Skip to content

build(deps): bump actions/attest-build-provenance from 3 to 4#1221

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/attest-build-provenance-3
Closed

build(deps): bump actions/attest-build-provenance from 3 to 4#1221
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/attest-build-provenance-3

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Nov 1, 2025

Bumps actions/attest-build-provenance from 3 to 4.

Release notes

Sourced from actions/attest-build-provenance's releases.

v4.0.0

[!NOTE] As of version 4, actions/attest-build-provenance is simply a wrapper on top of actions/attest.

Existing applications may continue to use the attest-build-provenance action, but new implementations should use actions/attest instead.

What's Changed

Full Changelog: actions/attest-build-provenance@v3.2.0...v4.0.0

v3.2.0

What's Changed

Full Changelog: actions/attest-build-provenance@v3.1.0...v3.2.0

v3.1.0

What's Changed

New Contributors

Full Changelog: actions/attest-build-provenance@v3...v3.1.0

Commits
  • a2bbfa2 bump actions/attest from 4.0.0 to 4.1.0 (#838)
  • 0856891 update RELEASE.md docs (#836)
  • e4d4f7c prepare v4 release (#835)
  • 02a49bd Bump github/codeql-action in the actions-minor group (#824)
  • 7c757df Bump the npm-development group with 2 updates (#825)
  • c44148e Bump github/codeql-action in the actions-minor group (#818)
  • 3234352 Bump @​types/node from 25.0.10 to 25.2.0 in the npm-development group (#819)
  • 18db129 Bump tar from 7.5.6 to 7.5.7 (#816)
  • 90fadfa Bump @​actions/core from 2.0.1 to 2.0.2 in the npm-production group (#799)
  • 57db8ba Bump the npm-development group across 1 directory with 3 updates (#808)
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Something related to GitHub Actions code labels Nov 1, 2025
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Something related to GitHub Actions code labels Nov 1, 2025
invernizzi
invernizzi previously approved these changes Apr 27, 2026
@invernizzi
Copy link
Copy Markdown
Member

@dependabot recreate

Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 3 to 4.
- [Release notes](https://github.com/actions/attest-build-provenance/releases)
- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md)
- [Commits](actions/attest-build-provenance@v3...v4)

---
updated-dependencies:
- dependency-name: actions/attest-build-provenance
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps): bump actions/attest-build-provenance from 2 to 3 build(deps): bump actions/attest-build-provenance from 3 to 4 Apr 27, 2026
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions/attest-build-provenance-3 branch from 2b91ccf to ff2c1dc Compare April 27, 2026 07:31
@invernizzi invernizzi enabled auto-merge (squash) April 27, 2026 07:39
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 1, 2026

Superseded by #1386.

@dependabot dependabot Bot closed this May 1, 2026
auto-merge was automatically disabled May 1, 2026 06:36

Pull request was closed

@dependabot dependabot Bot deleted the dependabot/github_actions/actions/attest-build-provenance-3 branch May 1, 2026 06:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Something related to GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant