build(deps): bump actions/attest from 4.2.0 to 4.2.2 - #218
build(deps): bump actions/attest from 4.2.0 to 4.2.2#218dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [actions/attest](https://github.com/actions/attest) from 4.2.0 to 4.2.2. - [Release notes](https://github.com/actions/attest/releases) - [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md) - [Commits](actions/attest@f7c74d2...1e69f48) --- updated-dependencies: - dependency-name: actions/attest dependency-version: 4.2.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits. |
Code Review BotNo comment/code divergences or documentation drift detected. Reviewed 1 file(s); skipped 0. |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/arkorThe overall coverage in commit 92873ec in the TypeScript / code-coverage/create-arkorThe overall coverage in commit 92873ec in the TypeScript / code-coverage/cli-internalThe overall coverage in commit 92873ec in the TypeScript / code-coverage/studio-appThe overall coverage in commit 92873ec in the Updated |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Bumps actions/attest from 4.2.0 to 4.2.2.
Release notes
Sourced from actions/attest's releases.
Commits
1e69f48Bump ip-address from 10.2.0 to 10.4.0 (#467)02787ceBump brace-expansion (#468)98ac037bump@sigstore/ocifrom 0.7.1 to 0.7.2 (#469)508db95fix: strip OCI image tag when pushing attestation to registry (#464)dda48f2Bump the npm-development group across 1 directory with 6 updates (#461)7d789a3Bump the actions-minor group with 3 updates (#463)1f3ca2fAdd release-cutter canvas extension (#454)d215549Bump tar from 7.5.17 to 7.5.21 (#459)20c90edBump the npm-development group with 2 updates (#455)43c2c81Bump the actions-minor group with 4 updates (#456)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Summary by cubic
Bump
actions/attestfrom 4.2.0 to 4.2.2 in.github/workflows/build.yamlto pick up upstream fixes and dependency updates. Improves reliability when generating attestations for release tarballs and SBOMs.Written for commit 92873ec. Summary will update on new commits.