Skip to content

Commit ad13ea4

Browse files
authored
chore: Release v1.6.0-rc.2 (#2063)
#label:release v1.6.0-rc.2 --------- Signed-off-by: Ian Lewis <[email protected]>
1 parent 5902f97 commit ad13ea4

File tree

15 files changed

+56
-56
lines changed

15 files changed

+56
-56
lines changed

.github/actions/generate-builder/action.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ runs:
4848
using: "composite"
4949
steps:
5050
- name: Checkout builder repository
51-
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@main
51+
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@v1.6.0-rc.2
5252
with:
5353
repository: ${{ inputs.repository }}
5454
ref: ${{ inputs.ref }}

.github/actions/secure-download-artifact/action.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@ runs:
5858

5959
- name: Compute the hash
6060
id: compute
61-
uses: slsa-framework/slsa-github-generator/.github/actions/compute-sha256@main
61+
uses: slsa-framework/slsa-github-generator/.github/actions/compute-sha256@v1.6.0-rc.2
6262
with:
6363
path: "${{ inputs.path }}"
6464

.github/actions/secure-download-folder/action.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ runs:
1717
steps:
1818
- name: Compute a random value
1919
id: rng
20-
uses: slsa-framework/slsa-github-generator/.github/actions/rng@main
20+
uses: slsa-framework/slsa-github-generator/.github/actions/rng@v1.6.0-rc.2
2121

2222
- name: Download the artifact
2323
uses: actions/download-artifact@9bc31d5ccc31df68ecc42ccf4149144866c47d8a # v3.0.2
@@ -27,7 +27,7 @@ runs:
2727

2828
- name: Compute the hash
2929
id: compute
30-
uses: slsa-framework/slsa-github-generator/.github/actions/compute-sha256@main
30+
uses: slsa-framework/slsa-github-generator/.github/actions/compute-sha256@v1.6.0-rc.2
3131
with:
3232
path: "${{ steps.rng.outputs.random }}/folder.tgz"
3333

.github/actions/secure-upload-artifact/action.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ runs:
1818
steps:
1919
- name: Compute binary hash
2020
id: compute-digest
21-
uses: slsa-framework/slsa-github-generator/.github/actions/compute-sha256@main
21+
uses: slsa-framework/slsa-github-generator/.github/actions/compute-sha256@v1.6.0-rc.2
2222
with:
2323
path: "${{ inputs.path }}"
2424

.github/actions/secure-upload-folder/action.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@ runs:
4646
4747
- name: Upload the artifact
4848
id: upload
49-
uses: slsa-framework/slsa-github-generator/.github/actions/secure-upload-artifact@main
49+
uses: slsa-framework/slsa-github-generator/.github/actions/secure-upload-artifact@v1.6.0-rc.2
5050
with:
5151
name: "${{ inputs.name }}"
5252
path: "${{ steps.create.outputs.tarball-path }}"

.github/workflows/builder_docker-based_slsa3.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -151,7 +151,7 @@ jobs:
151151
steps:
152152
- name: Generate random 16-byte value (32-char hex encoded)
153153
id: rng
154-
uses: slsa-framework/slsa-github-generator/.github/actions/rng@main
154+
uses: slsa-framework/slsa-github-generator/.github/actions/rng@v1.6.0-rc.2
155155

156156
# This detects the repository and ref of the reusable workflow.
157157
# For pull request, this gets the referenced slsa-github-generator workflow.
@@ -166,7 +166,7 @@ jobs:
166166
steps:
167167
- name: Detect the builder ref
168168
id: detect
169-
uses: slsa-framework/slsa-github-generator/.github/actions/detect-workflow-js@main
169+
uses: slsa-framework/slsa-github-generator/.github/actions/detect-workflow-js@v1.6.0-rc.2
170170

171171
###################################################################
172172
# #
@@ -183,7 +183,7 @@ jobs:
183183
steps:
184184
- name: Generate builder binary
185185
id: generate
186-
uses: slsa-framework/slsa-github-generator/.github/actions/generate-builder@main
186+
uses: slsa-framework/slsa-github-generator/.github/actions/generate-builder@v1.6.0-rc.2
187187
with:
188188
repository: "${{ needs.detect-env.outputs.repository }}"
189189
ref: "${{ needs.detect-env.outputs.ref }}"
@@ -216,7 +216,7 @@ jobs:
216216
steps:
217217
- uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab # v3.5.2
218218
- name: Checkout builder repository
219-
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@main
219+
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@v1.6.0-rc.2
220220
with:
221221
repository: "${{ needs.detect-env.outputs.repository }}"
222222
ref: "${{ needs.detect-env.outputs.ref }}"
@@ -344,7 +344,7 @@ jobs:
344344
345345
346346
- name: Checkout builder repository
347-
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@main
347+
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@v1.6.0-rc.2
348348
with:
349349
repository: "${{ needs.detect-env.outputs.repository }}"
350350
ref: "${{ needs.detect-env.outputs.ref }}"
@@ -472,7 +472,7 @@ jobs:
472472
provenance-sha256: ${{ steps.upload-signed.outputs.sha256 }}
473473
steps:
474474
- name: Checkout builder repository
475-
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@main
475+
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@v1.6.0-rc.2
476476
with:
477477
repository: "${{ needs.detect-env.outputs.repository }}"
478478
ref: "${{ needs.detect-env.outputs.ref }}"
@@ -562,7 +562,7 @@ jobs:
562562
if: inputs.upload-assets && (startsWith(github.ref, 'refs/tags/') || inputs.upload-tag-name != '')
563563
steps:
564564
- name: Checkout builder repository
565-
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@main
565+
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@v1.6.0-rc.2
566566
with:
567567
repository: "${{ needs.detect-env.outputs.repository }}"
568568
ref: "${{ needs.detect-env.outputs.ref }}"

.github/workflows/builder_go_slsa3.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -100,7 +100,7 @@ jobs:
100100
steps:
101101
- name: Generate random 16-byte value (32-char hex encoded)
102102
id: rng
103-
uses: slsa-framework/slsa-github-generator/.github/actions/rng@main
103+
uses: slsa-framework/slsa-github-generator/.github/actions/rng@v1.6.0-rc.2
104104

105105
detect-env:
106106
outputs:
@@ -112,7 +112,7 @@ jobs:
112112
steps:
113113
- name: Detect the builder ref
114114
id: detect
115-
uses: slsa-framework/slsa-github-generator/.github/actions/detect-workflow-js@main
115+
uses: slsa-framework/slsa-github-generator/.github/actions/detect-workflow-js@v1.6.0-rc.2
116116

117117
###################################################################
118118
# #
@@ -127,7 +127,7 @@ jobs:
127127
steps:
128128
- name: Generate builder binary
129129
id: generate
130-
uses: slsa-framework/slsa-github-generator/.github/actions/generate-builder@main
130+
uses: slsa-framework/slsa-github-generator/.github/actions/generate-builder@v1.6.0-rc.2
131131
with:
132132
repository: "${{ needs.detect-env.outputs.repository }}"
133133
ref: "${{ needs.detect-env.outputs.ref }}"
@@ -161,7 +161,7 @@ jobs:
161161
needs: [builder, rng, detect-env]
162162
steps:
163163
- name: Checkout builder repository
164-
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@main
164+
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@v1.6.0-rc.2
165165
with:
166166
repository: "${{ needs.detect-env.outputs.repository }}"
167167
ref: "${{ needs.detect-env.outputs.ref }}"
@@ -207,7 +207,7 @@ jobs:
207207
needs: [builder, build-dry, rng, detect-env]
208208
steps:
209209
- name: Checkout builder repository
210-
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@main
210+
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@v1.6.0-rc.2
211211
with:
212212
repository: "${{ needs.detect-env.outputs.repository }}"
213213
ref: "${{ needs.detect-env.outputs.ref }}"
@@ -287,7 +287,7 @@ jobs:
287287
go-provenance-sha256: ${{ steps.sign-prov.outputs.signed-provenance-sha256 }}
288288
steps:
289289
- name: Checkout builder repository
290-
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@main
290+
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@v1.6.0-rc.2
291291
with:
292292
repository: "${{ needs.detect-env.outputs.repository }}"
293293
ref: "${{ needs.detect-env.outputs.ref }}"
@@ -345,7 +345,7 @@ jobs:
345345
if: inputs.upload-assets && (startsWith(github.ref, 'refs/tags/') || inputs.upload-tag-name != '')
346346
steps:
347347
- name: Checkout builder repository
348-
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@main
348+
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@v1.6.0-rc.2
349349
with:
350350
repository: "${{ needs.detect-env.outputs.repository }}"
351351
ref: "${{ needs.detect-env.outputs.ref }}"

