Skip to content

chore(publish): bump intra-repo action pins to v0.9.0#49

Merged
vadimpiven merged 1 commit intomainfrom
chore/bump-intra-repo-actions-v0.9.0
Apr 22, 2026
Merged

chore(publish): bump intra-repo action pins to v0.9.0#49
vadimpiven merged 1 commit intomainfrom
chore/bump-intra-repo-actions-v0.9.0

Conversation

@vadimpiven
Copy link
Copy Markdown
Owner

Activates the v0.9.0 attest-addons and verify-addons actions: sidecar sigstore bundle flow (replaces the Rekor REST client) and the {url, bundleUrl} AddonUrlMap leaf shape.

Activates the v0.9.0 attest-addons and verify-addons actions: sidecar
sigstore bundle flow (replaces the Rekor REST client) and the
{url, bundleUrl} AddonUrlMap leaf shape.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@gemini-code-assist
Copy link
Copy Markdown

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

@vadimpiven vadimpiven merged commit 000ddac into main Apr 22, 2026
9 of 10 checks passed
@vadimpiven vadimpiven deleted the chore/bump-intra-repo-actions-v0.9.0 branch April 22, 2026 08:28
@greptile-apps
Copy link
Copy Markdown

greptile-apps Bot commented Apr 22, 2026

Greptile Summary

This PR bumps the two intra-repo composite action pins (attest-addons and verify-addons) to the SHA of the previous commit (311ea97…, tagged v0.9.0) and updates the addons input description to reflect the new { url, bundleUrl } AddonUrlMap leaf shape. The two-commit pin-update pattern is clearly documented in the workflow comments and is followed correctly here.

Confidence Score: 5/5

Safe to merge — the change is a routine intra-repo SHA pin bump following the established two-commit pattern.

Only two action SHA pins and one input description string were updated; the pattern is documented in-line and matches the repo's established policy. No logic changes, no new secrets exposure, no migration risk.

No files require special attention.

Important Files Changed

Filename Overview
.github/workflows/publish.yaml Bumps both intra-repo action pins (attest-addons and verify-addons) to SHA 311ea97…, tagged v0.9.0, and updates the addons input description to document the new {url, bundleUrl} leaf shape.

Reviews (1): Last reviewed commit: "chore(publish): bump intra-repo action p..." | Re-trigger Greptile

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant