Skip to content

Commit e7e7339

Browse files
authored
Merge pull request #470 from atsign-foundation/dependabot/github_actions/github-actions-7b65cbaeec
build(deps): Bump the github-actions group with 3 updates
2 parents bd9b3ed + 621f039 commit e7e7339

2 files changed

Lines changed: 6 additions & 6 deletions

File tree

.github/workflows/build-publish.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@ jobs:
3939
run: |
4040
poetry build
4141
- name: Store the distribution packages
42-
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
42+
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
4343
with:
4444
name: python-package-distributions
4545
path: dist/
@@ -56,7 +56,7 @@ jobs:
5656
id-token: write # IMPORTANT: mandatory for trusted publishing
5757
steps:
5858
- name: Download all the dists
59-
uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0
59+
uses: actions/download-artifact@70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3 # v8.0.0
6060
with:
6161
name: python-package-distributions
6262
path: dist/
@@ -80,7 +80,7 @@ jobs:
8080
id-token: write # IMPORTANT: mandatory for trusted publishing
8181
steps:
8282
- name: Download all the dists
83-
uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0
83+
uses: actions/download-artifact@70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3 # v8.0.0
8484
with:
8585
name: python-package-distributions
8686
path: dist/
@@ -110,7 +110,7 @@ jobs:
110110
pyproject.toml
111111
sparse-checkout-cone-mode: false
112112
- name: Download all the dists
113-
uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0
113+
uses: actions/download-artifact@70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3 # v8.0.0
114114
with:
115115
name: python-package-distributions
116116
path: dist/
@@ -134,7 +134,7 @@ jobs:
134134
run: |
135135
echo "hashes=$(cat checksums.txt | base64 -w0)" >> "$GITHUB_OUTPUT"
136136
- name: Attest the release artifacts
137-
uses: actions/attest-build-provenance@e4d4f7c39adfa4c260fb5c147f0622000aa14b99 # v4.0.0
137+
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
138138
with:
139139
subject-path: 'dist/**'
140140
- name: Upload artifact signatures to GitHub Release

.github/workflows/scorecards.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -59,7 +59,7 @@ jobs:
5959
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
6060
# format to the repository Actions tab.
6161
- name: "Upload artifact"
62-
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
62+
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
6363
with:
6464
name: SARIF file
6565
path: results.sarif

0 commit comments

Comments
 (0)