.github/workflows/builder_nodejs_slsa3.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -93,7 +93,7 @@ jobs:
9393
steps:
9494
- name: Generate the token
9595
id: generate
96-
uses: slsa-framework/slsa-github-generator/actions/delegator/setup-token@main
96+
uses: slsa-framework/slsa-github-generator/actions/delegator/setup-token@v1.6.0-rc.2
9797
with:
9898
slsa-workflow-recipient: "delegator_lowperms-generic_slsa3.yml"
9999
slsa-rekor-log-public: ${{ inputs.rekor-log-public }}
@@ -108,7 +108,7 @@ jobs:
108108
id-token: write # For signing.
109109
contents: read # For repo checkout of private repos.
110110
actions: read # For getting workflow run on private repos.
111-
uses: slsa-framework/slsa-github-generator/.github/workflows/delegator_lowperms-generic_slsa3.yml@main
111+
uses: slsa-framework/slsa-github-generator/.github/workflows/delegator_generic_slsa3.yml@v1.6.0-rc.2
112112
with:
113113
slsa-token: ${{ needs.slsa-setup.outputs.slsa-token }}
114114

@@ -134,7 +134,7 @@ jobs:
134134
# NOTE: secure-download-artifact ensures that the downloaded file doesn't overwrite an existing file.
135135
- name: Download package
136136
id: package-download
137-
uses: slsa-framework/slsa-github-generator/.github/actions/secure-download-artifact@main
137+
uses: slsa-framework/slsa-github-generator/.github/actions/secure-download-artifact@v1.6.0-rc.2
138138
with:
139139
name: ${{ fromJSON(needs.slsa-run.outputs.build-artifacts-outputs).package-download-name }}
140140
path: ${{ fromJSON(needs.slsa-run.outputs.build-artifacts-outputs).package-filename }}

.github/workflows/delegator_generic_slsa3.yml

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -80,7 +80,7 @@ jobs:
8080
steps:
8181
- name: Generate random 16-byte value (32-char hex encoded)
8282
id: rng
83-
uses: slsa-framework/slsa-github-generator/.github/actions/rng@main
83+
uses: slsa-framework/slsa-github-generator/.github/actions/rng@v1.6.0-rc.2
8484

8585
# verify-token verifies the slsa token.
8686
verify-token:
@@ -96,15 +96,15 @@ jobs:
9696
steps:
9797
- name: Verify token
9898
id: verify
99-
uses: slsa-framework/slsa-github-generator/.github/actions/verify-token@main
99+
uses: slsa-framework/slsa-github-generator/.github/actions/verify-token@v1.6.0-rc.2
100100
with:
101101
slsa-workflow-recipient: "delegator_generic_slsa3.yml"
102102
slsa-unverified-token: ${{ inputs.slsa-token }}
103103
output-predicate: ${{ env.SLSA_PREDICATE_FILE }}
104104

105105
- name: Upload predicate
106106
id: upload
107-
uses: slsa-framework/slsa-github-generator/.github/actions/secure-upload-artifact@main
107+
uses: slsa-framework/slsa-github-generator/.github/actions/secure-upload-artifact@v1.6.0-rc.2
108108
with:
109109
name: "${{ needs.rng.outputs.value }}-${{ env.SLSA_PREDICATE_FILE }}"
110110
path: ${{ env.SLSA_PREDICATE_FILE }}
@@ -115,7 +115,7 @@ jobs:
115115
runs-on: ubuntu-latest
116116
steps:
117117
- name: Check private repos
118-
uses: slsa-framework/slsa-github-generator/.github/actions/privacy-check@main
118+
uses: slsa-framework/slsa-github-generator/.github/actions/privacy-check@v1.6.0-rc.2
119119
with:
120120
error_message: "Repository is private. The workflow has halted in order to keep the repository name from being exposed in the public transparency log. Set 'private-repository' to override."
121121
override: ${{ fromJson(needs.verify-token.outputs.slsa-verified-token).builder.rekor_log_public }}
@@ -142,7 +142,7 @@ jobs:
142142
echo "$RUNNER: $RUNNER"
143143
144144
- name: Checkout the tool repository
145-
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@main
145+
uses: slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout@v1.6.0-rc.2
146146
with:
147147
repository: ${{ needs.verify-token.outputs.tool-repository }}
148148
ref: ${{ needs.verify-token.outputs.tool-ref }}
@@ -166,7 +166,7 @@ jobs:
166166
tree
167167
168168
- name: Checkout the project repository
169-
uses: slsa-framework/slsa-github-generator/.github/actions/secure-project-checkout@main
169+
uses: slsa-framework/slsa-github-generator/.github/actions/secure-project-checkout@v1.6.0-rc.2
170170
with:
171171
fetch-depth: ${{ toJson(needs.verify-token.outputs.slsa-verified-token).source.checkout.fetch_depth }}
172172

@@ -207,7 +207,7 @@ jobs:
207207
208208
- name: Upload artifact layout file
209209
id: upload
210-
uses: slsa-framework/slsa-github-generator/.github/actions/secure-upload-artifact@main
210+
uses: slsa-framework/slsa-github-generator/.github/actions/secure-upload-artifact@v1.6.0-rc.2
211211
with:
212212
name: "${{ needs.rng.outputs.value }}-${{ env.SLSA_ARTIFACTS_FILE }}"
213213
path: "${{ env.SLSA_ARTIFACTS_FILE }}"
@@ -222,14 +222,14 @@ jobs:
222222
runs-on: ubuntu-latest
223223
steps:
224224
- name: Download the artifact layout file
225-
uses: slsa-framework/slsa-github-generator/.github/actions/secure-download-artifact@main
225+
uses: slsa-framework/slsa-github-generator/.github/actions/secure-download-artifact@v1.6.0-rc.2
226226
with:
227227
name: "${{ needs.rng.outputs.value }}-${{ env.SLSA_ARTIFACTS_FILE }}"
228228
path: "${{ env.SLSA_ARTIFACTS_FILE }}"
229229
sha256: ${{ needs.build-artifacts-ubuntu.outputs.artifacts-layout-sha256 }}
230230

231231
- name: Download the predicate file
232-
uses: slsa-framework/slsa-github-generator/.github/actions/secure-download-artifact@main
232+
uses: slsa-framework/slsa-github-generator/.github/actions/secure-download-artifact@v1.6.0-rc.2
233233
with:
234234
name: "${{ needs.rng.outputs.value }}-${{ env.SLSA_PREDICATE_FILE }}"
235235
path: ${{ env.SLSA_PREDICATE_FILE }}
@@ -259,7 +259,7 @@ jobs:
259259
260260
- name: Generate attestations
261261
id: attestations
262-
uses: slsa-framework/slsa-github-generator/.github/actions/generate-attestations@main
262+
uses: slsa-framework/slsa-github-generator/.github/actions/generate-attestations@v1.6.0-rc.2
263263
with:
264264
slsa-layout-file: ${{ env.SLSA_ARTIFACTS_FILE }}
265265
predicate-type: ${{ steps.predicate-type.outputs.predicate-type }}
@@ -268,7 +268,7 @@ jobs:
268268

269269
- name: Sign attestations
270270
id: sign
271-
uses: slsa-framework/slsa-github-generator/.github/actions/sign-attestations@main
271+
uses: slsa-framework/slsa-github-generator/.github/actions/sign-attestations@v1.6.0-rc.2
272272
with:
273273
attestations: attestations
274274
output-folder: "${{ needs.rng.outputs.value }}-slsa-attestations"

0 commit comments

Comments
 (0)