Skip to content

build(deps): bump actions/attest from 4.2.1 to 4.2.2 - #4

Open
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/github_actions/actions/attest-4.2.2
Open

build(deps): bump actions/attest from 4.2.1 to 4.2.2#4
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/github_actions/actions/attest-4.2.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/attest from 4.2.1 to 4.2.2.

Release notes

Sourced from actions/attest's releases.

v4.2.2

What's Changed

Full Changelog: actions/attest@v4.2.1...v4.2.2

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 17, 2026
@dependabot
dependabot Bot requested a review from nstranquist as a code owner August 17, 2026 04:46
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 17, 2026
@nstranquist

Copy link
Copy Markdown
Owner

@dependabot rebase

Bumps [actions/attest](https://github.com/actions/attest) from 4.2.1 to 4.2.2.
- [Release notes](https://github.com/actions/attest/releases)
- [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md)
- [Commits](actions/attest@508db95...1e69f48)

---
updated-dependencies:
- dependency-name: actions/attest
  dependency-version: 4.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/attest-4.2.2 branch from b5aca40 to c58c5c5 Compare August 17, 2026 05:18
@nstranquist

Copy link
Copy Markdown
Owner

The workflow pin changed, but TestBetaReleaseWorkflowContract intentionally binds the reviewed attestation-action SHA. Every failing test reports the old SHA as missing. Review the v4.2.2 source and provenance, then update the workflow pin and contract test together in a maintainer change. Do not merge this bot-only PR as-is.

@nstranquist

Copy link
Copy Markdown
Owner

Maintainer repair added in 807dd83: the release workflow and its pin-contract test now advance together. Upstream review confirmed v4.2.2 is an immutable actions/attest release at 1e69f48acb82d1966a394da916b4c1698aa569d6; its three commits update @sigstore/oci, brace-expansion, and ip-address. Full local tests, race sweep, vet, actionlint, golangci-lint, and gitleaks pass. Because the maintainer made the latest reviewable push, the branch rule correctly requires a different reviewer to approve this new head.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant