ci: bump actions/attest-build-provenance from 4.1.1 to 4.2.2 - #426
Conversation
|
ZETETIC-REVIEW: REQUEST_CHANGES Stakes: High by criterion (touches the release/attestation supply chain SHA↔tag correspondence (point 1, extended to Actions)
Interface-drift claim, independently re-verified (point 2)Did not take the author's "no interface change" claim on faith — diffed the actual Went one level deeper into the wrapped Blocking — branch is stale against
|
Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 4.1.1 to 4.2.2. - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](actions/attest-build-provenance@0f67c3f...4d10147) --- updated-dependencies: - dependency-name: actions/attest-build-provenance dependency-version: 4.2.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
cf8576c to
e6556b6
Compare
|
ZETETIC-REVIEW: APPROVE Move 0: no ledger applicable (pinned SHA bump for a single GitHub Action across three call sites in one workflow); no seen-defect rationalization present. Verified on head e6556b6 (merge-base with origin/main == origin/main HEAD cdf084b — branch is current):
Mergeable as-is. |
Bumps actions/attest-build-provenance from 4.1.1 to 4.2.2.
Release notes
Sourced from actions/attest-build-provenance's releases.
Commits
4d10147Bump actions/attest from 4.2.0 to 4.2.1 in the actions-minor group (#862)e3fe62eBump the actions-minor group with 2 updates (#860)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)