diff --git a/.github/workflows/attest.yaml b/.github/workflows/attest.yaml index 7d25e22..60f0783 100644 --- a/.github/workflows/attest.yaml +++ b/.github/workflows/attest.yaml @@ -26,7 +26,7 @@ jobs: actions: read pull-requests: read artifact-metadata: write - uses: liatrio/autogov-workflows/.github/workflows/rw-attest-blob.yaml@3d27b7c23ba3de05f8a3bfd3efc617bbe1fb09b6 # v1.1.3 + uses: liatrio/autogov-workflows/.github/workflows/rw-attest-blob.yaml@69ae7bdc931567721161895d6245a27fbab2cd06 # v1.1.5 secrets: inherit with: subject-path: autogov @@ -40,12 +40,12 @@ jobs: contents: read actions: read artifact-metadata: write - uses: liatrio/autogov-workflows/.github/workflows/rw-verify.yaml@3d27b7c23ba3de05f8a3bfd3efc617bbe1fb09b6 # v1.1.3 + uses: liatrio/autogov-workflows/.github/workflows/rw-verify.yaml@69ae7bdc931567721161895d6245a27fbab2cd06 # v1.1.5 secrets: inherit with: build-type: blob blob-artifact-id: ${{ needs.attest-blob.outputs.blob-artifact-id }} - cert-identity: https://github.com/liatrio/autogov-workflows/.github/workflows/rw-attest-blob.yaml@3d27b7c23ba3de05f8a3bfd3efc617bbe1fb09b6 # v1.1.3 + cert-identity: https://github.com/liatrio/autogov-workflows/.github/workflows/rw-attest-blob.yaml@69ae7bdc931567721161895d6245a27fbab2cd06 # v1.1.5 # autogov's own release claims Source L3 (enforced controls), not L4 (review), # so it self-verifies at min_approvals 0; the published bundle stays strict. # zero_approval_merger_allowlist gates main's 0-approval release path on merger