chore(deps): update slsa-framework/slsa-github-generator action to v2.1.0
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| slsa-framework/slsa-github-generator | action | minor | v2.0.0 -> v2.1.0 |
Release Notes
slsa-framework/slsa-github-generator (slsa-framework/slsa-github-generator)
v2.1.0
v2.1.0: Sigstore Bundles for Generic Generator and Go Builder
The workflows generator_generic_slsa3.yml and builder_go_slsa3.yml
have been updated to produce signed Sigstore Bundles, just like all the other builders
that use the BYOB framework.
The workflow logs will now print a LogIndex, rather than a LogUUID. Both are equally searchanble on https://search.sigstore.dev/.
v2.1.0: Vars context recorded in provenance
-
Updated: GitHub
varscontext is now recorded in provenance for the generic and container generators. Thevarscontext cannot affect the build in the Go builder so it is not recorded.
Configuration
📅 Schedule: Branch creation - "after 10pm" in timezone Europe/Prague, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
- [ ] If you want to rebase/retry this PR, check this box
This PR was generated by Mend Renovate. View the repository job log.
Quality Gate passed
Issues
0 New issues
0 Accepted issues
Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code