Skip to content

chore(deps): bump actions/attest-build-provenance from 2.3.0 to 2.4.0#4919

Merged
Skarlso merged 1 commit intomainfrom
dependabot/github_actions/actions/attest-build-provenance-2.4.0
Jun 17, 2025
Merged

chore(deps): bump actions/attest-build-provenance from 2.3.0 to 2.4.0#4919
Skarlso merged 1 commit intomainfrom
dependabot/github_actions/actions/attest-build-provenance-2.4.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Jun 16, 2025

Bumps actions/attest-build-provenance from 2.3.0 to 2.4.0.

Release notes

Sourced from actions/attest-build-provenance's releases.

v2.4.0

What's Changed

Full Changelog: actions/attest-build-provenance@v2.3.0...v2.4.0

Commits
  • e8998f9 bump actions/attest from 2.3.0 to 2.4.0 (#654)
  • 11c67f2 Bump the npm-development group across 1 directory with 6 updates (#649)
  • 39cb715 Bump the npm-development group across 1 directory with 7 updates (#641)
  • 7d91c40 Bump undici from 5.28.5 to 5.29.0 (#633)
  • d848170 Bump super-linter/super-linter in the actions-minor group (#640)
  • 0ca36ea Bump the npm-development group with 7 updates (#582)
  • d82e7cd offboard from eslint in superlinter (#618)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file area/ci Pull requests that update Github_actions code labels Jun 16, 2025
@dependabot dependabot bot requested a review from a team as a code owner June 16, 2025 09:13
@dependabot dependabot bot requested a review from knelasevero June 16, 2025 09:13
@dependabot dependabot bot added dependencies Pull requests that update a dependency file area/ci Pull requests that update Github_actions code labels Jun 16, 2025
@dependabot dependabot bot force-pushed the dependabot/github_actions/actions/attest-build-provenance-2.4.0 branch from 6474774 to 3ad6a78 Compare June 17, 2025 05:15
@dependabot dependabot bot force-pushed the dependabot/github_actions/actions/attest-build-provenance-2.4.0 branch from 3ad6a78 to f167fc3 Compare June 17, 2025 05:49
Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 2.3.0 to 2.4.0.
- [Release notes](https://github.com/actions/attest-build-provenance/releases)
- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md)
- [Commits](actions/attest-build-provenance@db473fd...e8998f9)

---
updated-dependencies:
- dependency-name: actions/attest-build-provenance
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/github_actions/actions/attest-build-provenance-2.4.0 branch from f167fc3 to 20fc483 Compare June 17, 2025 05:50
@sonarqubecloud
Copy link
Copy Markdown

@Skarlso Skarlso merged commit 70fdd45 into main Jun 17, 2025
18 checks passed
@Skarlso Skarlso deleted the dependabot/github_actions/actions/attest-build-provenance-2.4.0 branch June 17, 2025 08:15
alliseeisgold pushed a commit to alliseeisgold/external-secrets that referenced this pull request Jul 10, 2025
…external-secrets#4919)

Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 2.3.0 to 2.4.0.
- [Release notes](https://github.com/actions/attest-build-provenance/releases)
- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md)
- [Commits](actions/attest-build-provenance@db473fd...e8998f9)

---
updated-dependencies:
- dependency-name: actions/attest-build-provenance
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: asrormirzoev <asrormirzoev@yandex-team.ru>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/ci Pull requests that update Github_actions code dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant