Skip to content

Commit a865098

Browse files
chore: bump slsa-framework/slsa-github-generator from 9103ac683d00ceecdb1c21507a9c7a9983ef46f4 to a09dd8c05eda63cace134cb7dccd7e019f25e6f3 (#2758)
Bumps [slsa-framework/slsa-github-generator](https://github.com/slsa-framework/slsa-github-generator) from 9103ac683d00ceecdb1c21507a9c7a9983ef46f4 to a09dd8c05eda63cace134cb7dccd7e019f25e6f3. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/CHANGELOG.md">slsa-framework/slsa-github-generator's changelog</a>.</em></p> <blockquote> <h1>CHANGELOG</h1> <p>All notable changes to this project will be documented in this file.</p> <p>The format is based on <a href="https://keepachangelog.com/en/1.0.0/">Keep a Changelog</a>, and this project adheres to <a href="https://semver.org/spec/v2.0.0.html">Semantic Versioning</a>.</p> <!-- raw HTML omitted --> <!-- raw HTML omitted --> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v210">v2.1.0</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v210-sigstore-bundles-for-generic-generator-and-go-builder">v2.1.0: Sigstore Bundles for Generic Generator and Go Builder</a></li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v210-vars-context-recorded-in-provenance">v2.1.0: Vars context recorded in provenance</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v200">v2.0.0</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v200-breaking-change-upload-artifact-and-download-artifact">v2.0.0: Breaking Change: upload-artifact and download-artifact</a></li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v200-breaking-change-attestation-name-workflow-input-and-output">v2.0.0: Breaking Change: attestation-name Workflow Input and Output</a></li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v200-dsse-rekor-type">v2.0.0: DSSE Rekor Type</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v1100">v1.10.0</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v1100-tuf-fix">v1.10.0: TUF fix</a></li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v1100-gradle-builder">v1.10.0: Gradle Builder</a></li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v1100-go-builder">v1.10.0: Go Builder</a></li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v1100-container-generator">v1.10.0: Container Generator</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v190">v1.9.0</a> <ul> <li><a href="#v190-byob-framework-https://github.com/slsa-framework/slsa-github-generator/blob/main/beta">v1.9.0: BYOB framework (https://github.com/slsa-framework/slsa-github-generator/blob/main/beta)</a></li> <li><a href="#v190-maven-builder-https://github.com/slsa-framework/slsa-github-generator/blob/main/beta">v1.9.0: Maven builder (https://github.com/slsa-framework/slsa-github-generator/blob/main/beta)</a></li> <li><a href="#v190-gradle-builder-https://github.com/slsa-framework/slsa-github-generator/blob/main/beta">v1.9.0: Gradle builder (https://github.com/slsa-framework/slsa-github-generator/blob/main/beta)</a></li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v190-jreleaser-builder">v1.9.0: JReleaser builder</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v180">v1.8.0</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v180-generic-generator">v1.8.0: Generic Generator</a></li> <li><a href="#v180-nodejs-builder-https://github.com/slsa-framework/slsa-github-generator/blob/main/beta">v1.8.0: Node.js Builder (https://github.com/slsa-framework/slsa-github-generator/blob/main/beta)</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v170">v1.7.0</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v170-go-builder">v1.7.0: Go builder</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v160">v1.6.0</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#summary-of-changes">Summary of changes</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#go-builder">Go builder</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#new-features">New Features</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#generic-generator">Generic generator</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#new-features-1">New Features</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#container-generator">Container generator</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#changelog-since-v150">Changelog since v1.5.0</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v150">v1.5.0</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#summary-of-changes-1">Summary of changes</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#go-builder-1">Go builder</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#new-features-2">New Features</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#generic-generator-1">Generic generator</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#new-features-3">New Features</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#container-generator-1">Container generator</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#new-features-4">New Features</a></li> </ul> </li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#changelog-since-v140">Changelog since v1.4.0</a></li> </ul> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/commit/a09dd8c05eda63cace134cb7dccd7e019f25e6f3"><code>a09dd8c</code></a> chore: Update unsupported v2 of go-jose to supported v4 (<a href="https://redirect.github.com/slsa-framework/slsa-github-generator/issues/4439">#4439</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/commit/4876e96b8268fd8b7b8d8574718d06c0d0426d40"><code>4876e96</code></a> chore: slsa-verifier v2.7.1 (<a href="https://redirect.github.com/slsa-framework/slsa-github-generator/issues/4332">#4332</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/commit/a5cc0c3d94f050998a69d915ea5e5c23ca584b3e"><code>a5cc0c3</code></a> chore: Remove old TODO (<a href="https://redirect.github.com/slsa-framework/slsa-github-generator/issues/4152">#4152</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/commit/9255e11bd1ff6fa028051c099dc4549121d250d2"><code>9255e11</code></a> chore(deps): update github-actions</li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/commit/8e3df77bcdb72773b0ac7cd1e0399d714f755d81"><code>8e3df77</code></a> chore: verify SLSA token at creation</li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/commit/24e3463c4c5882ca81483811c54212c50464a629"><code>24e3463</code></a> chore(deps): update github-actions</li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/commit/0617b3a0ca3f8d593a23051911338b206901bcb9"><code>0617b3a</code></a> chore(deps): update github-actions (<a href="https://redirect.github.com/slsa-framework/slsa-github-generator/issues/4132">#4132</a>)</li> <li>See full diff in <a href="https://github.com/slsa-framework/slsa-github-generator/compare/9103ac683d00ceecdb1c21507a9c7a9983ef46f4...a09dd8c05eda63cace134cb7dccd7e019f25e6f3">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Case Wylie <[email protected]>
1 parent ba46d96 commit a865098

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

.github/workflows/release.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -139,7 +139,7 @@ jobs:
139139
140140
- name: Publish package
141141
id: publish
142-
uses: slsa-framework/slsa-github-generator/actions/nodejs/publish@9103ac683d00ceecdb1c21507a9c7a9983ef46f4 # v2.0.0
142+
uses: slsa-framework/slsa-github-generator/actions/nodejs/publish@a09dd8c05eda63cace134cb7dccd7e019f25e6f3 # v2.0.0
143143
with:
144144
access: public
145145
node-auth-token: ${{ secrets.NPM_TOKEN }}

0 commit comments

Comments
 (0)