diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 10ae03226..2cc0bf9d8 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -81,7 +81,7 @@ jobs: ./dist/*.apk key: ${{ runner.os }}-go-${{ hashFiles('**/*.go') }}-${{ hashFiles('**/go.sum') }} - uses: sigstore/cosign-installer@ab3bb6a537fb08a1b78f7d1175fff799ca6850a3 # v2.1.0 - - uses: anchore/sbom-action/download-syft@ce4a7cf05d7b684693d7b6bba97bfbee56806edb # v0.7.0 + - uses: anchore/sbom-action/download-syft@2ad78246293830258e98b4e707b1fb02d0242828 # v0.7.0 - name: setup-validate-krew-manifest # TODO: replace this once https://github.com/kubernetes-sigs/krew/pull/736 is merged run: go install github.com/caarlos0/krew/cmd/validate-krew-manifest@fork