Skip to content

Commit 88d622b

Browse files
Merge pull request #4 from slsa-framework/v2.0.0-changes
chore: update refs to v2.0.0
2 parents 7e4a903 + d1969bd commit 88d622b

File tree

10 files changed

+17
-17
lines changed

10 files changed

+17
-17
lines changed

.github/workflows/builder_high-perms-checkout_slsa3.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -89,7 +89,7 @@ jobs:
8989
steps:
9090
- name: Generate the token
9191
id: generate
92-
uses: slsa-framework/slsa-github-generator/actions/delegator/setup-generic@main
92+
uses: slsa-framework/slsa-github-generator/actions/delegator/setup-generic@v2.0.0
9393
with:
9494
slsa-workflow-recipient: "delegator_generic_slsa3.yml"
9595
slsa-rekor-log-public: ${{ inputs.rekor-log-public }}
@@ -106,7 +106,7 @@ jobs:
106106
contents: write # For asset uploads.
107107
packages: write # For package uploads.
108108
actions: read # For the entrypoint.
109-
uses: slsa-framework/slsa-github-generator/.github/workflows/delegator_generic_slsa3.yml@main
109+
uses: slsa-framework/slsa-github-generator/.github/workflows/delegator_generic_slsa3.yml@v2.0.0
110110
with:
111111
slsa-token: ${{ needs.slsa-setup.outputs.slsa-token }}
112112
secrets:
@@ -121,7 +121,7 @@ jobs:
121121
runs-on: ubuntu-latest
122122
steps:
123123
- name: Download provenance
124-
uses: slsa-framework/slsa-github-generator/actions/delegator/secure-attestations-download@main
124+
uses: slsa-framework/slsa-github-generator/actions/delegator/secure-attestations-download@v2.0.0
125125
with:
126126
name: ${{ needs.slsa-run.outputs.attestations-download-name }}
127127
sha256: ${{ needs.slsa-run.outputs.attestations-download-sha256 }}

.github/workflows/builder_high-perms-checkout_slsa3_test.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ jobs:
2828
contents: write # For asset release.
2929
packages: write # For package upload.
3030
actions: read # For getting workflow run info.
31-
uses: slsa-framework/example-trw/.github/workflows/builder_high-perms-checkout_slsa3.yml@main
31+
uses: slsa-framework/example-trw/.github/workflows/builder_high-perms-checkout_slsa3.yml@v2.0.0
3232
with:
3333
artifact: my-artifact
3434
filename: high-perms-checkout/src/build.txt

.github/workflows/builder_high-perms_slsa3.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -84,7 +84,7 @@ jobs:
8484
steps:
8585
- name: Generate the token
8686
id: generate
87-
uses: slsa-framework/slsa-github-generator/actions/delegator/setup-generic@main
87+
uses: slsa-framework/slsa-github-generator/actions/delegator/setup-generic@v2.0.0
8888
with:
8989
slsa-workflow-recipient: "delegator_generic_slsa3.yml"
9090
slsa-rekor-log-public: ${{ inputs.rekor-log-public }}
@@ -100,7 +100,7 @@ jobs:
100100
contents: write # For asset uploads.
101101
packages: write # For package uploads.
102102
actions: read # For the entrypoint.
103-
uses: slsa-framework/slsa-github-generator/.github/workflows/delegator_generic_slsa3.yml@main
103+
uses: slsa-framework/slsa-github-generator/.github/workflows/delegator_generic_slsa3.yml@v2.0.0
104104
with:
105105
slsa-token: ${{ needs.slsa-setup.outputs.slsa-token }}
106106
secrets:

.github/workflows/builder_high-perms_slsa3_test.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ jobs:
2828
contents: write # For asset release.
2929
packages: write # For package upload.
3030
actions: read # For getting workflow run info.
31-
uses: slsa-framework/example-trw/.github/workflows/builder_high-perms_slsa3.yml@main # v0.0.1 has all refs at main.
31+
uses: slsa-framework/example-trw/.github/workflows/builder_high-perms_slsa3.yml@v2.0.0 # v0.0.1 has all refs at main.
3232
with:
3333
artifact: my-artifact
3434
content: "hello world"

.github/workflows/builder_low-perms_slsa3.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -94,7 +94,7 @@ jobs:
9494
steps:
9595
- name: Generate the token
9696
id: generate
97-
uses: slsa-framework/slsa-github-generator/actions/delegator/setup-generic@main
97+
uses: slsa-framework/slsa-github-generator/actions/delegator/setup-generic@v2.0.0
9898
with:
9999
slsa-workflow-recipient: "delegator_lowperms-generic_slsa3.yml"
100100
slsa-rekor-log-public: ${{ inputs.rekor-log-public }}
@@ -109,7 +109,7 @@ jobs:
109109
id-token: write # For signing.
110110
contents: read # For code access.
111111
actions: read # For the entrypoint.
112-
uses: slsa-framework/slsa-github-generator/.github/workflows/delegator_lowperms-generic_slsa3.yml@main
112+
uses: slsa-framework/slsa-github-generator/.github/workflows/delegator_lowperms-generic_slsa3.yml@v2.0.0
113113
with:
114114
slsa-token: ${{ needs.slsa-setup.outputs.slsa-token }}
115115
secrets:
@@ -124,7 +124,7 @@ jobs:
124124
runs-on: ubuntu-latest
125125
steps:
126126
- name: Download provenance
127-
uses: slsa-framework/slsa-github-generator/actions/delegator/secure-attestations-download@main
127+
uses: slsa-framework/slsa-github-generator/actions/delegator/secure-attestations-download@v2.0.0
128128
with:
129129
name: ${{ needs.slsa-run.outputs.attestations-download-name }}
130130
sha256: ${{ needs.slsa-run.outputs.attestations-download-sha256 }}
@@ -152,7 +152,7 @@ jobs:
152152
# Artifacts are downloaded in the current directory. The downloaded folder
153153
# is the one uploaded by the TCA, which in our case is called "artifacts".
154154
- name: Download artifacts
155-
uses: slsa-framework/slsa-github-generator/actions/delegator/secure-download-folder@main
155+
uses: slsa-framework/slsa-github-generator/actions/delegator/secure-download-folder@v2.0.0
156156
with:
157157
name: ${{ fromJson(needs.slsa-run.outputs.build-artifacts-outputs).artifact-download-name }}
158158
sha256: ${{ fromJson(needs.slsa-run.outputs.build-artifacts-outputs).artifact-download-sha256 }}

.github/workflows/builder_low-perms_slsa3_test.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ jobs:
2727
id-token: write # For signing
2828
contents: write # For asset release.
2929
actions: read # For getting workflow run info.
30-
uses: slsa-framework/example-trw/.github/workflows/builder_low-perms_slsa3.yml@main # v0.0.1 has all refs at main.
30+
uses: slsa-framework/example-trw/.github/workflows/builder_low-perms_slsa3.yml@v2.0.0 # v0.0.1 has all refs at main.
3131
with:
3232
artifact: my-artifact
3333
content: "hello world"

high-perms-checkout/actions/download/attestation/action.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ runs:
3030
using: "composite"
3131
steps:
3232
- name: Download the attestations
33-
uses: slsa-framework/slsa-github-generator/actions/delegator/secure-attestations-download@main
33+
uses: slsa-framework/slsa-github-generator/actions/delegator/secure-attestations-download@v2.0.0
3434
with:
3535
name: ${{ inputs.name }}
3636
path: ${{ inputs.path }}

high-perms/actions/download/attestation/action.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ runs:
3030
using: "composite"
3131
steps:
3232
- name: Download the attestations
33-
uses: slsa-framework/slsa-github-generator/actions/delegator/secure-attestations-download@main
33+
uses: slsa-framework/slsa-github-generator/actions/delegator/secure-attestations-download@v2.0.0
3434
with:
3535
name: ${{ inputs.name }}
3636
path: ${{ inputs.path }}

low-perms/actions/download/attestation/action.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ runs:
3030
using: "composite"
3131
steps:
3232
- name: Download the attestations
33-
uses: slsa-framework/slsa-github-generator/actions/delegator/secure-attestations-download@main
33+
uses: slsa-framework/slsa-github-generator/actions/delegator/secure-attestations-download@v2.0.0
3434
with:
3535
name: ${{ inputs.name }}
3636
path: ${{ inputs.path }}

low-perms/internal/callback_action/action.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -83,7 +83,7 @@ runs:
8383
- name: Create random value
8484
id: rng
8585
# WARNING: This is not cryptographically secure and will show in logs!
86-
uses: slsa-framework/slsa-github-generator/actions/delegator/random@main
86+
uses: slsa-framework/slsa-github-generator/actions/delegator/random@v2.0.0
8787

8888
# Create the folder to share.
8989
# The folder is local, so need its name needs not be randomized.
@@ -100,7 +100,7 @@ runs:
100100
# Share the artifacts folder, with a unique randomized name.
101101
- name: Share artifacts
102102
id: upload
103-
uses: slsa-framework/slsa-github-generator/actions/delegator/secure-upload-folder@main
103+
uses: slsa-framework/slsa-github-generator/actions/delegator/secure-upload-folder@v2.0.0
104104
with:
105105
name: "${{ steps.rng.outputs.random }}-artifacts"
106106
path: artifacts

0 commit comments

Comments
 (0)