diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 38a2f02..ba72d2c 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -43,13 +43,13 @@ jobs: - name: 'upload artifacts' id: upload - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0 + uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 with: name: artifacts path: target/assemble/* - name: 'attest artifacts' - uses: actions/attest-build-provenance@96278af6caaf10aea03fd8d33a09a777ca52d62f # v3.2.0 + uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0 with: subject-name: artifacts.zip subject-digest: "sha256:${{ steps.upload.outputs.artifact-digest }}" diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 929c98a..76cb95a 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -42,7 +42,7 @@ jobs: run: ./hack/assemble.sh - name: 'attest release artifacts' - uses: actions/attest-build-provenance@96278af6caaf10aea03fd8d33a09a777ca52d62f # v3.2.0 + uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0 with: subject-path: target/assemble/*