Skip to content

Commit cb7f0a7

Browse files
authored
Apply suggestions from code review
Signed-off-by: William Woodruff <[email protected]>
1 parent 57006e2 commit cb7f0a7

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

.github/workflows/cross-os.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@ jobs:
4646
cache-dependency-path: pyproject.toml
4747
- run: pip install .
4848
- name: Fetch testing oidc token
49-
uses: sigstore-conformance/extremely-dangerous-public-oidc-beacon@039e3afae9c6fde85c8c6c83f8b3e634a9e9fa94 # main
49+
uses: sigstore-conformance/extremely-dangerous-public-oidc-beacon@4a8befcc16064dac9e97f210948d226e5c869bdc # v1.0.0
5050
- name: Sign
5151
run: python -m sigstore --staging sign --identity-token $(cat oidc-token.txt) test/assets/a.txt
5252
- name: upload signature bundle

.github/workflows/cross-version-verify.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ jobs:
3838
cache-dependency-path: pyproject.toml
3939
- run: pip install .
4040
- name: Fetch testing oidc token
41-
uses: sigstore-conformance/extremely-dangerous-public-oidc-beacon@039e3afae9c6fde85c8c6c83f8b3e634a9e9fa94 # main
41+
uses: sigstore-conformance/extremely-dangerous-public-oidc-beacon@4a8befcc16064dac9e97f210948d226e5c869bdc # v1.0.0
4242
- name: Sign
4343
run: |
4444
python -m sigstore --staging sign --bundle artifact-rekor2.sigstore.json --identity-token $(cat oidc-token.txt) --rekor-version=2 test/assets/a.txt

0 commit comments

Comments
 (0)