Skip to content

Commit 13c4b9b

Browse files
dependabot[bot]vszakats
authored andcommitted
GHA: bump actions
- github/codeql-action from 3.30.5 to 4.31.2 - sigstore/cosign-installer from 3.10.0 to 4.0.0 Closes #95 Closes #96
1 parent ebab46d commit 13c4b9b

File tree

5 files changed

+7
-7
lines changed

5 files changed

+7
-7
lines changed

.github/workflows/build_latest_release_multi.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -65,7 +65,7 @@ jobs:
6565
buildah manifest push --format v2s2 --all curl-base-multi:$REL "docker://ghcr.io/curl/curl-container/curl-base-multi:${REL}"
6666
name: 'push images to github registry'
6767
- name: Install Cosign
68-
uses: sigstore/cosign-installer@d7543c93d881b35a8faa02e8e3605f69b7a1ce62 # v3.10.0
68+
uses: sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0.0
6969
- name: Write signing key to disk (only needed for `cosign sign --key`)
7070
run: echo "${{ secrets.COSIGN_PRIVATE_KEY }}" > cosign.key
7171
- name: Sign images with sigstore key

.github/workflows/build_master.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,7 @@ jobs:
6060
buildah push curl:master "docker://ghcr.io/curl/curl-container/curl:master"
6161
name: 'push images to github registry'
6262
- name: Install Cosign
63-
uses: sigstore/cosign-installer@d7543c93d881b35a8faa02e8e3605f69b7a1ce62 # v3.10.0
63+
uses: sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0.0
6464
- name: Write signing key to disk (only needed for `cosign sign --key`)
6565
run: echo "${{ secrets.COSIGN_PRIVATE_KEY }}" > cosign.key
6666
- name: Sign image with a key

.github/workflows/build_master_dev.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,7 @@ jobs:
5757
buildah push curl-dev-debian:master "docker://ghcr.io/curl/curl-container/curl-dev-debian:master"
5858
name: 'push images to github registry'
5959
- name: Install Cosign
60-
uses: sigstore/cosign-installer@d7543c93d881b35a8faa02e8e3605f69b7a1ce62 # v3.10.0
60+
uses: sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0.0
6161
- name: Write signing key to disk (only needed for `cosign sign --key`)
6262
run: echo "${{ secrets.COSIGN_PRIVATE_KEY }}" > cosign.key
6363
- name: Sign image with a key
@@ -78,7 +78,7 @@ jobs:
7878
buildah push curl-dev-fedora:master "docker://ghcr.io/curl/curl-container/curl-dev-fedora:master"
7979
name: 'push images to github registry'
8080
- name: Install Cosign
81-
uses: sigstore/cosign-installer@d7543c93d881b35a8faa02e8e3605f69b7a1ce62 # v3.10.0
81+
uses: sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0.0
8282
- name: Write signing key to disk (only needed for `cosign sign --key`)
8383
run: echo "${{ secrets.COSIGN_PRIVATE_KEY }}" > cosign.key
8484
- name: Sign image with a key

.github/workflows/build_master_multi.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -59,7 +59,7 @@ jobs:
5959
buildah manifest push --all --format v2s2 localhost/curl-multi:master "docker://ghcr.io/curl/curl-container/curl-multi:master"
6060
name: 'push multi images to github registry'
6161
- name: Install Cosign
62-
uses: sigstore/cosign-installer@d7543c93d881b35a8faa02e8e3605f69b7a1ce62 # v3.10.0
62+
uses: sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0.0
6363
- name: Write signing key to disk (only needed for `cosign sign --key`)
6464
run: echo "${{ secrets.COSIGN_PRIVATE_KEY }}" > cosign.key
6565
- name: Sign image with a key

.github/workflows/codeql.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27,10 +27,10 @@ jobs:
2727
persist-credentials: false
2828

2929
- name: 'initialize'
30-
uses: github/codeql-action/init@3599b3baa15b485a2e49ef411a7a4bb2452e7f93 # v3.30.5
30+
uses: github/codeql-action/init@0499de31b99561a6d14a36a5f662c2a54f91beee # v4.31.2
3131
with:
3232
languages: actions, python
3333
queries: security-extended
3434

3535
- name: 'perform analysis'
36-
uses: github/codeql-action/analyze@3599b3baa15b485a2e49ef411a7a4bb2452e7f93 # v3.30.5
36+
uses: github/codeql-action/analyze@0499de31b99561a6d14a36a5f662c2a54f91beee # v4.31.2

0 commit comments

Comments
 (0)