This repository was archived by the owner on Sep 23, 2025. It is now read-only.
File tree Expand file tree Collapse file tree 13 files changed +40
-40
lines changed
Expand file tree Collapse file tree 13 files changed +40
-40
lines changed Original file line number Diff line number Diff line change @@ -36,20 +36,20 @@ jobs:
3636 steps :
3737 - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3838
39- - uses : sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da # v3.7.0
39+ - uses : sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a # v3.8.1
4040
4141 - uses : actions/setup-go@3041bf56c941b39c61721a86cd11f3bb1338122a # v5.2.0
4242 with :
4343 go-version-file : ' ./go.mod'
4444 check-latest : true
4545
4646 # will use the latest release available for ko
47- - uses : ko-build/setup-ko@3aebd0597dc1e9d1a26bcfdb7cbeb19c131d3037 # v0.7
47+ - uses : ko-build/setup-ko@d982fec422852203cfb2053a8ec6ad302280d04d # v0.8
4848
4949 - uses : chainguard-dev/actions/goimports@dacf41f3472c33979cfd49bca5b503236be57de0 # main
5050
5151 - name : Set up Cloud SDK
52- uses : google-github-actions/auth@6fc4af4b145ae7821d527454aa9bd537d1f2dc5f # v2.1.7
52+ uses : google-github-actions/auth@71f986410dfbc7added4569d411d040a91dc6935 # v2.1.8
5353 with :
5454 workload_identity_provider : ' projects/498091336538/locations/global/workloadIdentityPools/githubactions/providers/sigstore-policy-controller'
5555 service_account :
' [email protected] '
Original file line number Diff line number Diff line change 4444 uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
4545
4646 - name : Utilize Go Module Cache
47- uses : actions/cache@1bd1e32a3bdc45362d1e726936510720a7c30a57 # v4.2.0
47+ uses : actions/cache@5a3ec84eff668545956fd18022155c47e93e2684 # v4.2.3
4848 with :
4949 path : |
5050 ~/go/pkg/mod
6161
6262 # Initializes the CodeQL tools for scanning.
6363 - name : Initialize CodeQL
64- uses : github/codeql-action/init@df409f7d9260372bd5f19e5b04e83cb3c43714ae # v3.27.9
64+ uses : github/codeql-action/init@1b549b9259bda1cb5ddde3b41741a82a2d15a841 # v3.28.13
6565 with :
6666 languages : ${{ matrix.language }}
6767
7070 make policy-controller
7171
7272 - name : Perform CodeQL Analysis
73- uses : github/codeql-action/analyze@df409f7d9260372bd5f19e5b04e83cb3c43714ae # v3.27.9
73+ uses : github/codeql-action/analyze@1b549b9259bda1cb5ddde3b41741a82a2d15a841 # v3.28.13
Original file line number Diff line number Diff line change @@ -101,19 +101,19 @@ jobs:
101101 check-latest : true
102102
103103 # will use the latest release available for ko
104- - uses : ko-build/setup-ko@3aebd0597dc1e9d1a26bcfdb7cbeb19c131d3037 # v0.7
104+ - uses : ko-build/setup-ko@d982fec422852203cfb2053a8ec6ad302280d04d # v0.8
105105
106106 - uses : imranismail/setup-kustomize@2ba527d4d055ab63514ba50a99456fc35684947f # v2.1.0
107107
108108 - name : Install yq
109- uses : mikefarah/yq@4839dbbf80445070a31c7a9c1055da527db2d5ee # v4.44.6
109+ uses : mikefarah/yq@8bf425b4d1344db7cd469a8d10a390876e0c77fd # v4.45.1
110110
111111 - name : Setup mirror
112112 uses : chainguard-dev/actions/setup-mirror@main
113113 with :
114114 mirror : mirror.gcr.io
115115
116- - uses : sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da
116+ - uses : sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a
117117
118118 - name : Install cluster + sigstore
119119 uses : sigstore/scaffolding/actions/setup@main
Original file line number Diff line number Diff line change @@ -106,19 +106,19 @@ jobs:
106106 check-latest : true
107107
108108 # will use the latest release available for ko
109- - uses : ko-build/setup-ko@3aebd0597dc1e9d1a26bcfdb7cbeb19c131d3037 # v0.7
109+ - uses : ko-build/setup-ko@d982fec422852203cfb2053a8ec6ad302280d04d # v0.8
110110
111111 - uses : imranismail/setup-kustomize@2ba527d4d055ab63514ba50a99456fc35684947f # v2.1.0
112112
113113 - name : Install yq
114- uses : mikefarah/yq@4839dbbf80445070a31c7a9c1055da527db2d5ee # v4.44.6
114+ uses : mikefarah/yq@8bf425b4d1344db7cd469a8d10a390876e0c77fd # v4.45.1
115115
116116 - name : Setup mirror
117117 uses : chainguard-dev/actions/setup-mirror@main
118118 with :
119119 mirror : mirror.gcr.io
120120
121- - uses : sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da
121+ - uses : sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a
122122
123123 - name : Install cluster + sigstore
124124 uses : sigstore/scaffolding/actions/setup@main
Original file line number Diff line number Diff line change @@ -101,19 +101,19 @@ jobs:
101101 check-latest : true
102102
103103 # will use the latest release available for ko
104- - uses : ko-build/setup-ko@3aebd0597dc1e9d1a26bcfdb7cbeb19c131d3037 # v0.7
