-
Notifications
You must be signed in to change notification settings - Fork 59
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Link & SLSA attestor #381
Link & SLSA attestor #381
Commits on May 9, 2024
-
Handle multiple results from run
Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for cadd809 - Browse repository at this point
Copy the full SHA cadd809View commit details -
Rename exportRun and add better file naming
Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 7f3fade - Browse repository at this point
Copy the full SHA 7f3fadeView commit details -
Configuration menu - View commit details
-
Copy full SHA for a281b86 - Browse repository at this point
Copy the full SHA a281b86View commit details -
Update go version in actions and point go.mod to WIP go-witness
Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for b8df3d2 - Browse repository at this point
Copy the full SHA b8df3d2View commit details -
Add explicit setup-go action for workflows and change attestation fil…
…e output to backwards compatible Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for aeaa710 - Browse repository at this point
Copy the full SHA aeaa710View commit details -
Add back license scanning badge (#377)
Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 898f1d3 - Browse repository at this point
Copy the full SHA 898f1d3View commit details -
chore: bump github/codeql-action from 3.23.2 to 3.24.0 (#378)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.23.2 to 3.24.0. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b7bf0a3...e8893c5) --- updated-dependencies: - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Tom Meadows <[email protected]> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for eddb6fa - Browse repository at this point
Copy the full SHA eddb6faView commit details -
chore: bump step-security/harden-runner from 2.6.1 to 2.7.0 (#379)
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.6.1 to 2.7.0. - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@eb238b5...63c24ba) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Tom Meadows <[email protected]> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for f66b23f - Browse repository at this point
Copy the full SHA f66b23fView commit details -
chore: bump sigstore/cosign-installer from 3.3.0 to 3.4.0 (#380)
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 3.3.0 to 3.4.0. - [Release notes](https://github.com/sigstore/cosign-installer/releases) - [Commits](sigstore/cosign-installer@9614fae...e1523de) --- updated-dependencies: - dependency-name: sigstore/cosign-installer dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 9bbdd77 - Browse repository at this point
Copy the full SHA 9bbdd77View commit details -
chore: bump actions/download-artifact from 4.1.1 to 4.1.2 (#382)
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4.1.1 to 4.1.2. - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@6b208ae...eaceaf8) --- updated-dependencies: - dependency-name: actions/download-artifact dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for b9457d5 - Browse repository at this point
Copy the full SHA b9457d5View commit details -
chore: bump actions/upload-artifact from 4.3.0 to 4.3.1 (#383)
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.3.0 to 4.3.1. - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@26f96df...5d5d22a) --- updated-dependencies: - dependency-name: actions/upload-artifact dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 51ba5ba - Browse repository at this point
Copy the full SHA 51ba5baView commit details -
Add Tom as a Witness maintainer (#385)
Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 34a321d - Browse repository at this point
Copy the full SHA 34a321dView commit details -
chore: bump testifysec/witness-run-action from 0.1.3 to 0.1.5 (#389)
Bumps [testifysec/witness-run-action](https://github.com/testifysec/witness-run-action) from 0.1.3 to 0.1.5. - [Release notes](https://github.com/testifysec/witness-run-action/releases) - [Commits](testifysec/witness-run-action@40aa4ef...2ae7f93) --- updated-dependencies: - dependency-name: testifysec/witness-run-action dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 6d3e4cd - Browse repository at this point
Copy the full SHA 6d3e4cdView commit details -
chore: bump golangci/golangci-lint-action from 3.7.0 to 4.0.0 (#387)
Bumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) from 3.7.0 to 4.0.0. - [Release notes](https://github.com/golangci/golangci-lint-action/releases) - [Commits](golangci/golangci-lint-action@3a91952...3cfe3a4) --- updated-dependencies: - dependency-name: golangci/golangci-lint-action dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for a655347 - Browse repository at this point
Copy the full SHA a655347View commit details -
chore: bump fossas/fossa-action from 1.3.1 to 1.3.3 (#390)
Bumps [fossas/fossa-action](https://github.com/fossas/fossa-action) from 1.3.1 to 1.3.3. - [Release notes](https://github.com/fossas/fossa-action/releases) - [Commits](fossas/fossa-action@f61a4c0...47ef11b) --- updated-dependencies: - dependency-name: fossas/fossa-action dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 0ed61ec - Browse repository at this point
Copy the full SHA 0ed61ecView commit details -
chore: bump github/codeql-action from 3.24.0 to 3.24.3 (#391)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.24.0 to 3.24.3. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@e8893c5...3796146) --- updated-dependencies: - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 7aa235b - Browse repository at this point
Copy the full SHA 7aa235bView commit details -
chore: bump actions/dependency-review-action from 4.0.0 to 4.1.1 (#392)
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 4.0.0 to 4.1.1. - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@4901385...fd07d42) --- updated-dependencies: - dependency-name: actions/dependency-review-action dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for acd9a18 - Browse repository at this point
Copy the full SHA acd9a18View commit details -
chore: bump actions/dependency-review-action from 4.1.1 to 4.1.3 (#395)
