Skip to content

Bump actions/attest-build-provenance from 3 to 4#141

Merged
JaredHatfield merged 2 commits into
mainfrom
dependabot/github_actions/actions/attest-build-provenance-4
May 25, 2026
Merged

Bump actions/attest-build-provenance from 3 to 4#141
JaredHatfield merged 2 commits into
mainfrom
dependabot/github_actions/actions/attest-build-provenance-4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Feb 28, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/attest-build-provenance from 3 to 4.

Release notes

Sourced from actions/attest-build-provenance's releases.

v4.0.0

[!NOTE] As of version 4, actions/attest-build-provenance is simply a wrapper on top of actions/attest.

Existing applications may continue to use the attest-build-provenance action, but new implementations should use actions/attest instead.

What's Changed

Full Changelog: actions/attest-build-provenance@v3.2.0...v4.0.0

v3.2.0

What's Changed

Full Changelog: actions/attest-build-provenance@v3.1.0...v3.2.0

v3.1.0

What's Changed

New Contributors

Full Changelog: actions/attest-build-provenance@v3...v3.1.0

Commits
  • a2bbfa2 bump actions/attest from 4.0.0 to 4.1.0 (#838)
  • 0856891 update RELEASE.md docs (#836)
  • e4d4f7c prepare v4 release (#835)
  • 02a49bd Bump github/codeql-action in the actions-minor group (#824)
  • 7c757df Bump the npm-development group with 2 updates (#825)
  • c44148e Bump github/codeql-action in the actions-minor group (#818)
  • 3234352 Bump @​types/node from 25.0.10 to 25.2.0 in the npm-development group (#819)
  • 18db129 Bump tar from 7.5.6 to 7.5.7 (#816)
  • 90fadfa Bump @​actions/core from 2.0.1 to 2.0.2 in the npm-production group (#799)
  • 57db8ba Bump the npm-development group across 1 directory with 3 updates (#808)
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Feb 28, 2026
Comment thread .github/workflows/release-maven-central-java-17.yml Fixed
Comment thread .github/workflows/release-maven-central-java-17.yml Fixed
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions/attest-build-provenance-4 branch from c8dedc3 to 83cb605 Compare February 28, 2026 13:08
@JaredHatfield JaredHatfield moved this from Todo to Backlog in UnitVectorY Labs Feb 28, 2026
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions/attest-build-provenance-4 branch 2 times, most recently from 5a593b5 to e902e2b Compare March 21, 2026 10:53
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions/attest-build-provenance-4 branch from e902e2b to 9aa5904 Compare March 21, 2026 12:26
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions/attest-build-provenance-4 branch from 9aa5904 to a6f720e Compare March 28, 2026 13:05
@JaredHatfield

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 3 to 4.
- [Release notes](https://github.com/actions/attest-build-provenance/releases)
- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md)
- [Commits](actions/attest-build-provenance@v3...v4)

---
updated-dependencies:
- dependency-name: actions/attest-build-provenance
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions/attest-build-provenance-4 branch from a6f720e to 2059ac6 Compare April 11, 2026 12:05
@codecov

codecov Bot commented May 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (63f1225) to head (283b948).
⚠️ Report is 13 commits behind head on main.

Additional details and impacted files
@@             Coverage Diff             @@
##                main      #141   +/-   ##
===========================================
  Coverage     100.00%   100.00%           
  Complexity        21        21           
===========================================
  Files              5         5           
  Lines             64        64           
  Branches           6         6           
===========================================
  Hits              64        64           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@JaredHatfield JaredHatfield merged commit fe7723a into main May 25, 2026
7 checks passed
@JaredHatfield JaredHatfield deleted the dependabot/github_actions/actions/attest-build-provenance-4 branch May 25, 2026 00:48
@github-project-automation github-project-automation Bot moved this from Backlog to Done in UnitVectorY Labs May 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

2 participants