chore(deps): bump actions/attest from 4.1.0 to 4.2.2 - #8
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [actions/attest](https://github.com/actions/attest) from 4.1.0 to 4.2.2. - [Release notes](https://github.com/actions/attest/releases) - [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md) - [Commits](actions/attest@59d8942...1e69f48) --- updated-dependencies: - dependency-name: actions/attest dependency-version: 4.2.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
* chore(deps): update Material for MkDocs to 9.7.7 * ci(deps): bump pinned workflow actions Apply the five open Dependabot GitHub Actions proposals in one change: - github/codeql-action/upload-sarif 4.36.2 -> 4.37.9 (PR #6) - actions/attest-build-provenance 4.1.1 -> 4.2.2 (PR #7) - actions/attest 4.1.0 -> 4.2.2 (PR #8) - actions/deploy-pages 5.0.0 -> 5.0.1 (PR #9) - anchore/sbom-action/download-syft 0.24.0 -> 0.24.2 (PR #10) Every SHA was verified against the upstream tag object, and the inputs used here (sarif_file/category, subject-checksums, subject-name/digest, push-to-registry) plus the deploy-pages page_url output are unchanged in the new revisions. download-syft now installs Syft v1.51.1 instead of v1.42.3; SPDX JSON still defaults to 2.3, so the goreleaser and apko SBOM paths keep producing what actions/attest-sbom consumes. * chore(deps): update proxy Testify to 1.12.1 * docs(proxy): explain the MCP SDK compatibility constraint * test(proxy): wait for applied logging levels Acknowledge logging/setLevel only after the SDK handler succeeds so the passthrough test cannot emit its message before logging is enabled.
|
Superseded by #14 (merged). This exact dependency update passed strict CI and the binary/container release rehearsal: https://github.com/meigma/template-mcp-codemode/actions/runs/34610639151. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps actions/attest from 4.1.0 to 4.2.2.
Release notes
Sourced from actions/attest's releases.
Commits
1e69f48Bump ip-address from 10.2.0 to 10.4.0 (#467)02787ceBump brace-expansion (#468)98ac037bump@sigstore/ocifrom 0.7.1 to 0.7.2 (#469)508db95fix: strip OCI image tag when pushing attestation to registry (#464)dda48f2Bump the npm-development group across 1 directory with 6 updates (#461)7d789a3Bump the actions-minor group with 3 updates (#463)1f3ca2fAdd release-cutter canvas extension (#454)d215549Bump tar from 7.5.17 to 7.5.21 (#459)20c90edBump the npm-development group with 2 updates (#455)43c2c81Bump the actions-minor group with 4 updates (#456)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)