From 8aadd8e54171fc0feee934553326c5f38c36d1dd Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sun, 28 Apr 2024 19:50:50 +0000 Subject: [PATCH 1/2] Bump slsa-framework/slsa-github-generator from 1.10.0 to 2.0.0 Bumps [slsa-framework/slsa-github-generator](https://github.com/slsa-framework/slsa-github-generator) from 1.10.0 to 2.0.0. - [Release notes](https://github.com/slsa-framework/slsa-github-generator/releases) - [Changelog](https://github.com/slsa-framework/slsa-github-generator/blob/main/CHANGELOG.md) - [Commits](https://github.com/slsa-framework/slsa-github-generator/compare/v1.10.0...v2.0.0) --- updated-dependencies: - dependency-name: slsa-framework/slsa-github-generator dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .github/workflows/release.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index da7bad1c..0986ed4b 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -65,7 +65,7 @@ jobs: actions: read id-token: write contents: write # https://github.com/slsa-framework/slsa-github-generator/issues/2044 :( - uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v1.10.0 + uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v2.0.0 with: base64-subjects: "${{ needs.ci.outputs.hashes }}" upload-assets: false From 59a14dbd88080d018c464a3cce6c2cd49b60f70c Mon Sep 17 00:00:00 2001 From: Matthias Valvekens Date: Sun, 28 Apr 2024 23:18:42 +0200 Subject: [PATCH 2/2] Bump upload-artifact in SLSA job --- .github/workflows/release.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 0986ed4b..fcb93fa1 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -88,7 +88,7 @@ jobs: name: pyhanko-dist path: dist/ - name: Download provenance data - uses: actions/download-artifact@v3 + uses: actions/download-artifact@v4 with: name: multiple.intoto.jsonl path: provenance/