build(deps): bump the ci group with 3 updates
Bumps the ci group with 3 updates: helm/kind-action, sigstore/cosign-installer and slsa-framework/slsa-github-generator.
Updates helm/kind-action from 1.9.0 to 1.10.0
Release notes
Sourced from helm/kind-action's releases.
v1.10.0
Requirements
We changed to use
wgetinstead ofcurlWhat's Changed
- Update kind to release v0.21.0 by
@cpanatoin helm/kind-action#104- Bump actions/checkout from 4.1.1 to 4.1.2 by
@dependabotin helm/kind-action#106- Bump actions/checkout from 4.1.2 to 4.1.3 by
@dependabotin helm/kind-action#108- bump kind to 0.22.0 / kubectl and general housekeeping by
@cpanatoin helm/kind-action#107- Bump actions/checkout from 4.1.2 to 4.1.3 in the actions group by
@dependabotin helm/kind-action#109Full Changelog: https://github.com/helm/kind-action/compare/v1.9.0...v1.10.0
Commits
0025e74Bump actions/checkout from 4.1.2 to 4.1.3 in the actions group (#109)2a7d25fbump kind to 0.22.0 / kubectl and general housekeeping (#107)d821386Bump actions/checkout from 4.1.2 to 4.1.3 (#108)e89fbc4Bump actions/checkout from 4.1.1 to 4.1.2 (#106)8300bd0Update kind to release v0.21.0 (#104)- See full diff in compare view
Updates sigstore/cosign-installer from 3.4.0 to 3.5.0
Release notes
Sourced from sigstore/cosign-installer's releases.
v3.5.0
What's Changed
- Bump actions/checkout from 4.1.1 to 4.1.2 by
@dependabotin sigstore/cosign-installer#157- use go 1.22 now by
@bobcallawayin sigstore/cosign-installer#160- bump default version to v2.2.4, prep for v3.5.0 release by
@bobcallawayin sigstore/cosign-installer#159Full Changelog: https://github.com/sigstore/cosign-installer/compare/v3.4.0...v3.5.0
Commits
Updates slsa-framework/slsa-github-generator from 1.10.0 to 2.0.0
Release notes
Sourced from slsa-framework/slsa-github-generator's releases.
v2.0.0
See the CHANGELOG for details.
v2.0.0-rc.0
See the CHANGELOG for details.
Changelog
Sourced from slsa-framework/slsa-github-generator's changelog.
v2.0.0
v2.0.0: Breaking Change: upload-artifact and download-artifact
- Our workflows now use the new
@v4s ofactions/upload-artifactandactions/download-artifact, which are incompatiblle with the prior@v3. See Our docs on the generic generator for more information and how to upgrade.v2.0.0: Breaking Change: attestation-name Workflow Input and Output
attestation-nameas a workflow input to.github/workflows/generator_generic_slsa3.ymlis now removed. Useprovenance-nameinstead.v2.0.0: DSSE Rekor Type
- When uploading signed provenance to the log, the entry created in the log is now a DSSE Rekor type. This fixes a bug where the current intoto type does not persist provenance signatures. The attestation will no longer be persisted in Rekor (#3299)
Commits
5a775b3chore: v2.0.0: update tags (#3583)41733f7chore: v2.0.0-rc.0: update tags (#3578)3789345docs: v.2.0.0: finalize CHANGELOG.md (#3577)02fc78bfix: deadlock and improve debugging experience (#3570)4534a0bbreak: Revert "chore: Revert "fix: upload-artifact and download-artifact v4""...e8c2dcffix(deps): Update Sigstore Dep to Sigstore 2.2.2 (#3491)2512315feat(breaking): remove attestation-name input and output (#3456)4fbc6a9chore: add ramonpetgrave64 to CODEOWNERS (#3490)8869c8afix: Switch to newer DSSE rekor type (#3299)9d81ca7chore: Update slsa-verifier version (#3454)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) -
@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) -
@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) -
@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency -
@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions