30
30
packages : write # needed for ghcr access
31
31
steps :
32
32
- name : Checkout
33
- uses : actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
33
+ uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
34
34
- name : Setup Kustomize
35
35
uses : fluxcd/pkg/actions/kustomize@main
36
36
- name : Prepare
@@ -42,16 +42,16 @@ jobs:
42
42
fi
43
43
echo "version=${VERSION}" >> $GITHUB_OUTPUT
44
44
- name : Setup Go
45
- uses : actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2
45
+ uses : actions/setup-go@41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed # v5.1.0
46
46
with :
47
47
go-version : 1.23.x
48
48
cache-dependency-path : |
49
49
**/go.sum
50
50
**/go.mod
51
51
- uses : docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3.2.0
52
- - uses : docker/setup-buildx-action@988b5a0280414f521da01fcc63a27aeeb4b104db # v3.6 .1
53
- - uses : sigstore/cosign-installer@4959ce089c160fddf62f7b42464195ba1a56d382 # v3.6 .0
54
- - uses : anchore/sbom-action/download-syft@61119d458adab75f756bc0b9e4bde25725f86a7a # v0.17.2
52
+ - uses : docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7 .1
53
+ - uses : sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da # v3.7 .0
54
+ - uses : anchore/sbom-action/download-syft@55dc4ee22412511ee8c3142cbea40418e6cec693 # v0.17.8
55
55
- name : Docker login ghcr.io
56
56
uses : docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
57
57
with :
@@ -65,15 +65,15 @@ jobs:
65
65
password : ${{ secrets.DOCKER_FLUXCD_PASSWORD }}
66
66
- name : Docker meta
67
67
id : meta
68
- uses : docker/metadata-action@8e5442c4ef9f78752691e2d8f8d19755c6f78e81 # v5.5 .1
68
+ uses : docker/metadata-action@369eb591f429131d6889c46b94e711f089e6ca96 # v5.6 .1
69
69
with :
70
70
images : |
71
71
fluxcd/${{ env.CONTROLLER }}
72
72
ghcr.io/fluxcd/${{ env.CONTROLLER }}
73
73
tags : |
74
74
type=raw,value=${{ steps.prep.outputs.version }}
75
75
- name : Docker push
76
- uses : docker/build-push-action@5cd11c3a4ced054e52742c5fd54dca954e0edd85 # v6.7 .0
76
+ uses : docker/build-push-action@48aba3b46d1b1fec4febb7c5d0c644b249a11355 # v6.10 .0
77
77
id : build-push
78
78
with :
79
79
sbom : true
94
94
- name : GoReleaser publish signed SBOM
95
95
id : run-goreleaser
96
96
if : startsWith(github.ref, 'refs/tags/v')
97
- uses : goreleaser/goreleaser-action@286f3b13b1b49da4ac219696163fb8c1c93e1200 # v6.0 .0
97
+ uses : goreleaser/goreleaser-action@9ed2f89a662bf1735a48bc8557fd212fa902bebf # v6.1 .0
98
98
with :
99
99
version : latest
100
100
args : release --clean --skip-validate
0 commit comments