@@ -152,17 +152,17 @@ jobs:
152
152
153
153
- name : Set up Docker Buildx
154
154
id : buildx
155
- uses : docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3
155
+ uses : docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3
156
156
157
157
- name : Login to GitHub Container Registry
158
- uses : docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3 .0
158
+ uses : docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4 .0
159
159
with :
160
160
registry : " ghcr.io"
161
161
username : ${{ github.actor }}
162
162
password : ${{ secrets.GITHUB_TOKEN }}
163
163
164
164
- name : Set up Cosign
165
- uses : sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a # v3.8 .1
165
+ uses : sigstore/cosign-installer@398d4b0eeef1380460a10c8013a76f728fb906ac # v3.9 .1
166
166
167
167
- name : Clean up image tag
168
168
id : clean-image-tag
@@ -179,7 +179,7 @@ jobs:
179
179
180
180
- name : Build Docker Image
181
181
id : docker_build_image
182
- uses : docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15 .0
182
+ uses : docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18 .0
183
183
with :
184
184
context : ${{ matrix.config.folder }}
185
185
platforms : linux/amd64,linux/arm64
@@ -208,14 +208,14 @@ jobs:
208
208
${{ env.IMAGE_NAME }}@${{ env.IMAGE_DIGEST }}
209
209
210
210
- name : Generate SBOM
211
- uses : anchore/sbom-action@f325610c9f50a54015d37c8d16cb3b0e2c8f4de0 # v0.18.0
211
+ uses : anchore/sbom-action@9246b90769f852b3a8921f330c59e0b3f439d6e9 # v0.20.1
212
212
with :
213
213
image : ${{ env.IMAGE_NAME }}:${{ steps.clean-image-tag.outputs.IMAGE_TAG }}
214
214
artifact-name : sbom-${{ matrix.config.name }}
215
215
output-file : ./sbom-${{ matrix.config.name }}.spdx.json
216
216
217
217
- name : Attach SBOM to release
218
- uses : softprops/action-gh-release@c95fe1489396fe8a9eb87c0abf8aa5b2ef267fda # v2.2.1
218
+ uses : softprops/action-gh-release@72f2c25fcb47643c292f7107632f7a47c1df5cd8 # v2.3.2
219
219
with :
220
220
tag_name : ${{ matrix.config.tagName }}
221
221
files : ./sbom-${{ matrix.config.name }}.spdx.json
0 commit comments