Merge pull request #295 from SpudGunMan/dependabot/github_actions/actions/attest-build-provenance-4

Bump actions/attest-build-provenance from 3 to 4
This commit is contained in:
Kelly
2026-03-05 12:51:20 -08:00
committed by GitHub

View File

@@ -53,7 +53,7 @@ jobs:
# This step generates an artifact attestation for the image, which is an unforgeable statement about where and how it was built. It increases supply chain security for people who consume the image. For more information, see [Using artifact attestations to establish provenance for builds](/actions/security-guides/using-artifact-attestations-to-establish-provenance-for-builds).
- name: Generate artifact attestation
uses: actions/attest-build-provenance@v3
uses: actions/attest-build-provenance@v4
with:
subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME}}
subject-digest: ${{ steps.push.outputs.digest }}