Skip to content

chore(deps): bump actions/attest from 4.2.0 to 4.2.2 - #27

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/attest-4.2.2
Open

chore(deps): bump actions/attest from 4.2.0 to 4.2.2#27
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/attest-4.2.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown

Bumps actions/attest from 4.2.0 to 4.2.2.

Release notes

Sourced from actions/attest's releases.

v4.2.2

What's Changed

Full Changelog: actions/attest@v4.2.1...v4.2.2

v4.2.1

What's Changed

Full Changelog: actions/attest@v4.2.0...v4.2.1

Commits
  • 1e69f48 Bump ip-address from 10.2.0 to 10.4.0 (#467)
  • 02787ce Bump brace-expansion (#468)
  • 98ac037 bump @​sigstore/oci from 0.7.1 to 0.7.2 (#469)
  • 508db95 fix: strip OCI image tag when pushing attestation to registry (#464)
  • dda48f2 Bump the npm-development group across 1 directory with 6 updates (#461)
  • 7d789a3 Bump the actions-minor group with 3 updates (#463)
  • 1f3ca2f Add release-cutter canvas extension (#454)
  • d215549 Bump tar from 7.5.17 to 7.5.21 (#459)
  • 20c90ed Bump the npm-development group with 2 updates (#455)
  • 43c2c81 Bump the actions-minor group with 4 updates (#456)
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies, supply-chain. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Bumps [actions/attest](https://github.com/actions/attest) from 4.2.0 to 4.2.2.
- [Release notes](https://github.com/actions/attest/releases)
- [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md)
- [Commits](actions/attest@f7c74d2...1e69f48)

---
updated-dependencies:
- dependency-name: actions/attest
  dependency-version: 4.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/attest-4.2.2 branch from 7b233c9 to b7f28a0 Compare August 13, 2026 20:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants