From be6179c2d2beab62b7d62d657181493509d222c4 Mon Sep 17 00:00:00 2001 From: "pulse-triage[bot]" <249995291+pulse-triage[bot]@users.noreply.github.com> Date: Sun, 20 Sep 2026 08:16:44 +0100 Subject: [PATCH] build(ci): refresh reviewed GitHub Actions pins Dependabot #2094, #2095 and #2096 bump actions/setup-go 6.4.0 -> 7.0.0, signpath/github-action-submit-signing-request 2 -> 3.0 and actions/github-script 8.0.0 -> 9.0.0. Each proposal is blocked only by the reviewed pin constants, the workflow-trust allowlist, the release-consumer action manifest and the installer governance assertions that hard-code the previous revisions. Carry all three bumps with those artifacts in one commit so the proposals can be closed as superseded. All three actions keep the node24 runtime and their existing inputs and outputs; no consumer interface, installer behaviour or public contract changes. The deployment-installability and agent-lifecycle workflow references are pin-only. Contract-Neutral: Reviewed action pin refresh with identical node24 consumer interfaces and unchanged inputs/outputs; no public-contract or installer-behaviour delta. Change-source: pulse-maintainer --- .github/workflows/backfill-release-assets.yml | 2 +- .github/workflows/build-and-test.yml | 6 +++--- .github/workflows/build-release-candidate.yml | 8 ++++---- .github/workflows/canonical-governance.yml | 2 +- .github/workflows/canonical-private-governance.yml | 2 +- .github/workflows/compile-release-payload.yml | 4 ++-- .github/workflows/create-release.yml | 6 +++--- .github/workflows/eval-model-matrix.yml | 2 +- .github/workflows/issue-version-label-sync.yml | 2 +- .github/workflows/patrol-qualification-regression.yml | 2 +- .github/workflows/qualify-secure-runtime-release.yml | 2 +- .github/workflows/reclaim-closed-pr-capacity.yml | 2 +- .github/workflows/release-dry-run.yml | 2 +- .github/workflows/root-pair-diagnostic.yml | 2 +- .github/workflows/security-scan.yml | 6 +++--- .github/workflows/signpath-test-signing.yml | 4 ++-- .github/workflows/test-e2e.yml | 2 +- .github/workflows/unified-agent-native.yml | 4 ++-- .github/workflows/update-demo-server.yml | 2 +- .github/workflows/uuid-layout-diagnostic.yml | 2 +- scripts/check_workflow_trust.py | 4 ++-- scripts/installtests/build_release_assets_test.go | 6 +++--- scripts/release_control/action_consumer_manifests.json | 4 ++-- scripts/release_control/release_promotion_policy_test.py | 4 ++-- 24 files changed, 41 insertions(+), 41 deletions(-) diff --git a/.github/workflows/backfill-release-assets.yml b/.github/workflows/backfill-release-assets.yml index d5c7f65c3..1c34b6b21 100644 --- a/.github/workflows/backfill-release-assets.yml +++ b/.github/workflows/backfill-release-assets.yml @@ -29,7 +29,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false diff --git a/.github/workflows/build-and-test.yml b/.github/workflows/build-and-test.yml index e00ff0c8f..00ac6d988 100644 --- a/.github/workflows/build-and-test.yml +++ b/.github/workflows/build-and-test.yml @@ -240,7 +240,7 @@ jobs: - name: Set up Go if: needs.changes.outputs.code == 'true' - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: true @@ -296,7 +296,7 @@ jobs: fetch-depth: 0 - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: true @@ -334,7 +334,7 @@ jobs: path: benchmark-base - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: true diff --git a/.github/workflows/build-release-candidate.yml b/.github/workflows/build-release-candidate.yml index 95f915092..45f219a35 100644 --- a/.github/workflows/build-release-candidate.yml +++ b/.github/workflows/build-release-candidate.yml @@ -282,7 +282,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false @@ -386,7 +386,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false @@ -462,7 +462,7 @@ jobs: - name: Submit SignPath Authenticode request if: ${{ inputs.windows_signing_backend == 'signpath' }} id: signpath - uses: signpath/github-action-submit-signing-request@c92b958760219087e01f8d67a1669ed57afe2627 # v2 + uses: signpath/github-action-submit-signing-request@f6d04783b4569d051e0c80105fe66e82819d0092 # v3.0 with: api-token: ${{ secrets.SIGNPATH_API_TOKEN }} organization-id: ${{ vars.SIGNPATH_ORGANIZATION_ID }} @@ -702,7 +702,7 @@ jobs: test "$(git rev-parse HEAD)" = "${GITHUB_SHA}" - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false diff --git a/.github/workflows/canonical-governance.yml b/.github/workflows/canonical-governance.yml index c606ebaaa..fe6db7666 100644 --- a/.github/workflows/canonical-governance.yml +++ b/.github/workflows/canonical-governance.yml @@ -31,7 +31,7 @@ jobs: path: repos/pulse - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: repos/pulse/go.mod cache: true diff --git a/.github/workflows/canonical-private-governance.yml b/.github/workflows/canonical-private-governance.yml index 24df2f4f0..a8f745448 100644 --- a/.github/workflows/canonical-private-governance.yml +++ b/.github/workflows/canonical-private-governance.yml @@ -59,7 +59,7 @@ jobs: path: repos/pulse-mobile - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: repos/pulse/go.mod cache: false diff --git a/.github/workflows/compile-release-payload.yml b/.github/workflows/compile-release-payload.yml index 7799807bb..f59a08da3 100644 --- a/.github/workflows/compile-release-payload.yml +++ b/.github/workflows/compile-release-payload.yml @@ -59,7 +59,7 @@ jobs: test "$(git rev-parse HEAD)" = "${EXPECTED_SOURCE_SHA}" - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false @@ -134,7 +134,7 @@ jobs: ref: ${{ inputs.source_sha }} - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false diff --git a/.github/workflows/create-release.yml b/.github/workflows/create-release.yml index 7bb147e55..375f89a2d 100644 --- a/.github/workflows/create-release.yml +++ b/.github/workflows/create-release.yml @@ -536,7 +536,7 @@ jobs: cp -r frontend-modern/dist internal/api/frontend-modern/ - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false @@ -582,7 +582,7 @@ jobs: cp -r frontend-modern/dist internal/api/frontend-modern/ - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: true @@ -1343,7 +1343,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false diff --git a/.github/workflows/eval-model-matrix.yml b/.github/workflows/eval-model-matrix.yml index 3bde95360..6f7393799 100644 --- a/.github/workflows/eval-model-matrix.yml +++ b/.github/workflows/eval-model-matrix.yml @@ -40,7 +40,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false diff --git a/.github/workflows/issue-version-label-sync.yml b/.github/workflows/issue-version-label-sync.yml index 772174265..701da9886 100644 --- a/.github/workflows/issue-version-label-sync.yml +++ b/.github/workflows/issue-version-label-sync.yml @@ -32,7 +32,7 @@ jobs: sparse-checkout-cone-mode: false - name: Sync issue version metadata - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: github-token: ${{ steps.triage-token.outputs.token }} script: | diff --git a/.github/workflows/patrol-qualification-regression.yml b/.github/workflows/patrol-qualification-regression.yml index ce857e1b5..bc590997a 100644 --- a/.github/workflows/patrol-qualification-regression.yml +++ b/.github/workflows/patrol-qualification-regression.yml @@ -50,7 +50,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod diff --git a/.github/workflows/qualify-secure-runtime-release.yml b/.github/workflows/qualify-secure-runtime-release.yml index fedb8f2bb..92f9e3f5a 100644 --- a/.github/workflows/qualify-secure-runtime-release.yml +++ b/.github/workflows/qualify-secure-runtime-release.yml @@ -86,7 +86,7 @@ jobs: python3 scripts/write_github_output.py line_ref "origin/${required_branch}" - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: true diff --git a/.github/workflows/reclaim-closed-pr-capacity.yml b/.github/workflows/reclaim-closed-pr-capacity.yml index f53ea018c..1022651e8 100644 --- a/.github/workflows/reclaim-closed-pr-capacity.yml +++ b/.github/workflows/reclaim-closed-pr-capacity.yml @@ -26,7 +26,7 @@ jobs: sparse-checkout-cone-mode: false - name: Cancel unfinished runs for the closed head - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: script: | const cleanup = require(`${process.env.GITHUB_WORKSPACE}/.github/scripts/reclaim-closed-pr-capacity.cjs`); diff --git a/.github/workflows/release-dry-run.yml b/.github/workflows/release-dry-run.yml index 9faa6263f..145838976 100644 --- a/.github/workflows/release-dry-run.yml +++ b/.github/workflows/release-dry-run.yml @@ -314,7 +314,7 @@ jobs: sudo apt-get install -y docker-compose - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false diff --git a/.github/workflows/root-pair-diagnostic.yml b/.github/workflows/root-pair-diagnostic.yml index bc8659565..5fd3aeb47 100644 --- a/.github/workflows/root-pair-diagnostic.yml +++ b/.github/workflows/root-pair-diagnostic.yml @@ -33,7 +33,7 @@ jobs: with: persist-credentials: false fetch-depth: 0 - - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: '1.26.8' cache: false diff --git a/.github/workflows/security-scan.yml b/.github/workflows/security-scan.yml index 9cfd24ec1..c7862e486 100644 --- a/.github/workflows/security-scan.yml +++ b/.github/workflows/security-scan.yml @@ -38,7 +38,7 @@ jobs: - name: Set up Go if: ${{ github.event.schedule != '17 */6 * * *' }} - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod @@ -377,7 +377,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod @@ -404,7 +404,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod diff --git a/.github/workflows/signpath-test-signing.yml b/.github/workflows/signpath-test-signing.yml index 054815e6e..ab712b160 100644 --- a/.github/workflows/signpath-test-signing.yml +++ b/.github/workflows/signpath-test-signing.yml @@ -31,7 +31,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false @@ -104,7 +104,7 @@ jobs: - name: Submit SignPath test-signing request id: signpath - uses: signpath/github-action-submit-signing-request@c92b958760219087e01f8d67a1669ed57afe2627 # v2 + uses: signpath/github-action-submit-signing-request@f6d04783b4569d051e0c80105fe66e82819d0092 # v3.0 with: api-token: ${{ secrets.SIGNPATH_API_TOKEN }} organization-id: ${{ vars.SIGNPATH_ORGANIZATION_ID }} diff --git a/.github/workflows/test-e2e.yml b/.github/workflows/test-e2e.yml index 652dede6c..0c2945067 100644 --- a/.github/workflows/test-e2e.yml +++ b/.github/workflows/test-e2e.yml @@ -92,7 +92,7 @@ jobs: frontend-modern/package-lock.json internal/cloudcp/portal/frontend/package-lock.json - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod - name: Install locked dependencies diff --git a/.github/workflows/unified-agent-native.yml b/.github/workflows/unified-agent-native.yml index b4979d4c5..ca020f2c3 100644 --- a/.github/workflows/unified-agent-native.yml +++ b/.github/workflows/unified-agent-native.yml @@ -79,7 +79,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: true @@ -186,7 +186,7 @@ jobs: persist-credentials: false - name: Set up Go - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: true diff --git a/.github/workflows/update-demo-server.yml b/.github/workflows/update-demo-server.yml index 663be34f7..c45738517 100644 --- a/.github/workflows/update-demo-server.yml +++ b/.github/workflows/update-demo-server.yml @@ -301,7 +301,7 @@ jobs: - name: Set up Go if: inputs.verify_only != true - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false diff --git a/.github/workflows/uuid-layout-diagnostic.yml b/.github/workflows/uuid-layout-diagnostic.yml index 3ad2deb39..0a160849f 100644 --- a/.github/workflows/uuid-layout-diagnostic.yml +++ b/.github/workflows/uuid-layout-diagnostic.yml @@ -33,7 +33,7 @@ jobs: with: persist-credentials: false fetch-depth: 0 - - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 + - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: '1.26.7' cache: false diff --git a/scripts/check_workflow_trust.py b/scripts/check_workflow_trust.py index 97f2c03a5..dded0a208 100644 --- a/scripts/check_workflow_trust.py +++ b/scripts/check_workflow_trust.py @@ -155,7 +155,7 @@ GENERATED_CODE_ACTION_INPUTS = { SAFE_PULL_REQUEST_TARGET_WORKFLOW = "reclaim-closed-pr-capacity.yml" SAFE_PULL_REQUEST_TARGET_ACTIONS = ( "actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1", - "actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd", + "actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3", ) # v7.0.1 includes checkout's fail-closed fork-PR protection for privileged # pull_request_target and workflow_run events. Keep this exact-pin allowlist @@ -172,7 +172,7 @@ REVIEWED_NODE24_ACTION_PINS = { {"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c"} ), "actions/github-script@": frozenset( - {"ed597411d8f924073f98dfc5c65a23a2325f34cd"} + {"3a2844b7e9c422d3c10d287c895573f7108da1b3"} ), } WRITE_CREDENTIAL_RATIONALE = "# required: authenticated git writes" diff --git a/scripts/installtests/build_release_assets_test.go b/scripts/installtests/build_release_assets_test.go index 467324fcc..8c2678b9a 100644 --- a/scripts/installtests/build_release_assets_test.go +++ b/scripts/installtests/build_release_assets_test.go @@ -1427,7 +1427,7 @@ func TestBackfillReleaseWorkflowRepairsPublishedAssetsWithoutRebuilds(t *testing `contents: write`, `runs-on: ubuntu-24.04`, `uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1`, - `uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0`, + `uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0`, `SYFT_VERSION="1.42.4"`, `SYFT_ARCHIVE="syft_${SYFT_VERSION}_linux_amd64.tar.gz"`, `SYFT_SHA256="590650c2743b83f327d1bf9bec64f6f83b7fec504187bb84f500c862bf8f2a0f"`, @@ -1747,7 +1747,7 @@ func TestReleaseCandidateRequiresPlatformNativeAgentSigning(t *testing.T) { `sign-windows-agent:`, `collect-windows-signing:`, `windows_signing_backend:`, - `signpath/github-action-submit-signing-request@c92b958760219087e01f8d67a1669ed57afe2627 # v2`, + `signpath/github-action-submit-signing-request@f6d04783b4569d051e0c80105fe66e82819d0092 # v3.0`, `github-artifact-id: ${{ steps.upload-unsigned-windows.outputs.artifact-id }}`, `wait-for-completion: false`, `windows-signing-request.json`, @@ -2279,7 +2279,7 @@ func TestUpdateDemoWorkflowUsesGovernedNetworkPath(t *testing.T) { `Waiting for activated release assets to be available`, `bash /tmp/pulse-install.sh --version "$TAG"`, `Refuse mutation during verification-only checks`, - `uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0`, + `uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0`, `go run ./scripts/release_update_key.go public-key-ssh`, `sed -i "s|^PINNED_RELEASE_SSH_PUBLIC_KEY=.*|PINNED_RELEASE_SSH_PUBLIC_KEY=\"${TRUSTED_SSH_PUBLIC_KEY}\"|" /tmp/pulse-install.sh`, `Verify target host identity`, diff --git a/scripts/release_control/action_consumer_manifests.json b/scripts/release_control/action_consumer_manifests.json index 114486075..876faf91f 100644 --- a/scripts/release_control/action_consumer_manifests.json +++ b/scripts/release_control/action_consumer_manifests.json @@ -165,8 +165,8 @@ } }, "signpath/github-action-submit-signing-request": { - "sha": "c92b958760219087e01f8d67a1669ed57afe2627", - "manifest_sha256": "d0b52fdfa234d87c1ff4d21c06a91d2b6e0dd45e1a8866ad3b58cbdeb9aef326", + "sha": "f6d04783b4569d051e0c80105fe66e82819d0092", + "manifest_sha256": "9afe14756752bb0b43421bf94e7cebdc3fead29765be4f07fbc60d82421ebc23", "inputs": [ "api-token", "artifact-configuration-slug", diff --git a/scripts/release_control/release_promotion_policy_test.py b/scripts/release_control/release_promotion_policy_test.py index ffe55f628..09df57eba 100644 --- a/scripts/release_control/release_promotion_policy_test.py +++ b/scripts/release_control/release_promotion_policy_test.py @@ -1632,7 +1632,7 @@ class ReleasePromotionPolicyTest(unittest.TestCase): workflow, ) self.assertIn( - "signpath/github-action-submit-signing-request@c92b958760219087e01f8d67a1669ed57afe2627 # v2", + "signpath/github-action-submit-signing-request@f6d04783b4569d051e0c80105fe66e82819d0092 # v3.0", workflow, ) self.assertIn("signedArtifactsPublished = $false", workflow) @@ -2008,7 +2008,7 @@ class ReleasePromotionPolicyTest(unittest.TestCase): self.assertIn("windows_signing_backend: signpath", content) self.assertIn('if [[ "$REQUIRE_WINDOWS_SIGNING" == "true" ]]', candidate_workflow) self.assertIn("inputs.require_windows_signing", candidate_workflow) - self.assertIn("signpath/github-action-submit-signing-request@c92b958760219087e01f8d67a1669ed57afe2627 # v2", candidate_workflow) + self.assertIn("signpath/github-action-submit-signing-request@f6d04783b4569d051e0c80105fe66e82819d0092 # v3.0", candidate_workflow) self.assertIn("github-artifact-id: ${{ steps.upload-unsigned-windows.outputs.artifact-id }}", candidate_workflow) self.assertIn("windows-signing-evidence.json", candidate_workflow) for signpath_setting in (