Skip to content

Commit 46fcb4f

Browse files
chore(deps): bump slsa-framework/slsa-github-generator from 2.0.0 to 2.1.0 (#23166) (#24471)
Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent 60b8d49 commit 46fcb4f

File tree

2 files changed

+18
-18
lines changed

2 files changed

+18
-18
lines changed

.github/workflows/image.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,7 @@ jobs:
8686
packages: write # for uploading attestations. (https://github.com/slsa-framework/slsa-github-generator/blob/main/internal/builders/container/README.md#known-issues)
8787
if: ${{ github.repository == 'argoproj/argo-cd' && github.event_name == 'push' }}
8888
# Must be refernced by a tag. https://github.com/slsa-framework/slsa-github-generator/blob/main/internal/builders/container/README.md#referencing-the-slsa-generator
89-
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_container_slsa3.yml@v2.0.0
89+
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_container_slsa3.yml@v2.1.0
9090
with:
9191
image: ghcr.io/argoproj/argo-cd/argocd
9292
digest: ${{ needs.build-and-publish.outputs.image-digest }}

.github/workflows/release.yaml

Lines changed: 17 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -31,20 +31,20 @@ jobs:
3131
quay_password: ${{ secrets.RELEASE_QUAY_TOKEN }}
3232

3333
argocd-image-provenance:
34-
needs: [argocd-image]
35-
permissions:
36-
actions: read # for detecting the Github Actions environment.
37-
id-token: write # for creating OIDC tokens for signing.
38-
packages: write # for uploading attestations. (https://github.com/slsa-framework/slsa-github-generator/blob/main/internal/builders/container/README.md#known-issues)
39-
# Must be refernced by a tag. https://github.com/slsa-framework/slsa-github-generator/blob/main/internal/builders/container/README.md#referencing-the-slsa-generator
40-
if: github.repository == 'argoproj/argo-cd'
41-
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_container_slsa3.yml@v2.0.0
42-
with:
43-
image: quay.io/argoproj/argocd
44-
digest: ${{ needs.argocd-image.outputs.image-digest }}
45-
secrets:
46-
registry-username: ${{ secrets.RELEASE_QUAY_USERNAME }}
47-
registry-password: ${{ secrets.RELEASE_QUAY_TOKEN }}
34+
needs: [argocd-image]
35+
permissions:
36+
actions: read # for detecting the Github Actions environment.
37+
id-token: write # for creating OIDC tokens for signing.
38+
packages: write # for uploading attestations. (https://github.com/slsa-framework/slsa-github-generator/blob/main/internal/builders/container/README.md#known-issues)
39+
# Must be refernced by a tag. https://github.com/slsa-framework/slsa-github-generator/blob/main/internal/builders/container/README.md#referencing-the-slsa-generator
40+
if: github.repository == 'argoproj/argo-cd'
41+
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_container_slsa3.yml@v2.1.0
42+
with:
43+
image: quay.io/argoproj/argocd
44+
digest: ${{ needs.argocd-image.outputs.image-digest }}
45+
secrets:
46+
registry-username: ${{ secrets.RELEASE_QUAY_USERNAME }}
47+
registry-password: ${{ secrets.RELEASE_QUAY_TOKEN }}
4848

4949
goreleaser:
5050
needs:
@@ -128,7 +128,7 @@ jobs:
128128
contents: write # Needed for release uploads
129129
if: github.repository == 'argoproj/argo-cd'
130130
# Must be refernced by a tag. https://github.com/slsa-framework/slsa-github-generator/blob/main/internal/builders/container/README.md#referencing-the-slsa-generator
131-
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v2.0.0
131+
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v2.1.0
132132
with:
133133
base64-subjects: "${{ needs.goreleaser.outputs.hashes }}"
134134
provenance-name: "argocd-cli.intoto.jsonl"
@@ -211,8 +211,8 @@ jobs:
211211
id-token: write # Needed for provenance signing and ID
212212
contents: write # Needed for release uploads
213213
if: github.repository == 'argoproj/argo-cd'
214-
# Must be refernced by a tag. https://github.com/slsa-framework/slsa-github-generator/blob/main/internal/builders/container/README.md#referencing-the-slsa-generator
215-
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v2.0.0
214+
# Must be referenced by a tag. https://github.com/slsa-framework/slsa-github-generator/blob/main/internal/builders/container/README.md#referencing-the-slsa-generator
215+
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v2.1.0
216216
with:
217217
base64-subjects: "${{ needs.generate-sbom.outputs.hashes }}"
218218
provenance-name: "argocd-sbom.intoto.jsonl"

0 commit comments

Comments
 (0)