pin actions/attest reference by commit sha (#493)

Signed-off-by: Brian DeHamer <bdehamer@github.com>
This commit is contained in:
Brian DeHamer
2025-03-05 11:07:49 -08:00
committed by GitHub
parent bd77c07785
commit c074443f1a
+1 -1
View File
@@ -64,7 +64,7 @@ runs:
steps:
- uses: actions/attest-build-provenance/predicate@1176ef556905f349f669722abf30bce1a6e16e01 # predicate@1.1.5
id: generate-build-provenance-predicate
- uses: actions/attest@v2.2.1
- uses: actions/attest@a63cfcc7d1aab266ee064c58250cfc2c7d07bc31 # v2.2.1
id: attest
with:
subject-path: ${{ inputs.subject-path }}