66 COSIGN_EXPERIMENTAL : 1
77 REGISTRY : ghcr.io
88 IMAGE_NAME : ${{ github.repository }}
9- VERSION : 0.2.4
9+ VERSION : 0.3.0
1010
1111jobs :
1212 build :
1919 image-release : ${{ steps.image-info.outputs.release }}
2020 steps :
2121 - name : Checkout source code
22- uses : actions/checkout@v3.0.2
22+ uses : actions/checkout@v3.1.0
2323
2424 - name : Set up Carvel
2525 uses : vmware-tanzu/carvel-setup-action@v1.1.1
5555 package_file=repo/package-repository.yml
5656 image_release=$(yq '.spec.fetch.imgpkgBundle.image' ${package_file})
5757 echo "IMAGE_RELEASE=${image_release}" >> $GITHUB_ENV
58- echo "::set-output name= release:: ${image_release}"
58+ echo "release= ${image_release}" >> $GITHUB_OUTPUT
5959
6060 - name : Add additional tags to OCI image
6161 run : |
8383 IMAGE_RELEASE : ${{ needs.build.outputs.image-release }}
8484 steps :
8585 - name : Install Cosign
86- uses : sigstore/cosign-installer@v2.7.0
86+ uses : sigstore/cosign-installer@v2.8.1
8787 with :
88- cosign-release : ' v1.12.1 '
88+ cosign-release : ' v1.13.0 '
8989
9090 - name : Log into container registry
9191 uses : redhat-actions/podman-login@v1.4
@@ -110,9 +110,9 @@ jobs:
110110 PROVENANCE_FILE : provenance.att
111111 steps :
112112 - name : Install Cosign
113- uses : sigstore/cosign-installer@v2.7.0
113+ uses : sigstore/cosign-installer@v2.8.1
114114 with :
115- cosign-release : ' v1.12.1 '
115+ cosign-release : ' v1.13.0 '
116116
117117 - name : Log into container registry
118118 uses : redhat-actions/podman-login@v1.4
@@ -140,7 +140,7 @@ jobs:
140140 jq '.predicate' "${PROVENANCE_FILE}" > provenance-predicate.att
141141 cosign attest --predicate provenance-predicate.att --type slsaprovenance "${IMAGE_RELEASE}"
142142
143- - uses : actions/upload-artifact@v3.1.0
143+ - uses : actions/upload-artifact@v3.1.1
144144 with :
145145 name : provenance.att
146146 path : ${{ env.PROVENANCE_FILE }}
0 commit comments