[PR #399] [MERGED] Bump slsa-framework/slsa-github-generator from 1.9.0 to 1.9.1 #410

Closed
opened 2026-03-03 14:31:03 +03:00 by kerem · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/konstruktoid/hardening/pull/399
Author: @dependabot[bot]
Created: 3/21/2024
Status: Merged
Merged: 3/21/2024
Merged by: @konstruktoid

Base: masterHead: dependabot/github_actions/slsa-framework/slsa-github-generator-1.9.1


📝 Commits (1)

  • 5d30e0b Bump slsa-framework/slsa-github-generator from 1.9.0 to 1.9.1

📊 Changes

1 file changed (+1 additions, -1 deletions)

View changed files

📝 .github/workflows/slsa.yml (+1 -1)

📄 Description

Bumps slsa-framework/slsa-github-generator from 1.9.0 to 1.9.1.

Release notes

Sourced from slsa-framework/slsa-github-generator's releases.

v1.9.1-rc.0

This is an un-finalized pre-release.

See the CHANGELOG for details.

Changelog

Sourced from slsa-framework/slsa-github-generator's changelog.

CHANGELOG

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/konstruktoid/hardening/pull/399 **Author:** [@dependabot[bot]](https://github.com/apps/dependabot) **Created:** 3/21/2024 **Status:** ✅ Merged **Merged:** 3/21/2024 **Merged by:** [@konstruktoid](https://github.com/konstruktoid) **Base:** `master` ← **Head:** `dependabot/github_actions/slsa-framework/slsa-github-generator-1.9.1` --- ### 📝 Commits (1) - [`5d30e0b`](https://github.com/konstruktoid/hardening/commit/5d30e0be7af820a04ce6449b2a0f1fa23e080b74) Bump slsa-framework/slsa-github-generator from 1.9.0 to 1.9.1 ### 📊 Changes **1 file changed** (+1 additions, -1 deletions) <details> <summary>View changed files</summary> 📝 `.github/workflows/slsa.yml` (+1 -1) </details> ### 📄 Description Bumps [slsa-framework/slsa-github-generator](https://github.com/slsa-framework/slsa-github-generator) from 1.9.0 to 1.9.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/slsa-framework/slsa-github-generator/releases">slsa-framework/slsa-github-generator's releases</a>.</em></p> <blockquote> <h2>v1.9.1-rc.0</h2> <p><strong>This is an un-finalized pre-release.</strong></p> <p>See the <a href="https://github.com/slsa-framework/slsa-github-generator/blob/HEAD/CHANGELOG.md">CHANGELOG</a> for details.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/CHANGELOG.md">slsa-framework/slsa-github-generator's changelog</a>.</em></p> <blockquote> <h1>CHANGELOG</h1> <p>All notable changes to this project will be documented in this file.</p> <p>The format is based on <a href="https://keepachangelog.com/en/1.0.0/">Keep a Changelog</a>, and this project adheres to <a href="https://semver.org/spec/v2.0.0.html">Semantic Versioning</a>.</p> <!-- raw HTML omitted --> <!-- raw HTML omitted --> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#unreleased">Unreleased</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#unreleased-breaking-change-attestation-name-workflow-input-and-output">Unreleased: Breaking Change: attestation-name Workflow Input and Output</a></li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#unreleased-gradle-builder">Unreleased: Gradle Builder</a></li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#unreleased-go-builder">Unreleased: Go Builder</a></li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#unreleased-container-generator">Unreleased: Container Generator</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v190">v1.9.0</a> <ul> <li><a href="#v190-byob-framework-https://github.com/slsa-framework/slsa-github-generator/blob/main/beta">v1.9.0: BYOB framework (https://github.com/slsa-framework/slsa-github-generator/blob/main/beta)</a></li> <li><a href="#v190-maven-builder-https://github.com/slsa-framework/slsa-github-generator/blob/main/beta">v1.9.0: Maven builder (https://github.com/slsa-framework/slsa-github-generator/blob/main/beta)</a></li> <li><a href="#v190-gradle-builder-https://github.com/slsa-framework/slsa-github-generator/blob/main/beta">v1.9.0: Gradle builder (https://github.com/slsa-framework/slsa-github-generator/blob/main/beta)</a></li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v190-jreleaser-builder">v1.9.0: JReleaser builder</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v180">v1.8.0</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v180-generic-generator">v1.8.0: Generic Generator</a></li> <li><a href="#v180-nodejs-builder-https://github.com/slsa-framework/slsa-github-generator/blob/main/beta">v1.8.0: Node.js Builder (https://github.com/slsa-framework/slsa-github-generator/blob/main/beta)</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v170">v1.7.0</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v170-go-builder">v1.7.0: Go builder</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v160">v1.6.0</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#summary-of-changes">Summary of changes</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#go-builder">Go builder</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#new-features">New Features</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#generic-generator">Generic