File tree Expand file tree Collapse file tree 5 files changed +7
-7
lines changed Expand file tree Collapse file tree 5 files changed +7
-7
lines changed Original file line number Diff line number Diff line change 6565 buildah manifest push --format v2s2 --all curl-base-multi:$REL "docker://ghcr.io/curl/curl-container/curl-base-multi:${REL}"
6666 name: 'push images to github registry'
6767 - name : Install Cosign
68- uses : sigstore/cosign-installer@d7543c93d881b35a8faa02e8e3605f69b7a1ce62 # v3.10 .0
68+ uses : sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0 .0
6969 - name : Write signing key to disk (only needed for `cosign sign --key`)
7070 run : echo "${{ secrets.COSIGN_PRIVATE_KEY }}" > cosign.key
7171 - name : Sign images with sigstore key
Original file line number Diff line number Diff line change 6060 buildah push curl:master "docker://ghcr.io/curl/curl-container/curl:master"
6161 name: 'push images to github registry'
6262 - name : Install Cosign
63- uses : sigstore/cosign-installer@d7543c93d881b35a8faa02e8e3605f69b7a1ce62 # v3.10 .0
63+ uses : sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0 .0
6464 - name : Write signing key to disk (only needed for `cosign sign --key`)
6565 run : echo "${{ secrets.COSIGN_PRIVATE_KEY }}" > cosign.key
6666 - name : Sign image with a key
Original file line number Diff line number Diff line change 5757 buildah push curl-dev-debian:master "docker://ghcr.io/curl/curl-container/curl-dev-debian:master"
5858 name: 'push images to github registry'
5959 - name : Install Cosign
60- uses : sigstore/cosign-installer@d7543c93d881b35a8faa02e8e3605f69b7a1ce62 # v3.10 .0
60+ uses : sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0 .0
6161 - name : Write signing key to disk (only needed for `cosign sign --key`)
6262 run : echo "${{ secrets.COSIGN_PRIVATE_KEY }}" > cosign.key
6363 - name : Sign image with a key
7878 buildah push curl-dev-fedora:master "docker://ghcr.io/curl/curl-container/curl-dev-fedora:master"
7979 name: 'push images to github registry'
8080 - name : Install Cosign
81- uses : sigstore/cosign-installer@d7543c93d881b35a8faa02e8e3605f69b7a1ce62 # v3.10 .0
81+ uses : sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0 .0
8282 - name : Write signing key to disk (only needed for `cosign sign --key`)
8383 run : echo "${{ secrets.COSIGN_PRIVATE_KEY }}" > cosign.key
8484 - name : Sign image with a key
Original file line number Diff line number Diff line change 5959 buildah manifest push --all --format v2s2 localhost/curl-multi:master "docker://ghcr.io/curl/curl-container/curl-multi:master"
6060 name: 'push multi images to github registry'
6161 - name : Install Cosign
62- uses : sigstore/cosign-installer@d7543c93d881b35a8faa02e8e3605f69b7a1ce62 # v3.10 .0
62+ uses : sigstore/cosign-installer@faadad0cce49287aee09b3a48701e75088a2c6ad # v4.0 .0
6363 - name : Write signing key to disk (only needed for `cosign sign --key`)
6464 run : echo "${{ secrets.COSIGN_PRIVATE_KEY }}" > cosign.key
6565 - name : Sign image with a key
Original file line number Diff line number Diff line change @@ -27,10 +27,10 @@ jobs:
2727 persist-credentials : false
2828
2929 - name : ' initialize'
30- uses : github/codeql-action/init@3599b3baa15b485a2e49ef411a7a4bb2452e7f93 # v3.30.5
30+ uses : github/codeql-action/init@0499de31b99561a6d14a36a5f662c2a54f91beee # v4.31.2
3131 with :
3232 languages : actions, python
3333 queries : security-extended
3434
3535 - name : ' perform analysis'
36- uses : github/codeql-action/analyze@3599b3baa15b485a2e49ef411a7a4bb2452e7f93 # v3.30.5
36+ uses : github/codeql-action/analyze@0499de31b99561a6d14a36a5f662c2a54f91beee # v4.31.2
You can’t perform that action at this time.
0 commit comments