104+ - uses : ko-build/setup-ko@d982fec422852203cfb2053a8ec6ad302280d04d # v0.8
105105
106106 - uses : imranismail/setup-kustomize@2ba527d4d055ab63514ba50a99456fc35684947f # v2.1.0
107107
108108 - name : Install yq
109- uses : mikefarah/yq@4839dbbf80445070a31c7a9c1055da527db2d5ee # v4.44.6
109+ uses : mikefarah/yq@8bf425b4d1344db7cd469a8d10a390876e0c77fd # v4.45.1
110110
111111 - name : Setup mirror
112112 uses : chainguard-dev/actions/setup-mirror@main
113113 with :
114114 mirror : mirror.gcr.io
115115
116- - uses : sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da # v2
116+ - uses : sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a # v2
117117
118118 - name : Install cluster + sigstore
119119 uses : sigstore/scaffolding/actions/setup@main
Original file line number Diff line number Diff line change @@ -115,19 +115,19 @@ jobs:
115115 check-latest : true
116116
117117 # will use the latest release available for ko
118- - uses : ko-build/setup-ko@3aebd0597dc1e9d1a26bcfdb7cbeb19c131d3037 # v0.7
118+ - uses : ko-build/setup-ko@d982fec422852203cfb2053a8ec6ad302280d04d # v0.8
119119
120120 - uses : imranismail/setup-kustomize@2ba527d4d055ab63514ba50a99456fc35684947f # v2.1.0
121121
122122 - name : Install yq
123- uses : mikefarah/yq@4839dbbf80445070a31c7a9c1055da527db2d5ee # v4.44.6
123+ uses : mikefarah/yq@8bf425b4d1344db7cd469a8d10a390876e0c77fd # v4.45.1
124124
125125 - name : Setup mirror
126126 uses : chainguard-dev/actions/setup-mirror@main
127127 with :
128128 mirror : mirror.gcr.io
129129
130- - uses : sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da
130+ - uses : sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a
131131
132132 - name : Install cluster + sigstore
133133 uses : sigstore/scaffolding/actions/setup@main
Original file line number Diff line number Diff line change @@ -98,14 +98,14 @@ jobs:
9898 go-version-file : ' ./go.mod'
9999 check-latest : true
100100
101- - uses : ko-build/setup-ko@3aebd0597dc1e9d1a26bcfdb7cbeb19c131d3037 # v0.7
101+ - uses : ko-build/setup-ko@d982fec422852203cfb2053a8ec6ad302280d04d # v0.8
102102
103103 - uses : imranismail/setup-kustomize@2ba527d4d055ab63514ba50a99456fc35684947f # v2.1.0
104104
105105 - name : Install yq
106- uses : mikefarah/yq@4839dbbf80445070a31c7a9c1055da527db2d5ee # v4.44.6
106+ uses : mikefarah/yq@8bf425b4d1344db7cd469a8d10a390876e0c77fd # v4.45.1
107107
108- - uses : sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da
108+ - uses : sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a
109109
110110 - name : Setup mirror
111111 uses : chainguard-dev/actions/setup-mirror@main
Original file line number Diff line number Diff line change @@ -98,14 +98,14 @@ jobs:
9898 go-version-file : ' ./go.mod'
9999 check-latest : true
100100
101- - uses : ko-build/setup-ko@3aebd0597dc1e9d1a26bcfdb7cbeb19c131d3037 # v0.7
101+ - uses : ko-build/setup-ko@d982fec422852203cfb2053a8ec6ad302280d04d # v0.8
102102
103103 - uses : imranismail/setup-kustomize@2ba527d4d055ab63514ba50a99456fc35684947f # v2.1.0
104104
105105 - name : Install yq
106- uses : mikefarah/yq@4839dbbf80445070a31c7a9c1055da527db2d5ee # v4.44.6
106+ uses : mikefarah/yq@8bf425b4d1344db7cd469a8d10a390876e0c77fd # v4.45.1
107107
108- - uses : sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da
108+ - uses : sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a
109109
110110 - name : Setup mirror
111111 uses : chainguard-dev/actions/setup-mirror@main
Original file line number Diff line number Diff line change 4949 run : |
5050 make policy-tester
5151
52- - uses : sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da
52+ - uses : sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a
5353
5454 - name : Setup local registry
5555 run : |
Original file line number Diff line number Diff line change 2727 go-version-file : ' ./go.mod'
2828 check-latest : true
2929
30- - uses : anchore/sbom-action/download-syft@df80a981bc6edbc4e220a492d3cbe9f5547a6e75 # v0.17.9
30+ - uses : anchore/sbom-action/download-syft@f325610c9f50a54015d37c8d16cb3b0e2c8f4de0 # v0.18.0
3131
32- - uses : ko-build/setup-ko@3aebd0597dc1e9d1a26bcfdb7cbeb19c131d3037 # v0.7
32+ - uses : ko-build/setup-ko@d982fec422852203cfb2053a8ec6ad302280d04d # v0.8
3333
3434 - name : Set LDFLAGS
3535 id : ldflags
4040
4141 - name : Run GoReleaser
4242 id : run-goreleaser
43- uses : goreleaser/goreleaser-action@9ed2f89a662bf1735a48bc8557fd212fa902bebf # v6.1 .0
43+ uses : goreleaser/goreleaser-action@9c156ee8a17a598857849441385a2041ef570552 # v6.3 .0
4444 with :
4545 version : latest
4646 args : release --snapshot --clean --timeout 120m --skip=sign
You can’t perform that action at this time.
0 commit comments