Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions .github/workflows/publish-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -708,8 +708,9 @@ jobs:
contents: write # attaches the statement to the release
# Referenced by tag, not by commit hash, on purpose: slsa-verifier can
# only verify the generator's ref when it is a tag (the generator's
# README, "Referencing SLSA builders and generators").
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v2.1.0
# README, "Referencing SLSA builders and generators"). The marker
# below tells SonarCloud's pin-by-hash rule that this one is deliberate.
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v2.1.0 # NOSONAR the SLSA generator must be referenced by tag
with:
base64-subjects: ${{ needs.hashes.outputs.hashes }}
provenance-name: release-assets.intoto.jsonl
Expand Down
Loading