55 tags :
66 - ' v*'
77
8+ permissions : {}
9+
810jobs :
911 release :
1012 runs-on : ubuntu-latest
@@ -18,23 +20,27 @@ jobs:
1820
1921 steps :
2022 - name : Check out code
21- uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
23+ uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
24+
25+ - name : Extract version of Go to use
26+ run : echo "GOVERSION=$(awk -F'[:@]' '/FROM golang/{print $2; exit}' Dockerfile.dev)" >> $GITHUB_ENV
2227
23- - uses : actions/setup-go@3041bf56c941b39c61721a86cd11f3bb1338122a # v5.2 .0
28+ - uses : actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0 .0
2429 with :
25- go-version : ' 1.24 '
30+ go-version : ' ${{ env.GOVERSION }} '
2631 check-latest : true
32+ cache : false
2733
2834 - name : Install cosign
29- uses : sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da # v3.7 .0
35+ uses : sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0 .0
3036
3137 - name : Install GoReleaser
32- uses : goreleaser/goreleaser-action@9ed2f89a662bf1735a48bc8557fd212fa902bebf # v6.1 .0
38+ uses : goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a # v6.4 .0
3339 with :
3440 install-only : true
3541
3642 - name : Run Mage
37- uses : magefile/mage-action@6a5dcb5fe61f43d7c08a98bc3cf9bc63c308c08e # v3.0 .0
43+ uses : magefile/mage-action@6f50bbb8ea47d56e62dee92392788acbc8192d0b # v3.1 .0
3844 with :
3945 version : latest
4046 args : buildBinaries
@@ -53,20 +59,20 @@ jobs:
5359
5460 steps :
5561 - name : Check out code
56- uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
62+ uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
5763
5864 - name : Set tag output
5965 id : tag
6066 run : echo "tag_name=${GITHUB_REF#refs/*/}" >> "$GITHUB_OUTPUT"
6167
6268 - name : Install tejolote
63- uses : kubernetes-sigs/release-actions/setup-tejolote@a69972745f85aab4ba5d6c681e2a0e7f73eaff2b # v0.3 .0
69+ uses : kubernetes-sigs/release-actions/setup-tejolote@8af7b2a5596dff526de9db59b2c4b8457e9f52a1 # v0.4 .0
6470
6571 - run : |
6672 tejolote attest --artifacts github://kubernetes-sigs/bom/${{ steps.tag.outputs.tag_name }} github://kubernetes-sigs/bom/"${GITHUB_RUN_ID}" --output bom.intoto.json --sign
6773
6874 - name : Release
69- uses : softprops/action-gh-release@7b4da11513bf3f43f9999e90eabced41ab8bb048 # v0.1.15
75+ uses : softprops/action-gh-release@6da8fa9354ddfdc4aeace5fc48d7f679b5214090 # v2.4.1
7076 with :
7177 files : bom.intoto.json
7278 tag_name : " ${{ steps.tag.outputs.tag_name }}"
0 commit comments