generator</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#new-features-1">New Features</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#container-generator">Container generator</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#changelog-since-v150">Changelog since v1.5.0</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v150">v1.5.0</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#summary-of-changes-1">Summary of changes</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#go-builder-1">Go builder</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#new-features-2">New Features</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#generic-generator-1">Generic generator</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#new-features-3">New Features</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#container-generator-1">Container generator</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#new-features-4">New Features</a></li> </ul> </li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#changelog-since-v140">Changelog since v1.4.0</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#v140">v1.4.0</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#whats-changed">What's Changed</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#generic-generator">Generic Generator</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#bug-fixes">Bug fixes</a></li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#go-builder">Go Builder</a> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#bug-fixes-1">Bug fixes</a></li> </ul> </li> </ul> </li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/blob/main/#new-contributors">New Contributors</a></li> </ul> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/slsa-framework/slsa-github-generator/commit/a2540a194637bb64a01ab139ff74ebdcf926f4f6"><code>a2540a1</code></a> chore: Update changelog for <a href="https://redirect.github.com/slsa-framework/slsa-github-generator/issues/3350">#3350</a> (<a href="https://redirect.github.com/slsa-framework/slsa-github-generator/issues/3401">#3401</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/commit/90f2eb146c8c9600120c49cbfa442fbe4f366ab8"><code>90f2eb1</code></a> chore: Revert &quot;fix: upload-artifact and download-artifact v4&quot; (<a href="https://redirect.github.com/slsa-framework/slsa-github-generator/issues/3398">#3398</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/commit/1fee7c6fdaf1b8532bd4cad778556e42ac27affa"><code>1fee7c6</code></a> fix: Bump Cosign to latest v2.2.3 (<a href="https://redirect.github.com/slsa-framework/slsa-github-generator/issues/3355">#3355</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/commit/b595e069f78187eaead9bac15429f87237be550a"><code>b595e06</code></a> fix: upload-artifact and download-artifact v4 (<a href="https://redirect.github.com/slsa-framework/slsa-github-generator/issues/3312">#3312</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/commit/e64a21260779eaa7823fa8d393d78171e267de64"><code>e64a212</code></a> fix: remove attestation-name input and output (<a href="https://redirect.github.com/slsa-framework/slsa-github-generator/issues/3313">#3313</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/commit/a66d8c0ab4ff83f68e1a736b3665f2fb514d27b8"><code>a66d8c0</code></a> feat: Create pull_request_template.md (<a href="https://redirect.github.com/slsa-framework/slsa-github-generator/issues/3268">#3268</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/commit/5f89252a5d7fb088c3e5a547b95e8f23b55323a8"><code>5f89252</code></a> docs: Update changelog with unreleased changes (<a href="https://redirect.github.com/slsa-framework/slsa-github-generator/issues/3263">#3263</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/commit/52372c6734897f13514167d8921538225027b009"><code>52372c6</code></a> chore: Upgrade TypeScript actions to Node 20 (<a href="https://redirect.github.com/slsa-framework/slsa-github-generator/issues/3264">#3264</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/commit/b09731887a87a8df2a68da9a874464e29684d4b8"><code>b097318</code></a> fix: gradle builds (<a href="https://redirect.github.com/slsa-framework/slsa-github-generator/issues/3250">#3250</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-github-generator/commit/a39709d4088cf9e6e171466d60c0c8bbba909474"><code>a39709d</code></a> docs: Add guide for multiple operating systems (<a href="https://redirect.github.com/slsa-framework/slsa-github-generator/issues/3257">#3257</a>)</li> <li>Additional commits viewable in <a href="https://github.com/slsa-framework/slsa-github-generator/compare/v1.9.0...v1.9.1">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=slsa-framework/slsa-github-generator&package-manager=github_actions&previous-version=1.9.0&new-version=1.9.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
kerem 2026-03-03 14:31:03 +03:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/hardening#410
No description provided.