mirror of
https://github.com/konstruktoid/hardening.git
synced 2026-04-26 17:25:52 +03:00
[PR #587] [MERGED] chore(deps): update slsa-framework/slsa-github-generator action to v2.1.0 #590
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/konstruktoid/hardening/pull/587
Author: @renovate[bot]
Created: 2/28/2025
Status: ✅ Merged
Merged: 2/28/2025
Merged by: @renovate[bot]
Base:
master← Head:renovate/slsa-framework-slsa-github-generator-2.x📝 Commits (1)
7ce6649chore(deps): update slsa-framework/slsa-github-generator action to v2.1.0📊 Changes
1 file changed (+1 additions, -1 deletions)
View changed files
📝
.github/workflows/slsa.yml(+1 -1)📄 Description
This PR contains the following updates:
v2.0.0->v2.1.0Release Notes
slsa-framework/slsa-github-generator (slsa-framework/slsa-github-generator)
v2.1.0Compare Source
v2.1.0: Sigstore Bundles for Generic Generator and Go Builder
The workflows
generator_generic_slsa3.ymlandbuilder_go_slsa3.ymlhave been updated to produce signed Sigstore Bundles, just like all the other builders
that use the BYOB framework.
The workflow logs will now print a LogIndex, rather than a LogUUID. Both are equally searchanble on
https://search.sigstore.dev/.
v2.1.0: Vars context recorded in provenance
varscontext is now recorded in provenance for the generic andcontainer generators. The
varscontext cannot affect the build in the Gobuilder so it is not recorded.
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.