Skip to content

chore(deps): bump actions/attest from 4.2.1 to 4.2.2 - #598

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/attest-4.2.2
Open

chore(deps): bump actions/attest from 4.2.1 to 4.2.2#598
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/attest-4.2.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 26, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/attest from 4.2.1 to 4.2.2.

Release notes

Sourced from actions/attest's releases.

v4.2.2

What's Changed

Full Changelog: actions/attest@v4.2.1...v4.2.2

Commits


Note

Overview
Pins actions/attest from v4.2.1 to v4.2.2 (commit 1e69f48…) on every Attest build provenance step that still used the old SHA.

manual-sdk-release-artifacts.yml updates two jobs (release-sdk, release-sdk-mac-arm64). release-please.yml updates eight attest steps across client, server, Redis, and DynamoDB release jobs (matrix and macOS arm64 variants). Step inputs (subject-checksums: checksums.txt) and permissions are unchanged; only the action version moves to pick up upstream dependency bumps in v4.2.2.

Reviewed by Cursor Bugbot for commit 6942a83. Bugbot is set up for automated code reviews on this repo. Configure here.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 26, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 26, 2026 19:14
@dependabot dependabot Bot added the github_actions Pull requests that update GitHub Actions code label Aug 26, 2026
@kinyoklion

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [actions/attest](https://github.com/actions/attest) from 4.2.1 to 4.2.2.
- [Release notes](https://github.com/actions/attest/releases)
- [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md)
- [Commits](actions/attest@508db95...1e69f48)

---
updated-dependencies:
- dependency-name: actions/attest
  dependency-version: 4.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/attest-4.2.2 branch from d2c78be to 6942a83 Compare September 1, 2026 15:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant