Skip to content

Bump actions/attest-build-provenance from 3 to 4#111

Merged
JaredHatfield merged 2 commits into
mainfrom
dependabot/github_actions/actions/attest-build-provenance-4
May 25, 2026
Merged

Bump actions/attest-build-provenance from 3 to 4#111
JaredHatfield merged 2 commits into
mainfrom
dependabot/github_actions/actions/attest-build-provenance-4

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Feb 28, 2026

Bumps actions/attest-build-provenance from 3 to 4.

Release notes

Sourced from actions/attest-build-provenance's releases.

v4.0.0

[!NOTE] As of version 4, actions/attest-build-provenance is simply a wrapper on top of actions/attest.

Existing applications may continue to use the attest-build-provenance action, but new implementations should use actions/attest instead.

What's Changed

Full Changelog: actions/attest-build-provenance@v3.2.0...v4.0.0

v3.2.0

What's Changed

Full Changelog: actions/attest-build-provenance@v3.1.0...v3.2.0

v3.1.0

What's Changed

New Contributors

Full Changelog: actions/attest-build-provenance@v3...v3.1.0

Commits
  • a2bbfa2 bump actions/attest from 4.0.0 to 4.1.0 (#838)
  • 0856891 update RELEASE.md docs (#836)
  • e4d4f7c prepare v4 release (#835)
  • 02a49bd Bump github/codeql-action in the actions-minor group (#824)
  • 7c757df Bump the npm-development group with 2 updates (#825)
  • c44148e Bump github/codeql-action in the actions-minor group (#818)
  • 3234352 Bump @​types/node from 25.0.10 to 25.2.0 in the npm-development group (#819)
  • 18db129 Bump tar from 7.5.6 to 7.5.7 (#816)
  • 90fadfa Bump @​actions/core from 2.0.1 to 2.0.2 in the npm-production group (#799)
  • 57db8ba Bump the npm-development group across 1 directory with 3 updates (#808)
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Feb 28, 2026
Comment thread .github/workflows/release-maven-central-java-17.yml Fixed
Comment thread .github/workflows/release-maven-central-java-17.yml Fixed
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions/attest-build-provenance-4 branch from eec7cd3 to 327ca5f Compare February 28, 2026 13:08
@JaredHatfield JaredHatfield moved this from Todo to Backlog in UnitVectorY Labs Feb 28, 2026
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions/attest-build-provenance-4 branch 2 times, most recently from 8f6b56f to 6431a9b Compare March 21, 2026 10:53
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions/attest-build-provenance-4 branch from 6431a9b to d0b1089 Compare March 21, 2026 12:26
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions/attest-build-provenance-4 branch from d0b1089 to 0301089 Compare March 28, 2026 13:05
@JaredHatfield
Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 3 to 4.
- [Release notes](https://github.com/actions/attest-build-provenance/releases)
- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md)
- [Commits](actions/attest-build-provenance@v3...v4)

---
updated-dependencies:
- dependency-name: actions/attest-build-provenance
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions/attest-build-provenance-4 branch from 0301089 to bf6a271 Compare April 11, 2026 12:05
@codecov
Copy link
Copy Markdown

codecov Bot commented May 25, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (c466399) to head (2f78041).
⚠️ Report is 9 commits behind head on main.

Additional details and impacted files
@@             Coverage Diff             @@
##                main      #111   +/-   ##
===========================================
  Coverage     100.00%   100.00%           
  Complexity        15        15           
===========================================
  Files              1         1           
  Lines             31        31           
  Branches           7         7           
===========================================
  Hits              31        31           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@JaredHatfield JaredHatfield merged commit b839183 into main May 25, 2026
7 checks passed
@JaredHatfield JaredHatfield deleted the dependabot/github_actions/actions/attest-build-provenance-4 branch May 25, 2026 00:48
@github-project-automation github-project-automation Bot moved this from Backlog to Done in UnitVectorY Labs May 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants