Skip to content

[v2.3][CI] Stabilize supply-chain triggers + action versions#50

Merged
JasonEran merged 1 commit intomasterfrom
feature/v2.3
Feb 25, 2026
Merged

[v2.3][CI] Stabilize supply-chain triggers + action versions#50
JasonEran merged 1 commit intomasterfrom
feature/v2.3

Conversation

@JasonEran
Copy link
Owner

Scope

Stabilize v2.3 CI/supply-chain workflows for Epic #14.

Closes #46
Closes #47

Changes

  • Add path-filtered push/pull_request triggers to:
    • .github/workflows/supply-chain.yml
    • .github/workflows/slsa-source-provenance.yml
  • Keep workflow_dispatch for manual release builds.
  • Refresh supply-chain action versions:
    • docker/build-push-action@v6
    • anchore/sbom-action@v0.22.2
    • sigstore/cosign-installer@v4
  • Add stabilization notes: docs/CI-SupplyChain-Stabilization-v2.3.md
  • Update README/changelog/release-notes references.

Validation

Acceptance Mapping

@JasonEran JasonEran merged commit 52b6597 into master Feb 25, 2026
7 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[CI] Fix supply-chain workflows (SLSA/SBOM/Syft permissions) [CI] Restrict workflow triggers (paths filters + workflow_dispatch)

1 participant