions/attest-build-provenance@96278af6caaf10aea03fd8d33a09a777ca52d62f
177177
with:
178178
subject-name: ghcr.io/nhsdigital/eps-devcontainers/${{ inputs.container_name }}
179179
subject-digest: ${{ steps.resolve_githubactions_arch_digest.outputs.digest }}
@@ -214,7 +214,7 @@ jobs:
214214
ARCHITECTURE: '${{ matrix.arch }}'
215215
- name: Attest github actions latest image
216216
if: ${{ inputs.tag_latest }}
217-
uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a
217+
uses: actions/attest-build-provenance@96278af6caaf10aea03fd8d33a09a777ca52d62f
218218
with:
219219
subject-name: ghcr.io/nhsdigital/eps-devcontainers/${{ inputs.container_name }}
220220
subject-digest: ${{ steps.resolve_githubactions_latest_arch_digest.outputs.digest }}
@@ -239,7 +239,7 @@ jobs:
239239
ARCHITECTURE: '${{ matrix.arch }}'
240240
- name: Attest latest image
241241
if: ${{ inputs.tag_latest }}
242-
uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a
242+
uses: actions/attest-build-provenance@96278af6caaf10aea03fd8d33a09a777ca52d62f
243243
with:
244244
subject-name: ghcr.io/nhsdigital/eps-devcontainers/${{ inputs.container_name }}
245245
subject-digest: ${{ steps.resolve_latest_arch_digest.outputs.digest }}
@@ -334,7 +334,7 @@ jobs:
334334
CONTAINER_NAME: '${{ inputs.container_name }}'
335335

336336
- name: Attest combined image
337-
uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a
337+
uses: actions/attest-build-provenance@96278af6caaf10aea03fd8d33a09a777ca52d62f
338338
with:
339339
subject-name: ghcr.io/nhsdigital/eps-devcontainers/${{ inputs.container_name }}
340340
subject-digest: ${{ steps.resolve_combined_digest.outputs.digest }}
@@ -358,7 +358,7 @@ jobs:
358358
CONTAINER_NAME: '${{ inputs.container_name }}'
359359

360360
- name: Attest combined github actions image
361-
uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a
361+
uses: actions/attest-build-provenance@96278af6caaf10aea03fd8d33a09a777ca52d62f
362362
with:
363363
subject-name: ghcr.io/nhsdigital/eps-devcontainers/${{ inputs.container_name }}
364364
subject-digest: ${{ steps.resolve_githubactions_combined_digest.outputs.digest }}
@@ -383,7 +383,7 @@ jobs:
383383

384384
- name: Attest latest github actions image
385385
if: ${{ inputs.tag_latest }}
386-
uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a
386+
uses: actions/attest-build-provenance@96278af6caaf10aea03fd8d33a09a777ca52d62f
387387
with:
388388
subject-name: ghcr.io/nhsdigital/eps-devcontainers/${{ inputs.container_name }}
389389
subject-digest: ${{ steps.resolve_githubactions_latest_digest.outputs.digest }}
@@ -408,7 +408,7 @@ jobs:
408408

409409
- name: Attest latest image
410410
if: ${{ inputs.tag_latest }}
411-
uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a
411+
uses: actions/attest-build-provenance@96278af6caaf10aea03fd8d33a09a777ca52d62f
412412
with:
413413
subject-name: ghcr.io/nhsdigital/eps-devcontainers/${{ inputs.container_name }}
414414
subject-digest: ${{ steps.resolve_latest_digest.outputs.digest }}

0 commit comments

Comments
 (0)