Merge pull request #10056 from cli/dependabot/github_actions/actions/attest-build-provenance-2.1.0

Bump actions/attest-build-provenance from 1.4.4 to 2.1.0
This commit is contained in:
William Martin 2024-12-12 13:39:44 +01:00 committed by GitHub
commit a6dc0f2d8a
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -299,7 +299,7 @@ jobs:
rpmsign --addsign dist/*.rpm
- name: Attest release artifacts
if: inputs.environment == 'production'
uses: actions/attest-build-provenance@ef244123eb79f2f7a7e75d99086184180e6d0018 # v1.4.4
uses: actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1.0
with:
subject-path: "dist/gh_*"
- name: Run createrepo