diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index c835318..4fae481 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -410,17 +410,17 @@ jobs: # ── Artifact attestations (SLSA provenance) ────────────── - name: Attest build provenance (tar.gz) - uses: actions/attest-build-provenance@96b4a1ef7235a096b17240c259729fdd70c83d45 # v2 + uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2 with: subject-path: '*.tar.gz' - name: Attest build provenance (zip) - uses: actions/attest-build-provenance@96b4a1ef7235a096b17240c259729fdd70c83d45 # v2 + uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2 with: subject-path: '*.zip' - name: Attest build provenance (checksums) - uses: actions/attest-build-provenance@96b4a1ef7235a096b17240c259729fdd70c83d45 # v2 + uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2 with: subject-path: 'checksums.txt'