Skip to content

Bump @actions/attest from 3.1.0 to 3.2.0 - #365

Merged
bdehamer merged 1 commit into
mainfrom
bdehamer/attest-toolkit-3.2.0
Feb 26, 2026
Merged

bdehamer merged 1 commit into
mainfrom
bdehamer/attest-toolkit-3.2.0

Conversation

@bdehamer

Copy link
Copy Markdown
Collaborator

Signed-off-by: Brian DeHamer <bdehamer@github.com>
@bdehamer
bdehamer requested a review from a team as a code owner February 26, 2026 19:28
Copilot AI review requested due to automatic review settings February 26, 2026 19:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the @actions/attest dependency from version 3.1.0 to 3.2.0, which includes internal refactoring to extract shared utility functions and reorganize internal file structure. The update involves regenerating the bundled distribution file to include the new version.

Changes:

  • Updated @actions/attest dependency version in package.json and package-lock.json
  • Regenerated dist/index.js bundle with the new @actions/attest version including refactored code

Reviewed changes

Copilot reviewed 1 out of 3 changed files in this pull request and generated no comments.

File Description
package.json Bumped @actions/attest version from ^3.1.0 to ^3.2.0
package-lock.json Updated lockfile with new version, integrity hash, and resolved URL for @actions/attest@3.2.0
dist/index.js Regenerated bundle including refactored @actions/attest code with extracted getUserAgent utility function

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@bdehamer
bdehamer merged commit 8b290b8 into main Feb 26, 2026
9 checks passed
@bdehamer
bdehamer deleted the bdehamer/attest-toolkit-3.2.0 branch February 26, 2026 20:36
renovate Bot added a commit to netresearch/t3x-nr-vault that referenced this pull request Feb 27, 2026
…87)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | minor | `v4.0.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/netresearch/t3x-nr-vault).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4zNi4yIiwidXBkYXRlZEluVmVyIjoiNDMuMzYuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
dubzzz pushed a commit to dubzzz/fast-check that referenced this pull request Feb 27, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | minor | `v4.0.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/dubzzz/fast-check).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4zNi4yIiwidXBkYXRlZEluVmVyIjoiNDMuMzYuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
severinstrobl pushed a commit to severinstrobl/overlap that referenced this pull request Feb 28, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |
|
[actions/download-artifact](https://redirect.github.com/actions/download-artifact)
| action | major | `v7.0.0` → `v8.0.0` |
|
[actions/upload-artifact](https://redirect.github.com/actions/upload-artifact)
| action | major | `v6.0.0` → `v7.0.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Bump tar from 7.5.2 to 7.5.6 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;809](https://redirect.github.com/actions/attest-build-provenance/pull/809)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 2.1.0 to 2.2.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;800](https://redirect.github.com/actions/attest-build-provenance/pull/800)
- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
from 2.0.1 to 2.0.3 in the npm-production group by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;799](https://redirect.github.com/actions/attest-build-provenance/pull/799)
- Bump tar from 7.5.6 to 7.5.7 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;816](https://redirect.github.com/actions/attest-build-provenance/pull/816)
- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

<details>
<summary>actions/download-artifact (actions/download-artifact)</summary>

###
[`v8.0.0`](https://redirect.github.com/actions/download-artifact/releases/tag/v8.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v7.0.0...v8.0.0)

#### v8 - What's new

##### Direct downloads

To support direct uploads in `actions/upload-artifact`, the action will
no longer attempt to unzip all downloaded files. Instead, the action
checks the `Content-Type` header ahead of unzipping and skips non-zipped
files. Callers wishing to download a zipped file as-is can also set the
new `skip-decompress` parameter to `false`.

##### Enforced checks (breaking)

A previous release introduced digest checks on the download. If a
download hash didn't match the expected hash from the server, the action
would log a warning. Callers can now configure the behavior on mismatch
with the `digest-mismatch` parameter. To be secure by default, we are
now defaulting the behavior to `error` which will fail the workflow run.

##### ESM

To support new versions of the @&#8203;actions/\* packages, we've
upgraded the package to ESM.

#### What's Changed

- Don't attempt to un-zip non-zipped downloads by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;460](https://redirect.github.com/actions/download-artifact/pull/460)
- Add a setting to specify what to do on hash mismatch and default it to
`error` by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;461](https://redirect.github.com/actions/download-artifact/pull/461)

**Full Changelog**:
<actions/download-artifact@v7...v8.0.0>

</details>

<details>
<summary>actions/upload-artifact (actions/upload-artifact)</summary>

###
[`v7.0.0`](https://redirect.github.com/actions/upload-artifact/releases/tag/v7.0.0)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v6.0.0...v7.0.0)

#### v7 What's new

##### Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can
set the new `archive` parameter to `false` to skip zipping the file
during upload. Right now, we only support single files. The action will
fail if the glob passed resolves to multiple files. The `name` parameter
is also ignored with this setting. Instead, the name of the artifact
will be the name of the uploaded file.

##### ESM

To support new versions of the `@actions/*` packages, we've upgraded the
package to ESM.

#### What's Changed

- Add proxy integration test by
[@&#8203;Link-](https://redirect.github.com/Link-) in
[#&#8203;754](https://redirect.github.com/actions/upload-artifact/pull/754)
- Upgrade the module to ESM and bump dependencies by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;762](https://redirect.github.com/actions/upload-artifact/pull/762)
- Support direct file uploads by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;764](https://redirect.github.com/actions/upload-artifact/pull/764)

#### New Contributors

- [@&#8203;Link-](https://redirect.github.com/Link-) made their first
contribution in
[#&#8203;754](https://redirect.github.com/actions/upload-artifact/pull/754)

**Full Changelog**:
<actions/upload-artifact@v6...v7.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/severinstrobl/overlap).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4zNi4yIiwidXBkYXRlZEluVmVyIjoiNDMuMzYuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwicmVub3ZhdGUiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
denialhaag added a commit to munich-quantum-toolkit/yaqs that referenced this pull request Feb 28, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-toolkit/yaqs).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
denialhaag added a commit to munich-quantum-toolkit/qcec that referenced this pull request Feb 28, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-toolkit/qcec).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
denialhaag added a commit to munich-quantum-toolkit/ionshuttler that referenced this pull request Feb 28, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-toolkit/ionshuttler).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
denialhaag added a commit to munich-quantum-toolkit/bench that referenced this pull request Feb 28, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-toolkit/bench).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
denialhaag added a commit to munich-quantum-toolkit/ddsim that referenced this pull request Feb 28, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-toolkit/ddsim).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
denialhaag added a commit to munich-quantum-toolkit/qecc that referenced this pull request Feb 28, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-toolkit/qecc).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
denialhaag added a commit to munich-quantum-toolkit/qmap that referenced this pull request Feb 28, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-toolkit/qmap).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
denialhaag added a commit to munich-quantum-toolkit/predictor that referenced this pull request Feb 28, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-toolkit/predictor).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
denialhaag added a commit to munich-quantum-toolkit/naviz that referenced this pull request Mar 1, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-toolkit/naviz).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
denialhaag added a commit to munich-quantum-toolkit/qusat that referenced this pull request Mar 1, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-toolkit/qusat).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
denialhaag added a commit to munich-quantum-toolkit/syrec that referenced this pull request Mar 1, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-toolkit/syrec).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
denialhaag added a commit to munich-quantum-toolkit/problemsolver that referenced this pull request Mar 1, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-toolkit/problemsolver).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
denialhaag added a commit to munich-quantum-toolkit/qudits that referenced this pull request Mar 2, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-toolkit/qudits).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
boomanaiden154 pushed a commit to llvm/llvm-project that referenced this pull request Mar 2, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.1.0` → `v4.1.0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/160328) for more information.

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

###
[`v3.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.1.0...v3.2.0)

#### What's Changed

- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
from 1.11.1 to 2.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;776](https://redirect.github.com/actions/attest-build-provenance/pull/776)
- Add more documentation on Artifact Metadata Storage Records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;797](https://redirect.github.com/actions/attest-build-provenance/pull/797)
- Update actions/attest to latest version v3.2.0 by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;812](https://redirect.github.com/actions/attest-build-provenance/pull/812)

**Full Changelog**:
<actions/attest-build-provenance@v3.1.0...v3.2.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 12:00 AM and 12:59 AM, only on
Monday ( * 0 * * 1 ) (UTC), Automerge - At any time (no schedule
defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/llvm/llvm-project).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
llvm-sync Bot pushed a commit to arm/arm-toolchain that referenced this pull request Mar 2, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.1.0` → `v4.1.0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/160328) for more information.

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

###
[`v3.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.1.0...v3.2.0)

#### What's Changed

- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
from 1.11.1 to 2.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;776](https://redirect.github.com/actions/attest-build-provenance/pull/776)
- Add more documentation on Artifact Metadata Storage Records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;797](https://redirect.github.com/actions/attest-build-provenance/pull/797)
- Update actions/attest to latest version v3.2.0 by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;812](https://redirect.github.com/actions/attest-build-provenance/pull/812)

**Full Changelog**:
<actions/attest-build-provenance@v3.1.0...v3.2.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 12:00 AM and 12:59 AM, only on
Monday ( * 0 * * 1 ) (UTC), Automerge - At any time (no schedule
defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/llvm/llvm-project).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
renovate-sh-app Bot added a commit to grafana/grafana-opentelemetry-java that referenced this pull request Mar 2, 2026
…1201)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | minor | `v4.0.0` → `v4.1.0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/1133) for more information.

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

## Need help?
You can ask for more help in the following Slack channel:
#proj-renovate-self-hosted. In that channel you can also find ADR and
FAQ docs in the Resources section.

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4zMC4xIiwidXBkYXRlZEluVmVyIjoiNDMuMzAuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsidXBkYXRlLW1pbm9yIl19-->

Signed-off-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
Co-authored-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
renovate-sh-app Bot added a commit to grafana/docker-otel-lgtm that referenced this pull request Mar 2, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/920) for more information.

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

##### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

## Need help?
You can ask for more help in the following Slack channel:
#proj-renovate-self-hosted. In that channel you can also find ADR and
FAQ docs in the Resources section.

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4zMC4xIiwidXBkYXRlZEluVmVyIjoiNDMuMzAuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsidXBkYXRlLW1ham9yIl19-->

Signed-off-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
Co-authored-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
denialhaag added a commit to munich-quantum-toolkit/core-plugins-catalyst that referenced this pull request Mar 2, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-toolkit/core-plugins-catalyst).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
sahas3 pushed a commit to sahas3/llvm-project that referenced this pull request Mar 4, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.1.0` → `v4.1.0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](..llvm/issues/160328) for more information.

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&llvm#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&llvm#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&llvm#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&llvm#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&llvm#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&llvm#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&llvm#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&llvm#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&llvm#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&llvm#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

###
[`v3.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.1.0...v3.2.0)

#### What's Changed

- Bump [@&llvm#8203;actions/core](https://redirect.github.com/actions/core)
from 1.11.1 to 2.0.1 by
[@&llvm#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&llvm#8203;776](https://redirect.github.com/actions/attest-build-provenance/pull/776)
- Add more documentation on Artifact Metadata Storage Records by
[@&llvm#8203;malancas](https://redirect.github.com/malancas) in
[#&llvm#8203;797](https://redirect.github.com/actions/attest-build-provenance/pull/797)
- Update actions/attest to latest version v3.2.0 by
[@&llvm#8203;malancas](https://redirect.github.com/malancas) in
[#&llvm#8203;812](https://redirect.github.com/actions/attest-build-provenance/pull/812)

**Full Changelog**:
<actions/attest-build-provenance@v3.1.0...v3.2.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 12:00 AM and 12:59 AM, only on
Monday ( * 0 * * 1 ) (UTC), Automerge - At any time (no schedule
defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/llvm/llvm-project).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
sujianIBM pushed a commit to sujianIBM/llvm-project that referenced this pull request Mar 5, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.1.0` → `v4.1.0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](..llvm/issues/160328) for more information.

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&llvm#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&llvm#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&llvm#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&llvm#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&llvm#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&llvm#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&llvm#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&llvm#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&llvm#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&llvm#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

###
[`v3.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.1.0...v3.2.0)

#### What's Changed

- Bump [@&llvm#8203;actions/core](https://redirect.github.com/actions/core)
from 1.11.1 to 2.0.1 by
[@&llvm#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&llvm#8203;776](https://redirect.github.com/actions/attest-build-provenance/pull/776)
- Add more documentation on Artifact Metadata Storage Records by
[@&llvm#8203;malancas](https://redirect.github.com/malancas) in
[#&llvm#8203;797](https://redirect.github.com/actions/attest-build-provenance/pull/797)
- Update actions/attest to latest version v3.2.0 by
[@&llvm#8203;malancas](https://redirect.github.com/malancas) in
[#&llvm#8203;812](https://redirect.github.com/actions/attest-build-provenance/pull/812)

**Full Changelog**:
<actions/attest-build-provenance@v3.1.0...v3.2.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 12:00 AM and 12:59 AM, only on
Monday ( * 0 * * 1 ) (UTC), Automerge - At any time (no schedule
defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/llvm/llvm-project).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
naa0yama added a commit to naa0yama/boilerplate-rust that referenced this pull request Mar 9, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |
|
[actions/download-artifact](https://redirect.github.com/actions/download-artifact)
| action | major | `v7.0.0` → `v8.0.0` |
|
[actions/upload-artifact](https://redirect.github.com/actions/upload-artifact)
| action | major | `v6.0.0` → `v7.0.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

<details>
<summary>actions/download-artifact (actions/download-artifact)</summary>

###
[`v8.0.0`](https://redirect.github.com/actions/download-artifact/releases/tag/v8.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v7.0.0...v8.0.0)

##### v8 - What's new

##### Direct downloads

To support direct uploads in `actions/upload-artifact`, the action will
no longer attempt to unzip all downloaded files. Instead, the action
checks the `Content-Type` header ahead of unzipping and skips non-zipped
files. Callers wishing to download a zipped file as-is can also set the
new `skip-decompress` parameter to `false`.

##### Enforced checks (breaking)

A previous release introduced digest checks on the download. If a
download hash didn't match the expected hash from the server, the action
would log a warning. Callers can now configure the behavior on mismatch
with the `digest-mismatch` parameter. To be secure by default, we are
now defaulting the behavior to `error` which will fail the workflow run.

##### ESM

To support new versions of the @&#8203;actions/\* packages, we've
upgraded the package to ESM.

##### What's Changed

- Don't attempt to un-zip non-zipped downloads by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;460](https://redirect.github.com/actions/download-artifact/pull/460)
- Add a setting to specify what to do on hash mismatch and default it to
`error` by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;461](https://redirect.github.com/actions/download-artifact/pull/461)

**Full Changelog**:
<actions/download-artifact@v7...v8.0.0>

</details>

<details>
<summary>actions/upload-artifact (actions/upload-artifact)</summary>

###
[`v7.0.0`](https://redirect.github.com/actions/upload-artifact/releases/tag/v7.0.0)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v6.0.0...v7.0.0)

#### v7 What's new

##### Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can
set the new `archive` parameter to `false` to skip zipping the file
during upload. Right now, we only support single files. The action will
fail if the glob passed resolves to multiple files. The `name` parameter
is also ignored with this setting. Instead, the name of the artifact
will be the name of the uploaded file.

##### ESM

To support new versions of the `@actions/*` packages, we've upgraded the
package to ESM.

#### What's Changed

- Add proxy integration test by
[@&#8203;Link-](https://redirect.github.com/Link-) in
[#&#8203;754](https://redirect.github.com/actions/upload-artifact/pull/754)
- Upgrade the module to ESM and bump dependencies by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;762](https://redirect.github.com/actions/upload-artifact/pull/762)
- Support direct file uploads by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;764](https://redirect.github.com/actions/upload-artifact/pull/764)

#### New Contributors

- [@&#8203;Link-](https://redirect.github.com/Link-) made their first
contribution in
[#&#8203;754](https://redirect.github.com/actions/upload-artifact/pull/754)

**Full Changelog**:
<actions/upload-artifact@v6...v7.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/naa0yama/boilerplate-rust).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40OC4xIiwidXBkYXRlZEluVmVyIjoiNDMuNTYuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGF0YXNvdXJjZTpnaXRodWItdGFncyIsImRlcFR5cGU6YWN0aW9uIiwibWFuYWdlcjpnaXRodWItYWN0aW9ucyIsInJlbm92YXRlIiwidXBkYXRlLW1ham9yIiwidmVyc2lvbmluZzpkb2NrZXIiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Naoki Aoyama <9667078+naa0yama@users.noreply.github.com>
woodruffw pushed a commit to astral-sh/uv that referenced this pull request Mar 9, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 12:00 AM and 03:59 AM, only on
Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule
defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/astral-sh/uv).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My41OS4wIiwidXBkYXRlZEluVmVyIjoiNDMuNTkuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiYnVpbGQ6c2tpcC1kb2NrZXIiLCJidWlsZDpza2lwLXJlbGVhc2UiLCJpbnRlcm5hbCJdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
denialhaag added a commit to munich-quantum-software/amazon-braket-qdmi-device that referenced this pull request Mar 11, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-software/amazon-braket-qdmi-device).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My41OS4wIiwidXBkYXRlZEluVmVyIjoiNDMuNTkuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
naa0yama pushed a commit to naa0yama/chezmage that referenced this pull request Mar 15, 2026
This PR contains the following updates:

| Package | Type | Update | Change | Pending |
|---|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` | |
|
[actions/download-artifact](https://redirect.github.com/actions/download-artifact)
| action | major | `v7.0.0` → `v8.0.0` | `v8.0.1` |
|
[actions/upload-artifact](https://redirect.github.com/actions/upload-artifact)
| action | major | `v6.0.0` → `v7.0.0` | |
| [docker/login-action](https://redirect.github.com/docker/login-action)
| action | major | `v3.7.0` → `v4.0.0` | |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/2) for more information.

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

<details>
<summary>actions/download-artifact (actions/download-artifact)</summary>

###
[`v8.0.0`](https://redirect.github.com/actions/download-artifact/releases/tag/v8.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v7.0.0...v8.0.0)

##### v8 - What's new

##### Direct downloads

To support direct uploads in `actions/upload-artifact`, the action will
no longer attempt to unzip all downloaded files. Instead, the action
checks the `Content-Type` header ahead of unzipping and skips non-zipped
files. Callers wishing to download a zipped file as-is can also set the
new `skip-decompress` parameter to `false`.

##### Enforced checks (breaking)

A previous release introduced digest checks on the download. If a
download hash didn't match the expected hash from the server, the action
would log a warning. Callers can now configure the behavior on mismatch
with the `digest-mismatch` parameter. To be secure by default, we are
now defaulting the behavior to `error` which will fail the workflow run.

##### ESM

To support new versions of the @&#8203;actions/\* packages, we've
upgraded the package to ESM.

##### What's Changed

- Don't attempt to un-zip non-zipped downloads by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;460](https://redirect.github.com/actions/download-artifact/pull/460)
- Add a setting to specify what to do on hash mismatch and default it to
`error` by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;461](https://redirect.github.com/actions/download-artifact/pull/461)

**Full Changelog**:
<actions/download-artifact@v7...v8.0.0>

</details>

<details>
<summary>actions/upload-artifact (actions/upload-artifact)</summary>

###
[`v7.0.0`](https://redirect.github.com/actions/upload-artifact/releases/tag/v7.0.0)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v6.0.0...v7.0.0)

#### v7 What's new

##### Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can
set the new `archive` parameter to `false` to skip zipping the file
during upload. Right now, we only support single files. The action will
fail if the glob passed resolves to multiple files. The `name` parameter
is also ignored with this setting. Instead, the name of the artifact
will be the name of the uploaded file.

##### ESM

To support new versions of the `@actions/*` packages, we've upgraded the
package to ESM.

#### What's Changed

- Add proxy integration test by
[@&#8203;Link-](https://redirect.github.com/Link-) in
[#&#8203;754](https://redirect.github.com/actions/upload-artifact/pull/754)
- Upgrade the module to ESM and bump dependencies by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;762](https://redirect.github.com/actions/upload-artifact/pull/762)
- Support direct file uploads by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;764](https://redirect.github.com/actions/upload-artifact/pull/764)

#### New Contributors

- [@&#8203;Link-](https://redirect.github.com/Link-) made their first
contribution in
[#&#8203;754](https://redirect.github.com/actions/upload-artifact/pull/754)

**Full Changelog**:
<actions/upload-artifact@v6...v7.0.0>

</details>

<details>
<summary>docker/login-action (docker/login-action)</summary>

###
[`v4.0.0`](https://redirect.github.com/docker/login-action/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/docker/login-action/compare/v3.7.0...v4.0.0)

- Node 24 as default runtime (requires [Actions Runner
v2.327.1](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)
or later) by [@&#8203;crazy-max](https://redirect.github.com/crazy-max)
in
[#&#8203;929](https://redirect.github.com/docker/login-action/pull/929)
- Switch to ESM and update config/test wiring by
[@&#8203;crazy-max](https://redirect.github.com/crazy-max) in
[#&#8203;927](https://redirect.github.com/docker/login-action/pull/927)
- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
from 1.11.1 to 3.0.0 in
[#&#8203;919](https://redirect.github.com/docker/login-action/pull/919)
- Bump
[@&#8203;aws-sdk/client-ecr](https://redirect.github.com/aws-sdk/client-ecr)
from 3.890.0 to 3.1000.0 in
[#&#8203;909](https://redirect.github.com/docker/login-action/pull/909)
[#&#8203;920](https://redirect.github.com/docker/login-action/pull/920)
- Bump
[@&#8203;aws-sdk/client-ecr-public](https://redirect.github.com/aws-sdk/client-ecr-public)
from 3.890.0 to 3.1000.0 in
[#&#8203;909](https://redirect.github.com/docker/login-action/pull/909)
[#&#8203;920](https://redirect.github.com/docker/login-action/pull/920)
- Bump
[@&#8203;docker/actions-toolkit](https://redirect.github.com/docker/actions-toolkit)
from 0.63.0 to 0.77.0 in
[#&#8203;910](https://redirect.github.com/docker/login-action/pull/910)
[#&#8203;928](https://redirect.github.com/docker/login-action/pull/928)
- Bump
[@&#8203;isaacs/brace-expansion](https://redirect.github.com/isaacs/brace-expansion)
from 5.0.0 to 5.0.1 in
[#&#8203;921](https://redirect.github.com/docker/login-action/pull/921)
- Bump js-yaml from 4.1.0 to 4.1.1 in
[#&#8203;901](https://redirect.github.com/docker/login-action/pull/901)

**Full Changelog**:
<docker/login-action@v3.7.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/naa0yama/chezmage).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40OC4xIiwidXBkYXRlZEluVmVyIjoiNDMuNTkuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGF0YXNvdXJjZTpnaXRodWItdGFncyIsImRlcFR5cGU6YWN0aW9uIiwibWFuYWdlcjpnaXRodWItYWN0aW9ucyIsInJlbm92YXRlIiwidXBkYXRlLW1ham9yIiwidmVyc2lvbmluZzpkb2NrZXIiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
sharkdp pushed a commit to astral-sh/ty that referenced this pull request Mar 16, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.1.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

###
[`v3.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.1.0...v3.2.0)

#### What's Changed

- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
from 1.11.1 to 2.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;776](https://redirect.github.com/actions/attest-build-provenance/pull/776)
- Add more documentation on Artifact Metadata Storage Records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;797](https://redirect.github.com/actions/attest-build-provenance/pull/797)
- Update actions/attest to latest version v3.2.0 by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;812](https://redirect.github.com/actions/attest-build-provenance/pull/812)

**Full Changelog**:
<actions/attest-build-provenance@v3.1.0...v3.2.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "before 4am on Monday" (UTC),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/astral-sh/ty).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My42Ni40IiwidXBkYXRlZEluVmVyIjoiNDMuNjYuNCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiaW50ZXJuYWwiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Keno-00 pushed a commit to Keno-00/mqt-qudits that referenced this pull request Mar 16, 2026
…ntum-toolkit#270)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-toolkit/qudits).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
dblinkhorn pushed a commit to grafana/generate-policy-bot-config that referenced this pull request Mar 18, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/attest-sbom](https://redirect.github.com/actions/attest-sbom)
| action | minor | `v4.0.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-sbom (actions/attest-sbom)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v4.0.0...v4.1.0)

> \[!WARNING]
> As of version 4.0.0 this action is being deprecated in favor of
[`actions/attest`](https://redirect.github.com/action/attest).
`actions/attest-sbom` will continue to function as a wrapper on top of
`actions/attest` for some period of time, but applications should make
plans to migrate.
>
> All of the existing action inputs are compatible with the
`actions/attest` interface.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;254](https://redirect.github.com/actions/attest-sbom/pull/254)
- Bump actions/attest from 4.0.0 to 4.1.0 in the actions-minor group by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;255](https://redirect.github.com/actions/attest-sbom/pull/255)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-sbom@v4.0.0...v4.1.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

## Need help?
You can ask for more help in the following Slack channel:
#proj-renovate-self-hosted. In that channel you can also find ADR and
FAQ docs in the Resources section.

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My42NS4wIiwidXBkYXRlZEluVmVyIjoiNDMuNjUuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZ2l0aHViLWFjdGlvbnMiLCJ1cGRhdGUtbWlub3IiXX0=-->

Signed-off-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
Co-authored-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
Keno-00 pushed a commit to Keno-00/mqt-qudits that referenced this pull request Mar 19, 2026
…ntum-toolkit#270)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-toolkit/qudits).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
Keno-00 pushed a commit to Keno-00/mqt-qudits that referenced this pull request Mar 20, 2026
…ntum-toolkit#270)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" (UTC), Automerge - At
any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/munich-quantum-toolkit/qudits).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiXX0=-->

---------

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Haag <121057143+denialhaag@users.noreply.github.com>
thedevappsecguy pushed a commit to thedevappsecguy/skill-scanner that referenced this pull request Apr 7, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |
| [astral-sh/setup-uv](https://redirect.github.com/astral-sh/setup-uv) |
action | major | `v7.5.0` → `v8.0.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

<details>
<summary>astral-sh/setup-uv (astral-sh/setup-uv)</summary>

###
[`v8.0.0`](https://redirect.github.com/astral-sh/setup-uv/releases/tag/v8.0.0):
🌈 Immutable releases and secure tags

[Compare
Source](https://redirect.github.com/astral-sh/setup-uv/compare/v7.6.0...v8.0.0)

##### This is the first immutable release of `setup-uv` 🥳

All future releases are also immutable, if you want to know more about
what this means checkout [the
docs](https://docs.github.com/en/code-security/concepts/supply-chain-security/immutable-releases).

This release also has two breaking changes

##### New format for `manifest-file`

The previously deprecated way of defining a custom version manifest to
control which `uv` versions are available and where to download them
from got removed. The functionality is still there but you have to use
the [new
format](https://redirect.github.com/astral-sh/setup-uv/blob/main/docs/customization.md#format).

##### No more major and minor tags

To increase **security** even more we will **stop publishing minor
tags**. You won't be able to use `@v8` or `@v8.0` any longer. We do this
because pinning to major releases opens up users to supply chain attacks
like what happened to
[tj-actions](https://unit42.paloaltonetworks.com/github-actions-supply-chain-attack/).

> \[!TIP]
> Use the immutable tag as a version `astral-sh/setup-uv@v8.0.0`
> Or even better the githash
`astral-sh/setup-uv@cec208311dfd045dd5311c1add060b2062131d57`

##### 🚨 Breaking changes

- Remove update-major-minor-tags workflow
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;826](https://redirect.github.com/astral-sh/setup-uv/issues/826))
- Remove deprecrated custom manifest
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;813](https://redirect.github.com/astral-sh/setup-uv/issues/813))

##### 🧰 Maintenance

- Shortcircuit latest version from manifest
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;828](https://redirect.github.com/astral-sh/setup-uv/issues/828))
- Simplify inputs.ts
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;827](https://redirect.github.com/astral-sh/setup-uv/issues/827))
- Bump release-drafter to v7.1.1
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;825](https://redirect.github.com/astral-sh/setup-uv/issues/825))
- Refactor inputs
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;823](https://redirect.github.com/astral-sh/setup-uv/issues/823))
- Replace inline compile args with tsconfig
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;824](https://redirect.github.com/astral-sh/setup-uv/issues/824))
- chore: update known checksums for 0.11.2
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;821](https://redirect.github.com/astral-sh/setup-uv/issues/821))
- chore: update known checksums for 0.11.1
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;817](https://redirect.github.com/astral-sh/setup-uv/issues/817))
- chore: update known checksums for 0.11.0
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;815](https://redirect.github.com/astral-sh/setup-uv/issues/815))
- Fix latest-version workflow check
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;812](https://redirect.github.com/astral-sh/setup-uv/issues/812))
- chore: update known checksums for 0.10.11/0.10.12
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;811](https://redirect.github.com/astral-sh/setup-uv/issues/811))

###
[`v7.6.0`](https://redirect.github.com/astral-sh/setup-uv/releases/tag/v7.6.0):
🌈 Fetch uv from Astral's mirror by default

[Compare
Source](https://redirect.github.com/astral-sh/setup-uv/compare/v7.5.0...v7.6.0)

##### Changes

We now default to download uv from `releases.astral.sh`.
This means by default we don't hit the GitHub API at all and shouldn't
see any rate limits and timeouts any more.

##### 🚀 Enhancements

- Fetch uv from Astral's mirror by default
[@&#8203;zsol](https://redirect.github.com/zsol)
([#&#8203;809](https://redirect.github.com/astral-sh/setup-uv/issues/809))

##### 🧰 Maintenance

- Switch to ESM for source and test, use CommonJS for dist
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;806](https://redirect.github.com/astral-sh/setup-uv/issues/806))
- chore: update known checksums for 0.10.10
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;804](https://redirect.github.com/astral-sh/setup-uv/issues/804))

##### ⬆️ Dependency updates

- chore(deps): bump zizmorcore/zizmor-action from 0.5.0 to 0.5.2
@&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
([#&#8203;808](https://redirect.github.com/astral-sh/setup-uv/issues/808))
- Bump deps [@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;805](https://redirect.github.com/astral-sh/setup-uv/issues/805))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 12:00 AM and 03:59 AM, only on
Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule
defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/thedevappsecguy/skill-scanner).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDIuMTEiLCJ1cGRhdGVkSW5WZXIiOiI0My4xMDIuMTEiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
alanwiss pushed a commit to WissCore/moldchat that referenced this pull request Apr 26, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v2` → `v4` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/5) for more information.

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

###
[`v4`](https://redirect.github.com/actions/attest-build-provenance/compare/v3...v4)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4)

###
[`v3.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.1.0...v3.2.0)

#### What's Changed

- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
from 1.11.1 to 2.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;776](https://redirect.github.com/actions/attest-build-provenance/pull/776)
- Add more documentation on Artifact Metadata Storage Records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;797](https://redirect.github.com/actions/attest-build-provenance/pull/797)
- Update actions/attest to latest version v3.2.0 by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;812](https://redirect.github.com/actions/attest-build-provenance/pull/812)

**Full Changelog**:
<actions/attest-build-provenance@v3.1.0...v3.2.0>

###
[`v3.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.0.0...v3.1.0)

#### What's Changed

- Prepare v3 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;697](https://redirect.github.com/actions/attest-build-provenance/pull/697)
- Bump js-yaml from 3.14.1 to 3.14.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;749](https://redirect.github.com/actions/attest-build-provenance/pull/749)
- Bump tar from 7.5.1 to 7.5.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;753](https://redirect.github.com/actions/attest-build-provenance/pull/753)
- Bump glob from 10.4.5 to 10.5.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;754](https://redirect.github.com/actions/attest-build-provenance/pull/754)
- Bump [@&#8203;types/node](https://redirect.github.com/types/node) from
24.10.1 to 25.0.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;774](https://redirect.github.com/actions/attest-build-provenance/pull/774)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 1.6.0 to 2.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;736](https://redirect.github.com/actions/attest-build-provenance/pull/736)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 2.0.0 to 2.1.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;775](https://redirect.github.com/actions/attest-build-provenance/pull/775)
- Add support for creating artifact metadata storage records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;779](https://redirect.github.com/actions/attest-build-provenance/pull/779)

#### New Contributors

- [@&#8203;malancas](https://redirect.github.com/malancas) made their
first contribution in
[#&#8203;779](https://redirect.github.com/actions/attest-build-provenance/pull/779)

**Full Changelog**:
<actions/attest-build-provenance@v3...v3.1.0>

###
[`v3`](https://redirect.github.com/actions/attest-build-provenance/compare/v2...v3)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.0.0...v3.0.0)

###
[`v3.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.4.0...v3.0.0)

#### What's Changed

- Adjust node max-http-header-size setting by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;687](https://redirect.github.com/actions/attest-build-provenance/pull/687)
- Bump actions/attest from v2.4.0 to
[v3.0.0](https://redirect.github.com/actions/attest/releases/tag/v3.0.0)
by [@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;691](https://redirect.github.com/actions/attest-build-provenance/pull/691)
  - Bump to node24 runtime
  - Improved checksum parsing
- Bump attest-build-provenance/predicate to v2.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;693](https://redirect.github.com/actions/attest-build-provenance/pull/693)
- Bump to node24 runtime by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;692](https://redirect.github.com/actions/attest-build-provenance/pull/692)

#### ⚠️ Minimum Compatible Runner Version

v2.327.1
[Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

Make sure your runner is updated to this version or newer to use this
release.

**Full Changelog**:
<actions/attest-build-provenance@v2.4.0...v3.0.0>

###
[`v2.4.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.4.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.3.0...v2.4.0)

##### What's Changed

- Bump undici from 5.28.5 to 5.29.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;633](https://redirect.github.com/actions/attest-build-provenance/pull/633)
- Bump actions/attest from 2.3.0 to
[2.4.0](https://redirect.github.com/actions/attest/releases/tag/v2.4.0)
by [@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;654](https://redirect.github.com/actions/attest-build-provenance/pull/654)
- Includes support for the new well-known summary file which will
accumulate paths to all attestations generated in a given workflow run

**Full Changelog**:
<actions/attest-build-provenance@v2.3.0...v2.4.0>

###
[`v2.3.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.3.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.3...v2.3.0)

##### What's Changed

- Bump `actions/attest` from 2.2.1 to 2.3.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;615](https://redirect.github.com/actions/attest-build-provenance/pull/615)
  - Updates `@sigstore/oci` from 0.4.0 to 0.5.0

**Full Changelog**:
<actions/attest-build-provenance@v2.2.3...v2.3.0>

###
[`v2.2.3`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.3)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.2...v2.2.3)

#### What's Changed

- Pin actions/attest reference by commit SHA by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;493](https://redirect.github.com/actions/attest-build-provenance/pull/493)

**Full Changelog**:
<actions/attest-build-provenance@v2.2.2...v2.2.3>

###
[`v2.2.2`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.2)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.1...v2.2.2)

#### What's Changed

- Bump predicate action from 1.1.4 to 1.1.5 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;485](https://redirect.github.com/actions/attest-build-provenance/pull/485)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 1.5.0 to 1.6.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;484](https://redirect.github.com/actions/attest-build-provenance/pull/484)
- Update buildSLSAProvenancePredicate to populate `workflow.ref` field
from the `ref` claim in the OIDC token
([actions/toolkit#1969](https://redirect.github.com/actions/toolkit/pull/1969))

**Full Changelog**:
<actions/attest-build-provenance@v2.2.1...v2.2.2>

###
[`v2.2.1`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.1)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.0...v2.2.1)

#### What's Changed

- Bump undici from 5.28.4 to 5.28.5 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;457](https://redirect.github.com/actions/attest-build-provenance/pull/457)
- Bump
[@&#8203;octokit/request-error](https://redirect.github.com/octokit/request-error)
from 5.0.1 to 5.1.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;469](https://redirect.github.com/actions/attest-build-provenance/pull/469)
- Bump
[@&#8203;octokit/request](https://redirect.github.com/octokit/request)
from 8.2.0 to 8.4.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;478](https://redirect.github.com/actions/attest-build-provenance/pull/478)
- Bump actions/attest from 2.2.0 to 2.2.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;481](https://redirect.github.com/actions/attest-build-provenance/pull/481)
- Includes `@actions/attest`
[v1.6.0](https://redirect.github.com/actions/toolkit/blob/main/packages/attest/RELEASES.md#160)

**Full Changelog**:
<actions/attest-build-provenance@v2.2.0...v2.2.1>

###
[`v2.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.1.0...v2.2.0)

#### What's Changed

- Bump actions/attest from v2.1.0 to v2.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;449](https://redirect.github.com/actions/attest-build-provenance/pull/449)
  - Includes support for now `subject-checksums` input parameter

**Full Changelog**:
<actions/attest-build-provenance@v2.1.0...v2.2.0>

###
[`v2.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.0.1...v2.1.0)

#### What's Changed

- Update README w/ note about GH plans supporting attestations by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;414](https://redirect.github.com/actions/attest-build-provenance/pull/414)
- Add `attestation-id` and `attestation-url` outputs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;415](https://redirect.github.com/actions/attest-build-provenance/pull/415)

**Full Changelog**:
<actions/attest-build-provenance@v2.0.1...v2.1.0>

###
[`v2.0.1`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.0.1)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2...v2.0.1)

#### What's Changed

- Bump actions/attest from 2.0.0 to 2.0.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;406](https://redirect.github.com/actions/attest-build-provenance/pull/406)
  - Deduplicate subjects before adding to in-toto statement

**Full Changelog**:
<actions/attest-build-provenance@v2.0.0...v2.0.1>

</details>

---

### Configuration

📅 **Schedule**: (in timezone UTC)

- Branch creation
  - "before 6am on monday"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/WissCore/moldchat).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNDEuMyIsInVwZGF0ZWRJblZlciI6IjQzLjE0MS4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
alanwiss pushed a commit to WissCore/moldchat that referenced this pull request Apr 26, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/attest-sbom](https://redirect.github.com/actions/attest-sbom)
| action | major | `v2` → `v4` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/5) for more information.

---

### Release Notes

<details>
<summary>actions/attest-sbom (actions/attest-sbom)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v4...v4.1.0)

> \[!WARNING]
> As of version 4.0.0 this action is being deprecated in favor of
[`actions/attest`](https://redirect.github.com/action/attest).
`actions/attest-sbom` will continue to function as a wrapper on top of
`actions/attest` for some period of time, but applications should make
plans to migrate.
>
> All of the existing action inputs are compatible with the
`actions/attest` interface.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;254](https://redirect.github.com/actions/attest-sbom/pull/254)
- Bump actions/attest from 4.0.0 to 4.1.0 in the actions-minor group by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;255](https://redirect.github.com/actions/attest-sbom/pull/255)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-sbom@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v4...v4)

> \[!WARNING]
> As of version 4.0.0 this action is being deprecated in favor of
[`actions/attest`](https://redirect.github.com/action/attest).
`actions/attest-sbom` will continue to function as a wrapper on top of
`actions/attest` for some period of time, but applications should make
plans to migrate.
>
> All of the existing action inputs are compatible with the
`actions/attest` interface.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;253](https://redirect.github.com/actions/attest-sbom/pull/253)

**Full Changelog**:
<actions/attest-sbom@v3...v4.0.0>

###
[`v4`](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v4)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v4)

###
[`v3`](https://redirect.github.com/actions/attest-sbom/compare/v2...v3)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v3.0.0)

###
[`v3.0.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.4.0...v3.0.0)

#### What's Changed

- Adjust node max-http-header-size setting by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;201](https://redirect.github.com/actions/attest-sbom/pull/201)
- Bump actions/attest from v2.4.0 to v3.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;202](https://redirect.github.com/actions/attest-sbom/pull/202)
  - Bump runtime to node24
  - Improved checksum parsing
- Bump attest-sbom/predicate to v2.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;206](https://redirect.github.com/actions/attest-sbom/pull/206)
- Bump predicate runtime to node24 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;204](https://redirect.github.com/actions/attest-sbom/pull/204)

#### ⚠️ Minimum Compatible Runner Version

v2.327.1
[Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

Make sure your runner is updated to this version or newer to use this
release.

