pin actions/attest reference by commit sha

Signed-off-by: Brian DeHamer <bdehamer@github.com>
This commit is contained in:
Brian DeHamer 2025-03-05 10:08:54 -08:00
parent bd77c07785
commit 70b9817e6e
No known key found for this signature in database

View File

@ -64,7 +64,7 @@ runs:
steps:
- uses: actions/attest-build-provenance/predicate@1176ef556905f349f669722abf30bce1a6e16e01 # predicate@1.1.5
id: generate-build-provenance-predicate
- uses: actions/attest@v2.2.1
- uses: actions/attest@a63cfcc7d1aab266ee064c58250cfc2c7d07bc31 # v2.2.1
id: attest
with:
subject-path: ${{ inputs.subject-path }}