Skip to content

chore(ci)(deps): bump actions/attest-build-provenance from 1 to 4 - #3001

Merged
gHashTag merged 1 commit into
masterfrom
dependabot/github_actions/actions/attest-build-provenance-4
Oct 2, 2026
Merged

gHashTag merged 1 commit into
masterfrom
dependabot/github_actions/actions/attest-build-provenance-4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps actions/attest-build-provenance from 1 to 4.

Release notes

Sourced from actions/attest-build-provenance's releases.

v4.0.0

[!NOTE] As of version 4, actions/attest-build-provenance is simply a wrapper on top of actions/attest.

Existing applications may continue to use the attest-build-provenance action, but new implementations should use actions/attest instead.

What's Changed

Full Changelog: actions/attest-build-provenance@v3.2.0...v4.0.0

v3.2.0

What's Changed

Full Changelog: actions/attest-build-provenance@v3.1.0...v3.2.0

v3.1.0

What's Changed

New Contributors

Full Changelog: actions/attest-build-provenance@v3...v3.1.0

v3.0.0

What's Changed

⚠️ Minimum Compatible Runner Version

v2.327.1 Release Notes

Make sure your runner is updated to this version or newer to use this release.

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added the ci label Sep 1, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-09-01 09:18:06 UTC

Summary

Status Count
Total Open PRs 10
PRs with Failing Checks 8
PRs with All Checks Green 2
READY 0
FAILING 8
PENDING 0

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=fd84214651ae != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

📓 NotebookLM Notebook linked to this PR

This notebook contains session context, decisions, and artifacts for this work.

This was referenced Sep 3, 2026
@gHashTag

gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Reviewer bee X. Reviewed: a one-line major bump of a pinned action; the inputs this repo passes (subject-path / files / sarif_file) are unchanged across the major, and the job permissions the new major needs (contents / id-token / attestations write where relevant) are already declared. The only red check (compile-proofs) is unrelated to workflows. Labelled bee-reviewed. Not merged by me: the change touches .github/workflows and the reviewer token lacks the workflow scope -- awaiting the owner's merge.

@gHashTag

gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner

@dependabot rebase

(Reviewer bee: the required check parse-ratchet never ran on this head, which dates from 2026-09-14. A rebase gives the current required checks a fresh head to run on. I will re-review the rebased diff before re-applying bee-reviewed.)

Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 1 to 4.
- [Release notes](https://github.com/actions/attest-build-provenance/releases)
- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md)
- [Commits](actions/attest-build-provenance@v1...v4)

---
updated-dependencies:
- dependency-name: actions/attest-build-provenance
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/attest-build-provenance-4 branch from c7e7cd6 to 238be1a Compare October 2, 2026 19:14
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

📓 NotebookLM Notebook linked to this PR

This notebook contains session context, decisions, and artifacts for this work.

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-02 19:20:38 UTC

Summary

Status Count
Total Open PRs 39
PRs with Failing Checks 38
PRs with All Checks Green 1
READY 1
FAILING 38
PENDING 0
NO CHECKS YET 0

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b45a356c2eb6 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@gHashTag gHashTag added bee-reviewed A reviewer bee reviewed and verified this PR at its current head; the only merge signal (#5525) and removed bee-reviewed A reviewer bee reviewed and verified this PR at its current head; the only merge signal (#5525) labels Oct 2, 2026
@gHashTag

gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner

bee review (reviewer, not author) — head 238be1a84131e411a1f365122f6338252c2117e0

Checked:

  • Diff is one line in .github/workflows/sign-release.yml: actions/attest-build-provenance@v1 -> @v4. No other files.
  • Release notes:
    • v2: multi-subject attestations; subject-path: 'dist/*' now yields one attestation listing every artifact.
    • v3: Node 24 runtime; needs runner >= 2.327.1, which ubuntu-latest satisfies.
    • v4: the action is now a wrapper over actions/attest.
  • action.yml@v4.0.0 still declares subject-path, the only input used.
  • The job permissions include id-token: write and attestations: write (plus contents: write for the upload step).
  • Required checks at this head: validate, check-linked-issue and parse-ratchet are all success.
  • Still mergeable after chore(ci)(deps): bump softprops/action-gh-release from 2 to 3 #3000 (squash 5f40f66) changed the action-gh-release line in the same file. That is a separate hunk, and the head is unchanged since review.

Red checks not caused by this PR:

  • untrusted-input is red on master and on every open PR.
  • coverage is red on master.
  • integrity-gate and pack-index-consistency report SHA drift in conformance/vectors/*_conformance_v0.json, files this PR does not touch.

Label bee-reviewed re-applied after this head.

@t27-bees t27-bees Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

bee review: see evidence comment

@gHashTag
gHashTag merged commit f51167c into master Oct 2, 2026
42 of 48 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/actions/attest-build-provenance-4 branch October 2, 2026 19:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bee-reviewed A reviewer bee reviewed and verified this PR at its current head; the only merge signal (#5525) ci

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant