8787 type=ref,event=branch
8888 -
8989 name : Set up QEMU
90- uses : docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3
90+ uses : docker/setup-qemu-action@53851d14592bedcffcf25ea515637cff71ef929a # v3
9191 -
9292 name : Set up Docker Buildx
9393 uses : docker/setup-buildx-action@6524bf65af31da8d45b59e8c27de4bd072b392f5 # v3
@@ -106,7 +106,7 @@ jobs:
106106 password : ${{ secrets.GITHUB_TOKEN }}
107107 -
108108 name : Build and push
109- uses : docker/build-push-action@48aba3b46d1b1fec4febb7c5d0c644b249a11355 # v6
109+ uses : docker/build-push-action@ca877d9245402d1537745e0e356eab47c3520991 # v6
110110 id : build-and-push
111111 with :
112112 context : athenapdf-service
@@ -115,26 +115,26 @@ jobs:
115115 tags : ${{ steps.meta.outputs.tags }}
116116 labels : ${{ steps.meta.outputs.labels }}
117117 - name : Attest dockerhub image
118- uses : actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1 .0
118+ uses : actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2 .0
119119 with :
120120 subject-digest : ${{steps.build-and-push.outputs.digest}}
121121 subject-name : index.docker.io/${{ github.repository_owner }}/athenapdf-service
122122 push-to-registry : true
123123 - name : Attest ghcr image
124- uses : actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1 .0
124+ uses : actions/attest-build-provenance@520d128f165991a6c774bcb264f323e3d70747f4 # v2.2 .0
125125 with :
126126 subject-digest : ${{steps.build-and-push.outputs.digest}}
127127 subject-name : ghcr.io/${{ github.repository_owner }}/athenapdf-service
128128 push-to-registry : true
129- - uses : anchore/sbom-action@df80a981bc6edbc4e220a492d3cbe9f5547a6e75 # v0.17.9
129+ - uses : anchore/sbom-action@f325610c9f50a54015d37c8d16cb3b0e2c8f4de0 # v0.18.0
130130 if : startsWith(github.ref, 'refs/tags/')
131131 with :
132132 image : ghcr.io/${{ github.repository_owner }}/athenapdf-service@${{steps.build-and-push.outputs.digest}}
133133 output-file : sbom.spdx.json
134134 upload-artifact : false
135135 upload-release-assets : false
136136 - name : Release
137- uses : softprops/action-gh-release@e7a8f85e1c67a31e6ed99a94b41bd0b71bbee6b8 # v2
137+ uses : softprops/action-gh-release@c95fe1489396fe8a9eb87c0abf8aa5b2ef267fda # v2
138138 if : startsWith(github.ref, 'refs/tags/')
139139 with :
140140 files : |
0 commit comments