Skip to content

Conversation

xentra-bot[bot]
Copy link
Contributor

@xentra-bot xentra-bot bot commented Mar 6, 2025

This PR contains the following updates:

Package Type Update Change OpenSSF
slsa-framework/slsa-github-generator action minor v2.0.0 -> v2.1.0 OpenSSF Scorecard

Release Notes

slsa-framework/slsa-github-generator (slsa-framework/slsa-github-generator)

v2.1.0

Compare Source

v2.1.0: Sigstore Bundles for Generic Generator and Go Builder

The workflows generator_generic_slsa3.yml and builder_go_slsa3.yml
have been updated to produce signed Sigstore Bundles, just like all the other builders
that use the BYOB framework.

The workflow logs will now print a LogIndex, rather than a LogUUID. Both are equally searchanble on
https://search.sigstore.dev/.

v2.1.0: Vars context recorded in provenance
  • Updated: GitHub vars context is now recorded in provenance for the generic and
    container generators. The vars context cannot affect the build in the Go
    builder so it is not recorded.

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled because a matching PR was automerged previously.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@xentra-bot xentra-bot bot requested review from xunholy and maheshrayas as code owners March 6, 2025 10:03
@xunholy xunholy merged commit 1ea856a into main Jun 5, 2025
@xunholy xunholy deleted the renovate/slsa-framework-slsa-github-generator-2.x branch June 5, 2025 22:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant