@@ -45,20 +45,20 @@ jobs:
4545
4646 steps :
4747 - name : Checkout repository
48- uses : actions/checkout@v4
48+ uses : actions/checkout@v6
4949
5050 - name : Set up Docker Buildx
51- uses : docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3.10 .0
51+ uses : docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12 .0
5252
5353 - name : Log in to the Container registry
54- uses : docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4 .0
54+ uses : docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7 .0
5555 with :
5656 registry : ${{ env.REGISTRY }}
5757 username : ${{ github.actor }}
5858 password : ${{ secrets.GITHUB_TOKEN }}
5959
6060 - name : Set Container Metadata
61- uses : docker/metadata-action@902fa8ec7d6ecbf8d84d538b9b233a880e428804
61+ uses : docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051
6262 id : meta
6363 with :
6464 images : ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
7272 type=semver,pattern=v{{major}}.{{minor}},value=${{ inputs.version }}
7373
7474 - name : Build & Publish Container ${{ env.IMAGE_NAME }}
75- uses : docker/build-push-action@471d1dc4e07e5cdedd4c2171150001c434f0b7a4 # v6.15 .0
75+ uses : docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18 .0
7676 id : build
7777 with :
7878 file : " ${{ inputs.container-file }}"
@@ -85,20 +85,20 @@ jobs:
8585
8686 # Upload Software Bill of Materials (SBOM) to GitHub
8787 - name : Upload SBOM
88- uses : advanced-security/spdx-dependency-submission-action@5530bab9ee4bbe66420ce8280624036c77f89746 # v0.1.1
88+ uses : advanced-security/spdx-dependency-submission-action@f957edbb35161c1f9e33f61026fc86a671c58cae # v0.1.2
8989 with :
9090 filePath : ' .'
9191 filePattern : ' *.spdx.json'
9292
9393 # Build provenance attestations
9494 - name : Attest Container Image
95- uses : actions/attest-build-provenance@c074443f1aee8d4aeeae555aebba3282517141b2 # v2 .2.3
95+ uses : actions/attest-build-provenance@96278af6caaf10aea03fd8d33a09a777ca52d62f # v3 .2.0
9696 with :
9797 subject-name : ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
9898 subject-digest : ${{ steps.build.outputs.digest }}
9999 push-to-registry : true
100100
101101 # - name: Attest Container SBOM
102- # uses: actions/attest-build-provenance@c074443f1aee8d4aeeae555aebba3282517141b2 # v2 .2.3
102+ # uses: actions/attest-build-provenance@96278af6caaf10aea03fd8d33a09a777ca52d62f # v3 .2.0
103103 # with:
104104 # subject-path:: '*.spdx.json'
0 commit comments