@@ -43,10 +43,10 @@ jobs:
4343 uses : actions/checkout@v6
4444
4545 - name : Set up Docker Buildx
46- uses : docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
46+ uses : docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
4747
4848 - name : Log in to the Container registry
49- uses : docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6 .0
49+ uses : docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7 .0
5050 with :
5151 registry : ${{ env.REGISTRY }}
5252 username : ${{ github.actor }}
@@ -80,20 +80,20 @@ jobs:
8080
8181 # Upload Software Bill of Materials (SBOM) to GitHub
8282 - name : Upload SBOM
83- uses : advanced-security/spdx-dependency-submission-action@5530bab9ee4bbe66420ce8280624036c77f89746 # v0.1.1
83+ uses : advanced-security/spdx-dependency-submission-action@f957edbb35161c1f9e33f61026fc86a671c58cae # v0.1.2
8484 with :
8585 filePath : ' .'
8686 filePattern : ' *.spdx.json'
8787
8888 # Build provenance attestations
8989 - name : Attest Container Image
90- uses : actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a # v3.0 .0
90+ uses : actions/attest-build-provenance@96278af6caaf10aea03fd8d33a09a777ca52d62f # v3.2 .0
9191 with :
9292 subject-name : ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
9393 subject-digest : ${{ steps.build.outputs.digest }}
9494 push-to-registry : true
9595
9696 # - name: Attest Container SBOM
97- # uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a # v3.0 .0
97+ # uses: actions/attest-build-provenance@96278af6caaf10aea03fd8d33a09a777ca52d62f # v3.2 .0
9898 # with:
9999 # subject-path:: '*.spdx.json'
0 commit comments