File tree Expand file tree Collapse file tree 1 file changed +3
-3
lines changed Expand file tree Collapse file tree 1 file changed +3
-3
lines changed Original file line number Diff line number Diff line change 37
37
output : ' trivy-results.sarif'
38
38
severity : ' CRITICAL,HIGH'
39
39
- name : Install Cosign
40
- uses : sigstore/cosign-installer@6e04d228eb30da1757ee4e1dd75a0ec73a653e06 # v3.1.1
40
+ uses : sigstore/cosign-installer@1fc5bd396d372bee37d608f955b336615edf79c8 # v3.2.0
41
41
- name : Publish image
42
42
id : publish-kyverno-notation-aws
43
43
uses : ./.github/actions/publish-image
62
62
packages : write # To upload assets to release.
63
63
actions : read # To read the workflow path.
64
64
# NOTE: The container generator workflow is not officially released as GA.
65
- uses : slsa-framework/slsa-github-generator/.github/workflows/generator_container_slsa3.yml@v1.7 .0
65
+ uses : slsa-framework/slsa-github-generator/.github/workflows/generator_container_slsa3.yml@v1.9 .0
66
66
with :
67
67
image : ghcr.io/${{ github.repository_owner }}/kyverno-notation-aws
68
68
digest : " ${{ needs.publish-images.outputs.image-digest }}"
82
82
uses : actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
83
83
- uses : creekorful/goreportcard-action@1f35ced8cdac2cba28c9a2f2288a16aacfd507f9 # v1.0
84
84
- name : Install Cosign
85
- uses : sigstore/cosign-installer@6e04d228eb30da1757ee4e1dd75a0ec73a653e06 # v3.1.1
85
+ uses : sigstore/cosign-installer@1fc5bd396d372bee37d608f955b336615edf79c8 # v3.2.0
86
86
- name : Run GoReleaser
87
87
uses : goreleaser/goreleaser-action@336e29918d653399e599bfca99fadc1d7ffbc9f7 # v4.3.0
88
88
with :
You can’t perform that action at this time.
0 commit comments