diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 1c25ac5..253ea40 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -82,7 +82,7 @@ jobs: python3 _localsetup/tools/localsetup_v3.py --source-root . verify-release "dist/localsetup-v${version}.tar.gz" --expected-commit "$GITHUB_SHA" - name: Upload release artifacts - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: localsetup-release-${{ github.sha }} path: | @@ -91,7 +91,7 @@ jobs: dist/localsetup-v*.tar.gz.cdx.json - name: Attest release tarball - uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a # v3 + uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0 with: subject-path: dist/localsetup-v*.tar.gz