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 4.1.1 to 4.1.3. - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@fd07d42...9129d7d) --- updated-dependencies: - dependency-name: actions/dependency-review-action dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 4ac175e - Browse repository at this point
Copy the full SHA 4ac175eView commit details -
chore: bump github/codeql-action from 3.24.3 to 3.24.5 (#396)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.24.3 to 3.24.5. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@3796146...47b3d88) --- updated-dependencies: - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 76970fe - Browse repository at this point
Copy the full SHA 76970feView commit details -
chore: bump actions/cache from 4.0.0 to 4.0.1 (#401)
Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 288d8ea - Browse repository at this point
Copy the full SHA 288d8eaView commit details -
chore: bump github/codeql-action from 3.24.5 to 3.24.6 (#400)
Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 7ba330a - Browse repository at this point
Copy the full SHA 7ba330aView commit details -
chore: bump actions/download-artifact from 4.1.2 to 4.1.4 (#399)
Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 6b163ec - Browse repository at this point
Copy the full SHA 6b163ecView commit details -
fix: run e2e test script as part of workflows (#397)
* fix: run e2e test script as part of workflows --------- Signed-off-by: Mikhail Swift <[email protected]> Co-authored-by: John Kjell <[email protected]> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for f1b310f - Browse repository at this point
Copy the full SHA f1b310fView commit details -
chore: bump github/codeql-action from 3.24.6 to 3.24.8 (#415)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.24.6 to 3.24.8. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@8a470fd...05963f4) --- updated-dependencies: - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 2fa6166 - Browse repository at this point
Copy the full SHA 2fa6166View commit details -
chore: bump docker/login-action from 3.0.0 to 3.1.0 (#413)
Bumps [docker/login-action](https://github.com/docker/login-action) from 3.0.0 to 3.1.0. - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@343f7c4...e92390c) --- updated-dependencies: - dependency-name: docker/login-action dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for ffcaa83 - Browse repository at this point
Copy the full SHA ffcaa83View commit details -
chore: bump github/codeql-action from 3.24.8 to 3.24.9 (#419)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.24.8 to 3.24.9. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@05963f4...1b1aada) --- updated-dependencies: - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 75da05f - Browse repository at this point
Copy the full SHA 75da05fView commit details -
chore: bump actions/dependency-review-action from 4.1.3 to 4.2.4 (#420)
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 4.1.3 to 4.2.4. - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@9129d7d...733dd5d) --- updated-dependencies: - dependency-name: actions/dependency-review-action dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for f1617cb - Browse repository at this point
Copy the full SHA f1617cbView commit details -
chore: bump actions/cache from 4.0.1 to 4.0.2 (#421)
Bumps [actions/cache](https://github.com/actions/cache) from 4.0.1 to 4.0.2. - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@ab5e6d0...0c45773) --- updated-dependencies: - dependency-name: actions/cache dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 32a12e8 - Browse repository at this point
Copy the full SHA 32a12e8View commit details -
Change to group dependency updates per ecosystem (GHA, go-mod) Signed-off-by: John Kjell <[email protected]> Co-authored-by: Tom Meadows <[email protected]> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for fc695ef - Browse repository at this point
Copy the full SHA fc695efView commit details -
chore: bump the all-gha group with 1 update (#426)
Bumps the all-gha group with 1 update: [actions/dependency-review-action](https://github.com/actions/dependency-review-action). Updates `actions/dependency-review-action` from 4.2.4 to 4.2.5 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@733dd5d...5bbc3ba) --- updated-dependencies: - dependency-name: actions/dependency-review-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-gha ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 80c02b9 - Browse repository at this point
Copy the full SHA 80c02b9View commit details -
Update GHA triggers to fine tune for code changes vs other updates (#406
) Signed-off-by: John Kjell <[email protected]> Co-authored-by: Tom Meadows <[email protected]> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for fc59d7e - Browse repository at this point
Copy the full SHA fc59d7eView commit details -
Configuration menu - View commit details
-
Copy full SHA for 537ee51 - Browse repository at this point
Copy the full SHA 537ee51View commit details -
chore: bump the all-gha group with 2 updates (#431)
Bumps the all-gha group with 2 updates: [github/codeql-action](https://github.com/github/codeql-action) and [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer). Updates `github/codeql-action` from 3.24.9 to 3.24.10 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@1b1aada...4355270) Updates `sigstore/cosign-installer` from 3.4.0 to 3.5.0 - [Release notes](https://github.com/sigstore/cosign-installer/releases) - [Commits](sigstore/cosign-installer@e1523de...59acb62) --- updated-dependencies: - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-gha - dependency-name: sigstore/cosign-installer dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-gha ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 43e74f3 - Browse repository at this point
Copy the full SHA 43e74f3View commit details -
Merge branch 'main' into link-attestor
Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 1373cea - Browse repository at this point
Copy the full SHA 1373ceaView commit details -
Fix breaks from go-witness updates
Signed-off-by: John Kjell <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for bd1efde - Browse repository at this point
Copy the full SHA bd1efdeView commit details