deps: ci: bump actions/attest-build-provenance from 2 to 4
- Dominant language
- Shell
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
## Dependabot Update
Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 2 to 4.
Release notes
Sourced from actions/attest-build-provenance's releases.
v4.0.0
[!NOTE]
As of version 4,actions/attest-build-provenanceis simply a wrapper on top ofactions/attest.Existing applications may continue to use the
attest-build-provenanceaction, but new implementations should useactions/attestinstead.What's Changed
- Prepare v4 release by
@bdehamerin actions/attest-build-provenance#835Full Changelog: https://github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0
v3.2.0
What's Changed
- Bump
@actions/corefrom 1.11.1 to 2.0.1 by@dependabot[bot] in actions/attest-build-provenance#776- Add more documentation on Artifact Metadata Storage Records by
@malancasin actions/attest-build-provenance#797- Update actions/attest to latest version v3.2.0 by
@malancasin actions/attest-build-provenance#812Full Changelog: https://github.com/actions/attest-build-provenance/compare/v3.1.0...v3.2.0
v3.1.0
What's Changed
- Prepare v3 release by
@bdehamerin actions/attest-build-provenance#697- Bump js-yaml from 3.14.1 to 3.14.2 by
@dependabot[bot] in actions/attest-build-provenance#749- Bump tar from 7.5.1 to 7.5.2 by
@dependabot[bot] in actions/attest-build-provenance#753- Bump glob from 10.4.5 to 10.5.0 by
@dependabot[bot] in actions/attest-build-provenance#754- Bump
@types/nodefrom 24.10.1 to 25.0.2 by@dependabot[bot] in actions/attest-build-provenance#774- Bump
@actions/attestfrom 1.6.0 to 2.0.0 by@dependabot[bot] in actions/attest-build-provenance#736- Bump
@actions/attestfrom 2.0.0 to 2.1.0 by@dependabot[bot] in actions/attest-build-provenance#775- Add support for creating artifact metadata storage records by
@malancasin actions/attest-build-provenance#779New Contributors
@malancasmade their first contribution in actions/attest-build-provenance#779Full Changelog: https://github.com/actions/attest-build-provenance/compare/v3...v3.1.0
v3.0.0
What's Changed
- Adjust node max-http-header-size setting by
@bdehamerin actions/attest-build-provenance#687- Bump actions/attest from v2.4.0 to v3.0.0 by
@bdehamerin actions/attest-build-provenance#691
- Bump to node24 runtime
- Improved checksum parsing
- Bump attest-build-provenance/predicate to v2.0.0 by
@bdehamerin actions/attest-build-provenance#693
- Bump to node24 runtime by
@bdehamerin actions/attest-build-provenance#692⚠️ Minimum Compatible Runner Version
v2.327.1
Release NotesMake sure your runner is updated to this version or newer to use this release.
... (truncated)
Commits
a2bbfa2bump actions/attest from 4.0.0 to 4.1.0 (#838)0856891update RELEASE.md docs (#836)e4d4f7cprepare v4 release (#835)02a49bdBump github/codeql-action in the actions-minor group (#824)7c757dfBump the npm-development group with 2 updates (#825)c44148eBump github/codeql-action in the actions-minor group (#818)3234352Bump@types/nodefrom 25.0.10 to 25.2.0 in the npm-development group (#819)18db129Bump tar from 7.5.6 to 7.5.7 (#816)90fadfaBump@actions/corefrom 2.0.1 to 2.0.2 in the npm-production group (#799)57db8baBump the npm-development group across 1 directory with 3 updates (#808)- Additional commits viewable in compare view
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
## Pull Request
- PR: #61
- Author: @dependabot[bot]
- URL: https://github.com/aRustyDev/gh/pull/61
---
This issue was automatically created to track the Dependabot update.
Contributor guide
Assessment
This issue has not been assessed yet.