Skip to content

Releases: actions/attest-build-provenance

v1.4.0

30 Jul 20:23
210c191
Compare
Choose a tag to compare

What's Changed

  • Bump predicate action from 1.1.0 to 1.1.1 by @bdehamer in #182
    • Fix for JWKS proxy bug
  • Bump actions/attest from 1.3.3 to 1.4.0 by @bdehamer in #183
    • Add show-summary input
    • Format summary output as list

Full Changelog: v1.3.3...v1.4.0

v1.3.3

09 Jul 17:09
5e9cb68
Compare
Choose a tag to compare

What's Changed

  • Bump actions/attest from 1.3.2 to 1.3.3 by @bdehamer in #152
    • Bugfix for properly handling glob exclusion patterns in subject-path input

Full Changelog: v1.3.2...v1.3.3

v1.3.2

17 Jun 17:35
bdd5137
Compare
Choose a tag to compare

What's Changed

  • Bump actions/attest from 1.3.1 to 1.3.2 by @bdehamer in #123
    • Increase timeout for OCI operations

Full Changelog: v1.3.1...v1.3.2

v1.3.1

13 Jun 21:59
534b352
Compare
Choose a tag to compare

What's Changed

  • Bump actions/attest from 1.3.0 to 1.3.1 by @bdehamer in #117
    • Bugfix when detecting support for the referrers API with OCI registries

Full Changelog: v1.3.0...v1.3.1

v1.3.0

13 Jun 16:00
3119152
Compare
Choose a tag to compare

What's Changed

  • Bump actions/attest-build-provenance/predicate from 1.0.0 to 1.1.0 by @bdehamer in #116
  • Bump actions/attest from 1.2.0 to 1.3.0 by @bdehamer in #116
    • Dynamic construction of GitHub API URLs based on GITHUB_SERVER_URL
    • Improved handling of Rekor 409 responses
    • Bugfix - detection of registries with support for the OCI referrers API

Full Changelog: v1.2.0...v1.3.0

v1.2.0

03 Jun 18:00
49df96e
Compare
Choose a tag to compare

What's Changed

  • Bump actions/attest from 1.1.2 to 1.2.0 by @bdehamer in #101
    • Batch processing w/ exponential backoff
    • Bugfix when pushing attestation to OCI registry

Full Changelog: v1.1.2...v1.2.0

v1.1.2

16 May 19:42
173725a
Compare
Choose a tag to compare

What's Changed

  • Bump actions/attest from 1.1.1 to 1.1.2 by @bdehamer in #79
    • Downcase subject name for OCI images
    • Fix accept header when retrieving image manifest
    • Support variants of the Docker Hub registry name

Full Changelog: v1.1.1...v1.1.2

v1.1.1

10 May 17:55
951c0c5
Compare
Choose a tag to compare

What's Changed

  • Bump actions/attest from v1.1.0 to v1.1.1 by @bdehamer in #67
    • Bump @sigstore/sign from 2.3.0 to 2.3.1
    • Bump @sigstore/oci from 0.3.0 to 0.3.2
    • Include more detail in error logging
    • Send API errors to GHA debug log
    • Fix bug preventing failed API requests from being retried

Full Changelog: v1.1.0...v1.1.1

v1.1.0

06 May 19:18
f8d5ea8
Compare
Choose a tag to compare

What's Changed

  • Bump actions/attest to v1.1.0 by @bdehamer in #65
    • adds list support for subjectPath input
    • limit attestation subject count
    • ensure subject globs match only files

Full Changelog: v1.0.0...v1.1.0

v1.0.0

30 Apr 18:58
897ed5e
Compare
Choose a tag to compare

What's Changed

  • Update README.md to use attestations permission by @phillmv in #43
  • Bump actions/attest action to v1.0.0 by @bdehamer in #46
  • Bump @actions/attest package from 1.1.0 to 1.2.1 by @bdehamer in #47
  • Bump predicate action from 0.2.0 to 1.0.0 by @bdehamer in #48

Full Changelog: v0.2.0...v1.0.0