diff --git a/.github/workflows/release-drafter.yml b/.github/workflows/release-drafter.yml index 37ee825..013cf11 100644 --- a/.github/workflows/release-drafter.yml +++ b/.github/workflows/release-drafter.yml @@ -22,7 +22,7 @@ jobs: with: egress-policy: audit - - uses: release-drafter/release-drafter@ed4bc48ec97379be2258e7b7ac2624a3e26ab809 # v7.4.0 + - uses: release-drafter/release-drafter@4d75298e00d9e34c483e5ff8c68d0ea1c1940c1e # v7.5.1 with: # Use the actual commit SHA (or PR head SHA on PR events). The action # default of refs/pull/N/merge is rejected by GitHub's release API diff --git a/{{cookiecutter.project_slug}}/.github/workflows/slsa-provenance.yml b/{{cookiecutter.project_slug}}/.github/workflows/slsa-provenance.yml index 01177a2..69856c0 100644 --- a/{{cookiecutter.project_slug}}/.github/workflows/slsa-provenance.yml +++ b/{{cookiecutter.project_slug}}/.github/workflows/slsa-provenance.yml @@ -89,7 +89,7 @@ jobs: retention-days: 90 - name: Generate artifact attestation - uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0 + uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1 with: subject-path: 'dist/*'