**Full Changelog**:
<actions/attest-sbom@v2.4.0...v3.0.0>

###
[`v2.4.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.4.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.2.0...v2.4.0)

#### What's Changed

- Bump actions/attest from 2.2.1 to 2.3.0 in the actions-minor group by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;169](https://redirect.github.com/actions/attest-sbom/pull/169)
- Bump undici from 5.28.5 to 5.29.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;172](https://redirect.github.com/actions/attest-sbom/pull/172)
- Bump actions/attest from 2.3.0 to 2.4.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;178](https://redirect.github.com/actions/attest-sbom/pull/178)
- Includes support for the new well-known summary file which will
accumulate paths to all attestations generated in a given workflow run

**Full Changelog**:
<actions/attest-sbom@v2.2.0...v2.4.0>

###
[`v2.2.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.1.0...v2.2.0)

#### What's Changed

- Bump actions/attest from v2.1.0 to v2.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;148](https://redirect.github.com/actions/attest-sbom/pull/148)
  - Includes support for new `subject-checksums` input parameter

**Full Changelog**:
<actions/attest-sbom@v2.1.0...v2.2.0>

###
[`v2.1.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.0.1...v2.1.0)

#### What's Changed

- Update README w/ note about GH plans supporting attestations by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;136](https://redirect.github.com/actions/attest-sbom/pull/136)
- Add `attestation-id` and `attestation-url` outputs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;137](https://redirect.github.com/actions/attest-sbom/pull/137)

**Full Changelog**:
<actions/attest-sbom@v2.0.1...v2.1.0>

###
[`v2.0.1`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.0.1)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2...v2.0.1)

#### What's Changed

- Bump actions/attest from 2.0.0 to 2.0.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;133](https://redirect.github.com/actions/attest-sbom/pull/133)
  - Deduplicate subjects before adding to in-toto statement

**Full Changelog**:
<actions/attest-sbom@v2.0.0...v2.0.1>

</details>

---

### Configuration

📅 **Schedule**: (in timezone UTC)

- Branch creation
  - "before 6am on monday"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/WissCore/moldchat).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNDEuMyIsInVwZGF0ZWRJblZlciI6IjQzLjE0MS4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Tim275 added a commit to Tim275/drova that referenced this pull request May 15, 2026
📦 Drova Dependency Update — review CHANGELOG before merge.

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v2` → `v4` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/50) for more information.

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

###
[`v4`](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4)

###
[`v3.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.1.0...v3.2.0)

#### What's Changed

- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
from 1.11.1 to 2.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;776](https://redirect.github.com/actions/attest-build-provenance/pull/776)
- Add more documentation on Artifact Metadata Storage Records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;797](https://redirect.github.com/actions/attest-build-provenance/pull/797)
- Update actions/attest to latest version v3.2.0 by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;812](https://redirect.github.com/actions/attest-build-provenance/pull/812)

**Full Changelog**:
<actions/attest-build-provenance@v3.1.0...v3.2.0>

###
[`v3.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.0.0...v3.1.0)

#### What's Changed

- Prepare v3 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;697](https://redirect.github.com/actions/attest-build-provenance/pull/697)
- Bump js-yaml from 3.14.1 to 3.14.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;749](https://redirect.github.com/actions/attest-build-provenance/pull/749)
- Bump tar from 7.5.1 to 7.5.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;753](https://redirect.github.com/actions/attest-build-provenance/pull/753)
- Bump glob from 10.4.5 to 10.5.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;754](https://redirect.github.com/actions/attest-build-provenance/pull/754)
- Bump [@&#8203;types/node](https://redirect.github.com/types/node) from
24.10.1 to 25.0.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;774](https://redirect.github.com/actions/attest-build-provenance/pull/774)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 1.6.0 to 2.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;736](https://redirect.github.com/actions/attest-build-provenance/pull/736)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 2.0.0 to 2.1.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;775](https://redirect.github.com/actions/attest-build-provenance/pull/775)
- Add support for creating artifact metadata storage records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;779](https://redirect.github.com/actions/attest-build-provenance/pull/779)

#### New Contributors

- [@&#8203;malancas](https://redirect.github.com/malancas) made their
first contribution in
[#&#8203;779](https://redirect.github.com/actions/attest-build-provenance/pull/779)

**Full Changelog**:
<actions/attest-build-provenance@v3...v3.1.0>

###
[`v3.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.0.0...v3.0.0)

#### What's Changed

- Adjust node max-http-header-size setting by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;687](https://redirect.github.com/actions/attest-build-provenance/pull/687)
- Bump actions/attest from v2.4.0 to
[v3.0.0](https://redirect.github.com/actions/attest/releases/tag/v3.0.0)
by [@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;691](https://redirect.github.com/actions/attest-build-provenance/pull/691)
  - Bump to node24 runtime
  - Improved checksum parsing
- Bump attest-build-provenance/predicate to v2.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;693](https://redirect.github.com/actions/attest-build-provenance/pull/693)
- Bump to node24 runtime by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;692](https://redirect.github.com/actions/attest-build-provenance/pull/692)

#### ⚠️ Minimum Compatible Runner Version

v2.327.1
[Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

Make sure your runner is updated to this version or newer to use this
release.

**Full Changelog**:
<actions/attest-build-provenance@v2.4.0...v3.0.0>

###
[`v3`](https://redirect.github.com/actions/attest-build-provenance/compare/v2.4.0...v3.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.4.0...v3.0.0)

###
[`v2.4.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.4.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.3.0...v2.4.0)

#### What's Changed

- Bump undici from 5.28.5 to 5.29.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;633](https://redirect.github.com/actions/attest-build-provenance/pull/633)
- Bump actions/attest from 2.3.0 to
[2.4.0](https://redirect.github.com/actions/attest/releases/tag/v2.4.0)
by [@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;654](https://redirect.github.com/actions/attest-build-provenance/pull/654)
- Includes support for the new well-known summary file which will
accumulate paths to all attestations generated in a given workflow run

**Full Changelog**:
<actions/attest-build-provenance@v2.3.0...v2.4.0>

###
[`v2.3.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.3.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.3...v2.3.0)

#### What's Changed

- Bump `actions/attest` from 2.2.1 to 2.3.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;615](https://redirect.github.com/actions/attest-build-provenance/pull/615)
  - Updates `@sigstore/oci` from 0.4.0 to 0.5.0

**Full Changelog**:
<actions/attest-build-provenance@v2.2.3...v2.3.0>

###
[`v2.2.3`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.3)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.2...v2.2.3)

#### What's Changed

- Pin actions/attest reference by commit SHA by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;493](https://redirect.github.com/actions/attest-build-provenance/pull/493)

**Full Changelog**:
<actions/attest-build-provenance@v2.2.2...v2.2.3>

###
[`v2.2.2`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.2)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.1...v2.2.2)

#### What's Changed

- Bump predicate action from 1.1.4 to 1.1.5 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;485](https://redirect.github.com/actions/attest-build-provenance/pull/485)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 1.5.0 to 1.6.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;484](https://redirect.github.com/actions/attest-build-provenance/pull/484)
- Update buildSLSAProvenancePredicate to populate `workflow.ref` field
from the `ref` claim in the OIDC token
([actions/toolkit#1969](https://redirect.github.com/actions/toolkit/pull/1969))

**Full Changelog**:
<actions/attest-build-provenance@v2.2.1...v2.2.2>

###
[`v2.2.1`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.1)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.0...v2.2.1)

#### What's Changed

- Bump undici from 5.28.4 to 5.28.5 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;457](https://redirect.github.com/actions/attest-build-provenance/pull/457)
- Bump
[@&#8203;octokit/request-error](https://redirect.github.com/octokit/request-error)
from 5.0.1 to 5.1.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;469](https://redirect.github.com/actions/attest-build-provenance/pull/469)
- Bump
[@&#8203;octokit/request](https://redirect.github.com/octokit/request)
from 8.2.0 to 8.4.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;478](https://redirect.github.com/actions/attest-build-provenance/pull/478)
- Bump actions/attest from 2.2.0 to 2.2.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;481](https://redirect.github.com/actions/attest-build-provenance/pull/481)
- Includes `@actions/attest`
[v1.6.0](https://redirect.github.com/actions/toolkit/blob/main/packages/attest/RELEASES.md#160)

**Full Changelog**:
<actions/attest-build-provenance@v2.2.0...v2.2.1>

###
[`v2.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.1.0...v2.2.0)

#### What's Changed

- Bump actions/attest from v2.1.0 to v2.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;449](https://redirect.github.com/actions/attest-build-provenance/pull/449)
  - Includes support for now `subject-checksums` input parameter

**Full Changelog**:
<actions/attest-build-provenance@v2.1.0...v2.2.0>

###
[`v2.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.0.1...v2.1.0)

#### What's Changed

- Update README w/ note about GH plans supporting attestations by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;414](https://redirect.github.com/actions/attest-build-provenance/pull/414)
- Add `attestation-id` and `attestation-url` outputs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;415](https://redirect.github.com/actions/attest-build-provenance/pull/415)

**Full Changelog**:
<actions/attest-build-provenance@v2.0.1...v2.1.0>

###
[`v2.0.1`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.0.1)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2...v2.0.1)

#### What's Changed

- Bump actions/attest from 2.0.0 to 2.0.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;406](https://redirect.github.com/actions/attest-build-provenance/pull/406)
  - Deduplicate subjects before adding to in-toto statement

**Full Changelog**:
<actions/attest-build-provenance@v2.0.0...v2.0.1>

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Berlin)

- Branch creation
  - Every minute (`* * * * *`)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzYuMyIsInVwZGF0ZWRJblZlciI6IjQzLjE3Ni4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJtYWpvciIsInJlbm92YXRlIl19-->

Co-authored-by: Renovate Bot <tim275@users.noreply.github.com>
naa0yama added a commit to naa0yama/boilerplate-rust that referenced this pull request May 20, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.2.0` → `v4.1.0` |
|
[actions/download-artifact](https://redirect.github.com/actions/download-artifact)
| action | major | `v7.0.0` → `v8.0.0` |
|
[actions/upload-artifact](https://redirect.github.com/actions/upload-artifact)
| action | major | `v6.0.0` → `v7.0.0` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

</details>

<details>
<summary>actions/download-artifact (actions/download-artifact)</summary>

###
[`v8.0.0`](https://redirect.github.com/actions/download-artifact/releases/tag/v8.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v7.0.0...v8.0.0)

##### v8 - What's new

##### Direct downloads

To support direct uploads in `actions/upload-artifact`, the action will
no longer attempt to unzip all downloaded files. Instead, the action
checks the `Content-Type` header ahead of unzipping and skips non-zipped
files. Callers wishing to download a zipped file as-is can also set the
new `skip-decompress` parameter to `false`.

##### Enforced checks (breaking)

A previous release introduced digest checks on the download. If a
download hash didn't match the expected hash from the server, the action
would log a warning. Callers can now configure the behavior on mismatch
with the `digest-mismatch` parameter. To be secure by default, we are
now defaulting the behavior to `error` which will fail the workflow run.

##### ESM

To support new versions of the @&#8203;actions/\* packages, we've
upgraded the package to ESM.

##### What's Changed

- Don't attempt to un-zip non-zipped downloads by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;460](https://redirect.github.com/actions/download-artifact/pull/460)
- Add a setting to specify what to do on hash mismatch and default it to
`error` by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;461](https://redirect.github.com/actions/download-artifact/pull/461)

**Full Changelog**:
<actions/download-artifact@v7...v8.0.0>

</details>

<details>
<summary>actions/upload-artifact (actions/upload-artifact)</summary>

###
[`v7.0.0`](https://redirect.github.com/actions/upload-artifact/releases/tag/v7.0.0)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v6.0.0...v7.0.0)

#### v7 What's new

##### Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can
set the new `archive` parameter to `false` to skip zipping the file
during upload. Right now, we only support single files. The action will
fail if the glob passed resolves to multiple files. The `name` parameter
is also ignored with this setting. Instead, the name of the artifact
will be the name of the uploaded file.

##### ESM

To support new versions of the `@actions/*` packages, we've upgraded the
package to ESM.

#### What's Changed

- Add proxy integration test by
[@&#8203;Link-](https://redirect.github.com/Link-) in
[#&#8203;754](https://redirect.github.com/actions/upload-artifact/pull/754)
- Upgrade the module to ESM and bump dependencies by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;762](https://redirect.github.com/actions/upload-artifact/pull/762)
- Support direct file uploads by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;764](https://redirect.github.com/actions/upload-artifact/pull/764)

#### New Contributors

- [@&#8203;Link-](https://redirect.github.com/Link-) made their first
contribution in
[#&#8203;754](https://redirect.github.com/actions/upload-artifact/pull/754)

**Full Changelog**:
<actions/upload-artifact@v6...v7.0.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/naa0yama/boilerplate-rust).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40OC4xIiwidXBkYXRlZEluVmVyIjoiNDMuNTYuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGF0YXNvdXJjZTpnaXRodWItdGFncyIsImRlcFR5cGU6YWN0aW9uIiwibWFuYWdlcjpnaXRodWItYWN0aW9ucyIsInJlbm92YXRlIiwidXBkYXRlLW1ham9yIiwidmVyc2lvbmluZzpkb2NrZXIiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Naoki Aoyama <9667078+naa0yama@users.noreply.github.com>
tgrecojr pushed a commit to tgrecojr/soildata that referenced this pull request May 23, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v2` → `v4` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

###
[`v4`](https://redirect.github.com/actions/attest-build-provenance/compare/v3...v4)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4)

###
[`v3.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.1.0...v3.2.0)

#### What's Changed

- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
from 1.11.1 to 2.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;776](https://redirect.github.com/actions/attest-build-provenance/pull/776)
- Add more documentation on Artifact Metadata Storage Records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;797](https://redirect.github.com/actions/attest-build-provenance/pull/797)
- Update actions/attest to latest version v3.2.0 by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;812](https://redirect.github.com/actions/attest-build-provenance/pull/812)

**Full Changelog**:
<actions/attest-build-provenance@v3.1.0...v3.2.0>

###
[`v3.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.0.0...v3.1.0)

#### What's Changed

- Prepare v3 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;697](https://redirect.github.com/actions/attest-build-provenance/pull/697)
- Bump js-yaml from 3.14.1 to 3.14.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;749](https://redirect.github.com/actions/attest-build-provenance/pull/749)
- Bump tar from 7.5.1 to 7.5.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;753](https://redirect.github.com/actions/attest-build-provenance/pull/753)
- Bump glob from 10.4.5 to 10.5.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;754](https://redirect.github.com/actions/attest-build-provenance/pull/754)
- Bump [@&#8203;types/node](https://redirect.github.com/types/node) from
24.10.1 to 25.0.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;774](https://redirect.github.com/actions/attest-build-provenance/pull/774)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 1.6.0 to 2.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;736](https://redirect.github.com/actions/attest-build-provenance/pull/736)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 2.0.0 to 2.1.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;775](https://redirect.github.com/actions/attest-build-provenance/pull/775)
- Add support for creating artifact metadata storage records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;779](https://redirect.github.com/actions/attest-build-provenance/pull/779)

