Skip to content

chore(deps): update github-actions pinned digests - #134

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions-pinned-digests
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions-pinned-digests

Conversation

@renovate

@renovate renovate Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

This PR contains the following updates:

Package Type Update Change
actions/attest-build-provenance action minor v4.1.1 → v4.2.2
actions/checkout action pin v6 → v6.1.0
actions/checkout action pin v7 → v7.0.1
actions/checkout action minor v4.2.2 → v4.4.0
actions/create-github-app-token action pin v3 → v3.2.0
actions/download-artifact action pin v8 → v8.0.1
actions/setup-java action pin v5 → v5.7.0
actions/setup-node action pin v6 → v6.5.0
actions/setup-node action pin v4 → v4.4.0
actions/setup-node action pin v7 → v7.0.0
actions/setup-python action pin v6 → v6.3.0
actions/upload-artifact action pinDigest → 043fb46
cachix/install-nix-action action pin v31 → v31.11.1
docker/build-push-action action pin v7 → v7.4.0
docker/login-action action pin v4 → v4.6.0
docker/setup-buildx-action action pin v4 → v4.4.1
docker/setup-qemu-action action pin v4 → v4.4.0
googleapis/release-please-action action pin v5 → v5.0.0
gradle/actions action pin v6 → v6.4.0
pnpm/action-setup action pin v6 → v6.1.0
re-actors/alls-green action pinDigest → b5b5b37
sigstore/cosign uses-with patch v2.6.1 → v2.6.5

Release Notes

actions/attest-build-provenance (actions/attest-build-provenance)

v4.2.2

Compare Source

[!NOTE]
As of version 4, actions/attest-build-provenance is simply a wrapper on top of actions/attest.

Existing applications may continue to use the attest-build-provenance action, but new implementations should use actions/attest instead.

What's Changed

Full Changelog: actions/attest-build-provenance@v4.1.1...v4.2.2

actions/checkout (actions/checkout)

v4.4.0

Compare Source

v4.3.1

Compare Source

v4.3.0

Compare Source

sigstore/cosign (sigstore/cosign)

v2.6.5

Compare Source

Changelog

This release backports GHSA-fx35-mq7g-6g98 (Verification bypass via public key in legacy bundle) to Cosign v2.6.x.

We strongly encourage folks to continue their migration to the bundle format. The Cosign v3.1.x releases support both formats; the primary change being that the default for signing is the bundle format (although you can specify --new-bundle-format=false to sign with the old format). The verification commands in Cosign v3.1.x support both formats, and will try to detect the format for you for maximum compatibility.

Thanks to all contributors!

v2.6.4

Compare Source

This release is a backport of OCI manifest fixes, and better support for cosign attestation download when you are using a mix of old Cosign signatures with the more recent bundle format.

We strongly encourage folks to continue their migration to the bundle format. The Cosign v3.1.x releases support both formats; the primary change being that the default for signing is the bundle format (although you can specify --new-bundle-format=false to sign with the old format). The verification commands in Cosign v3.1.x support both formats, and will try to detect the format for you for maximum compatibility.

Changelog

  • 26261f0 Allow attestation download to handle both bundle types (#​4996) (#​5017)
  • d49a0c1 fix: include artifactType in OCI 1.1 signature referrer manifest (cherry-pick PR-4997 to release-2.6) (#​5002)
Thanks to all contributors!

v2.6.3

Compare Source

Changelog

v2.6.3 resolves GHSA-w6c6-c85g-mmv6.

Thanks to all contributors!

v2.6.2

Compare Source

v2.6.2 resolves GHSA-whqx-f9j3-ch6m.

Changes


Configuration

📅 Schedule: (in timezone Etc/UTC)

  • Branch creation
    • "before 9am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added area: tooling Reusable workflows, Gradle, templates, Renovate, and API tooling. component: dependencies Dependency update or dependency policy. dependencies Dependency update, lockfile change, or dependency policy. priority: P2 Medium; normal planned work. type: chore Maintenance work without intended behavior change. labels Sep 14, 2026
@renovate
renovate Bot force-pushed the renovate/github-actions-pinned-digests branch 2 times, most recently from 407c177 to bf7d925 Compare September 20, 2026 03:47
@renovate
renovate Bot force-pushed the renovate/github-actions-pinned-digests branch 2 times, most recently from 1b5046e to 49cffd1 Compare October 3, 2026 11:41
@renovate
renovate Bot force-pushed the renovate/github-actions-pinned-digests branch from 49cffd1 to d55f792 Compare October 4, 2026 13:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: tooling Reusable workflows, Gradle, templates, Renovate, and API tooling. component: dependencies Dependency update or dependency policy. dependencies Dependency update, lockfile change, or dependency policy. priority: P2 Medium; normal planned work. type: chore Maintenance work without intended behavior change.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants