build(deps): Bump actions/attest-build-provenance from 3 to 4#132
build(deps): Bump actions/attest-build-provenance from 3 to 4#132dependabot[bot] wants to merge 2 commits into
Conversation
890ff4b to
64d67c2
Compare
Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 3 to 4. - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](actions/attest-build-provenance@v3...v4) --- updated-dependencies: - dependency-name: actions/attest-build-provenance dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
64d67c2 to
fe7c6af
Compare
Update the release workflow assertion to match the Dependabot bump to actions/attest-build-provenance@v4.
athena-omt
left a comment
There was a problem hiding this comment.
I didn’t find a substantive blocker in the attest v4 bump itself. The workflow updates line up with the new OIDC/attestation requirements, and the test changes cover the new provenance/signing steps.
The only thing I could not fully validate locally was the Vitest run in this worker worktree, because node_modules is absent here and the test command failed before execution. That is an environment limitation, not a code finding.
Summary: the PR looks mergeable from a correctness standpoint, with the caveat that I couldn’t execute the targeted test suite in this checkout.
pheidon
left a comment
There was a problem hiding this comment.
Reviewed the Dependabot bump plus the synced workflow assertion. The patch consistently moves actions/attest-build-provenance from v3 to v4 in both release workflows and updates the release-workflow test expectation. CI, dependency review, CodeQL, OSV, and the relevant runner contracts are green. No blockers found.
Bumps actions/attest-build-provenance from 3 to 4.
Release notes
Sourced from actions/attest-build-provenance's releases.
Commits
a2bbfa2bump actions/attest from 4.0.0 to 4.1.0 (#838)0856891update RELEASE.md docs (#836)e4d4f7cprepare v4 release (#835)02a49bdBump github/codeql-action in the actions-minor group (#824)7c757dfBump the npm-development group with 2 updates (#825)c44148eBump github/codeql-action in the actions-minor group (#818)3234352Bump@types/nodefrom 25.0.10 to 25.2.0 in the npm-development group (#819)18db129Bump tar from 7.5.6 to 7.5.7 (#816)90fadfaBump@actions/corefrom 2.0.1 to 2.0.2 in the npm-production group (#799)57db8baBump the npm-development group across 1 directory with 3 updates (#808)