From 3f9d4ec865aaf6be4de623233d087604e9bc59da Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 11 Apr 2026 12:05:42 +0000 Subject: [PATCH 1/2] Bump actions/attest-build-provenance from 3 to 4 Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 3 to 4. - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](https://github.com/actions/attest-build-provenance/compare/v3...v4) --- updated-dependencies: - dependency-name: actions/attest-build-provenance dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .github/workflows/release-maven-central-java-17.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/release-maven-central-java-17.yml b/.github/workflows/release-maven-central-java-17.yml index a65acaa..3860f2d 100644 --- a/.github/workflows/release-maven-central-java-17.yml +++ b/.github/workflows/release-maven-central-java-17.yml @@ -57,12 +57,12 @@ jobs: GITHUB_TOKEN: ${{ github.TOKEN }} - name: GitHub Attestation for JAR files - uses: actions/attest-build-provenance@v3 + uses: actions/attest-build-provenance@v4 with: subject-path: "target/*.jar" - name: GitHub Attestation for POM file - uses: actions/attest-build-provenance@v3 + uses: actions/attest-build-provenance@v4 with: subject-path: "pom.xml" subject-name: "${{ steps.maven_artifact.outputs.artifactId }}-${{ steps.maven_artifact.outputs.version }}.pom" From 244886742bb6d09e4ea69f2dea8d2c265bb2859e Mon Sep 17 00:00:00 2001 From: Jared Hatfield Date: Mon, 25 May 2026 00:42:52 +0000 Subject: [PATCH 2/2] Pin actions/attest-build-provenance to v4.1.0 (a2bbfa2) --- .github/workflows/release-maven-central-java-17.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/release-maven-central-java-17.yml b/.github/workflows/release-maven-central-java-17.yml index 3860f2d..9881c5f 100644 --- a/.github/workflows/release-maven-central-java-17.yml +++ b/.github/workflows/release-maven-central-java-17.yml @@ -57,12 +57,12 @@ jobs: GITHUB_TOKEN: ${{ github.TOKEN }} - name: GitHub Attestation for JAR files - uses: actions/attest-build-provenance@v4 + uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0 with: subject-path: "target/*.jar" - name: GitHub Attestation for POM file - uses: actions/attest-build-provenance@v4 + uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0 with: subject-path: "pom.xml" subject-name: "${{ steps.maven_artifact.outputs.artifactId }}-${{ steps.maven_artifact.outputs.version }}.pom"