chore(deps): update actions/attest-sbom action to v4 - #87
cachekit-renovate-bot[bot] wants to merge 1 commit into
Conversation
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This PR updates the
actions/attest-sbomaction in.github/workflows/release.ymlfrom v2 to v4. It is used in the "Attest SBOM" step of the release job.Change details
10926c72720ffc3f7b666661c8e55b1344e2a365(v2) toc604332985a26aa8cf1bdc465b92731239ec6b9e(v4). It stays pinned to a commit hash rather than a floating tag.subject-path: target/package/*.cratesbom-path: sbom.cdx.jsonThese inputs remain compatible with the v4 interface.
Impact
actions/attest-sbomis deprecated. It now works as a thin wrapper aroundactions/attest. A later migration toactions/attestshould be planned, which the upstream project describes as a drop-in replacement with the same inputs.