Skip to content

chore(deps): update actions/attest-sbom action to v4 - #87

Open
cachekit-renovate-bot[bot] wants to merge 1 commit into
mainfrom
renovate/actions-attest-sbom-4.x
Open

cachekit-renovate-bot[bot] wants to merge 1 commit into
mainfrom
renovate/actions-attest-sbom-4.x

Conversation

@cachekit-renovate-bot

@cachekit-renovate-bot cachekit-renovate-bot Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

This PR updates the actions/attest-sbom action in .github/workflows/release.yml from v2 to v4. It is used in the "Attest SBOM" step of the release job.

Change details

  • The action's pinned commit SHA changes from 10926c72720ffc3f7b666661c8e55b1344e2a365 (v2) to c604332985a26aa8cf1bdc465b92731239ec6b9e (v4). It stays pinned to a commit hash rather than a floating tag.
  • The step's inputs are unchanged:
    • subject-path: target/package/*.crate
    • sbom-path: sbom.cdx.json

These inputs remain compatible with the v4 interface.

Impact

  • Runtime: v3 and later run on Node 24. Self-hosted runners must be at least version v2.327.1. GitHub-hosted runners are unaffected.
  • Deprecation: starting with v4, actions/attest-sbom is deprecated. It now works as a thin wrapper around actions/attest. A later migration to actions/attest should be planned, which the upstream project describes as a drop-in replacement with the same inputs.
  • Scope: no other workflow steps, public APIs, or crate code are modified. Only the release-time SBOM attestation is affected.

@cachekit-renovate-bot cachekit-renovate-bot Bot added dependencies Pull requests that update a dependency file major labels Sep 29, 2026
@kodus-27b

kodus-27b Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 13d24041-026a-48ce-8b27-34b440ad9efe

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file major

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant