cli icon indicating copy to clipboard operation
cli copied to clipboard

Missing archive GH artifact attestations

Open scop opened this issue 10 months ago • 0 comments

https://github.com/dependabot/cli/attestations has attestations only for executables within archives, even though the intent in the workflow seems to be to provide them for archives, too: https://github.com/dependabot/cli/blob/f12cbee98c99f7557af95e201632c2ec11081cf8/.github/workflows/release.yml#L40-L45

Maybe the archive artifact names in subject-path are not correct?

scop avatar Apr 28 '25 18:04 scop