Skip to content

Commit a57dbb0

Browse files
authored
Merge pull request #78 from realshuting/bump_gh_action_tools
chore: bump cosign,slsa versions in releaser
2 parents 6705906 + 364ea55 commit a57dbb0

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

.github/workflows/release.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ jobs:
3737
output: 'trivy-results.sarif'
3838
severity: 'CRITICAL,HIGH'
3939
- name: Install Cosign
40-
uses: sigstore/cosign-installer@6e04d228eb30da1757ee4e1dd75a0ec73a653e06 # v3.1.1
40+
uses: sigstore/cosign-installer@1fc5bd396d372bee37d608f955b336615edf79c8 # v3.2.0
4141
- name: Publish image
4242
id: publish-kyverno-notation-aws
4343
uses: ./.github/actions/publish-image
@@ -62,7 +62,7 @@ jobs:
6262
packages: write # To upload assets to release.
6363
actions: read # To read the workflow path.
6464
# NOTE: The container generator workflow is not officially released as GA.
65-
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_container_slsa3.yml@v1.7.0
65+
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_container_slsa3.yml@v1.9.0
6666
with:
6767
image: ghcr.io/${{ github.repository_owner }}/kyverno-notation-aws
6868
digest: "${{ needs.publish-images.outputs.image-digest }}"
@@ -82,7 +82,7 @@ jobs:
8282
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
8383
- uses: creekorful/goreportcard-action@1f35ced8cdac2cba28c9a2f2288a16aacfd507f9 # v1.0
8484
- name: Install Cosign
85-
uses: sigstore/cosign-installer@6e04d228eb30da1757ee4e1dd75a0ec73a653e06 # v3.1.1
85+
uses: sigstore/cosign-installer@1fc5bd396d372bee37d608f955b336615edf79c8 # v3.2.0
8686
- name: Run GoReleaser
8787
uses: goreleaser/goreleaser-action@336e29918d653399e599bfca99fadc1d7ffbc9f7 # v4.3.0
8888
with:

0 commit comments

Comments
 (0)