#### New Contributors

- [@&#8203;malancas](https://redirect.github.com/malancas) made their
first contribution in
[#&#8203;779](https://redirect.github.com/actions/attest-build-provenance/pull/779)

**Full Changelog**:
<actions/attest-build-provenance@v3...v3.1.0>

###
[`v3.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.0.0...v3.0.0)

#### What's Changed

- Adjust node max-http-header-size setting by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;687](https://redirect.github.com/actions/attest-build-provenance/pull/687)
- Bump actions/attest from v2.4.0 to
[v3.0.0](https://redirect.github.com/actions/attest/releases/tag/v3.0.0)
by [@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;691](https://redirect.github.com/actions/attest-build-provenance/pull/691)
  - Bump to node24 runtime
  - Improved checksum parsing
- Bump attest-build-provenance/predicate to v2.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;693](https://redirect.github.com/actions/attest-build-provenance/pull/693)
- Bump to node24 runtime by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;692](https://redirect.github.com/actions/attest-build-provenance/pull/692)

#### ⚠️ Minimum Compatible Runner Version

v2.327.1
[Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

Make sure your runner is updated to this version or newer to use this
release.

**Full Changelog**:
<actions/attest-build-provenance@v2.4.0...v3.0.0>

###
[`v3`](https://redirect.github.com/actions/attest-build-provenance/compare/v2...v3)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.4.0...v3.0.0)

###
[`v2.4.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.4.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.3.0...v2.4.0)

##### What's Changed

- Bump undici from 5.28.5 to 5.29.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;633](https://redirect.github.com/actions/attest-build-provenance/pull/633)
- Bump actions/attest from 2.3.0 to
[2.4.0](https://redirect.github.com/actions/attest/releases/tag/v2.4.0)
by [@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;654](https://redirect.github.com/actions/attest-build-provenance/pull/654)
- Includes support for the new well-known summary file which will
accumulate paths to all attestations generated in a given workflow run

**Full Changelog**:
<actions/attest-build-provenance@v2.3.0...v2.4.0>

###
[`v2.3.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.3.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.3...v2.3.0)

##### What's Changed

- Bump `actions/attest` from 2.2.1 to 2.3.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;615](https://redirect.github.com/actions/attest-build-provenance/pull/615)
  - Updates `@sigstore/oci` from 0.4.0 to 0.5.0

**Full Changelog**:
<actions/attest-build-provenance@v2.2.3...v2.3.0>

###
[`v2.2.3`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.3)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.2...v2.2.3)

#### What's Changed

- Pin actions/attest reference by commit SHA by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;493](https://redirect.github.com/actions/attest-build-provenance/pull/493)

**Full Changelog**:
<actions/attest-build-provenance@v2.2.2...v2.2.3>

###
[`v2.2.2`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.2)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.1...v2.2.2)

#### What's Changed

- Bump predicate action from 1.1.4 to 1.1.5 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;485](https://redirect.github.com/actions/attest-build-provenance/pull/485)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 1.5.0 to 1.6.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;484](https://redirect.github.com/actions/attest-build-provenance/pull/484)
- Update buildSLSAProvenancePredicate to populate `workflow.ref` field
from the `ref` claim in the OIDC token
([actions/toolkit#1969](https://redirect.github.com/actions/toolkit/pull/1969))

**Full Changelog**:
<actions/attest-build-provenance@v2.2.1...v2.2.2>

###
[`v2.2.1`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.1)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.0...v2.2.1)

#### What's Changed

- Bump undici from 5.28.4 to 5.28.5 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;457](https://redirect.github.com/actions/attest-build-provenance/pull/457)
- Bump
[@&#8203;octokit/request-error](https://redirect.github.com/octokit/request-error)
from 5.0.1 to 5.1.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;469](https://redirect.github.com/actions/attest-build-provenance/pull/469)
- Bump
[@&#8203;octokit/request](https://redirect.github.com/octokit/request)
from 8.2.0 to 8.4.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;478](https://redirect.github.com/actions/attest-build-provenance/pull/478)
- Bump actions/attest from 2.2.0 to 2.2.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;481](https://redirect.github.com/actions/attest-build-provenance/pull/481)
- Includes `@actions/attest`
[v1.6.0](https://redirect.github.com/actions/toolkit/blob/main/packages/attest/RELEASES.md#160)

**Full Changelog**:
<actions/attest-build-provenance@v2.2.0...v2.2.1>

###
[`v2.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.1.0...v2.2.0)

#### What's Changed

- Bump actions/attest from v2.1.0 to v2.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;449](https://redirect.github.com/actions/attest-build-provenance/pull/449)
  - Includes support for now `subject-checksums` input parameter

**Full Changelog**:
<actions/attest-build-provenance@v2.1.0...v2.2.0>

###
[`v2.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.0.1...v2.1.0)

#### What's Changed

- Update README w/ note about GH plans supporting attestations by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;414](https://redirect.github.com/actions/attest-build-provenance/pull/414)
- Add `attestation-id` and `attestation-url` outputs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;415](https://redirect.github.com/actions/attest-build-provenance/pull/415)

**Full Changelog**:
<actions/attest-build-provenance@v2.0.1...v2.1.0>

###
[`v2.0.1`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.0.1)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2...v2.0.1)

#### What's Changed

- Bump actions/attest from 2.0.0 to 2.0.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;406](https://redirect.github.com/actions/attest-build-provenance/pull/406)
  - Deduplicate subjects before adding to in-toto statement

**Full Changelog**:
<actions/attest-build-provenance@v2.0.0...v2.0.1>

</details>

---

### Configuration

📅 **Schedule**: (in timezone America/New_York)

- Branch creation
  - "after 10pm every weekday,before 5am every weekday,every weekend"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/tgrecojr/soildata).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJtYWpvci11cGRhdGUiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
tgrecojr pushed a commit to tgrecojr/gmailclassifier that referenced this pull request May 23, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v2` → `v4` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

###
[`v4`](https://redirect.github.com/actions/attest-build-provenance/compare/v3...v4)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4)

###
[`v3.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.1.0...v3.2.0)

#### What's Changed

- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
from 1.11.1 to 2.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;776](https://redirect.github.com/actions/attest-build-provenance/pull/776)
- Add more documentation on Artifact Metadata Storage Records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;797](https://redirect.github.com/actions/attest-build-provenance/pull/797)
- Update actions/attest to latest version v3.2.0 by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;812](https://redirect.github.com/actions/attest-build-provenance/pull/812)

**Full Changelog**:
<actions/attest-build-provenance@v3.1.0...v3.2.0>

###
[`v3.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.0.0...v3.1.0)

#### What's Changed

- Prepare v3 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;697](https://redirect.github.com/actions/attest-build-provenance/pull/697)
- Bump js-yaml from 3.14.1 to 3.14.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;749](https://redirect.github.com/actions/attest-build-provenance/pull/749)
- Bump tar from 7.5.1 to 7.5.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;753](https://redirect.github.com/actions/attest-build-provenance/pull/753)
- Bump glob from 10.4.5 to 10.5.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;754](https://redirect.github.com/actions/attest-build-provenance/pull/754)
- Bump [@&#8203;types/node](https://redirect.github.com/types/node) from
24.10.1 to 25.0.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;774](https://redirect.github.com/actions/attest-build-provenance/pull/774)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 1.6.0 to 2.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;736](https://redirect.github.com/actions/attest-build-provenance/pull/736)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 2.0.0 to 2.1.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;775](https://redirect.github.com/actions/attest-build-provenance/pull/775)
- Add support for creating artifact metadata storage records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;779](https://redirect.github.com/actions/attest-build-provenance/pull/779)

#### New Contributors

- [@&#8203;malancas](https://redirect.github.com/malancas) made their
first contribution in
[#&#8203;779](https://redirect.github.com/actions/attest-build-provenance/pull/779)

**Full Changelog**:
<actions/attest-build-provenance@v3...v3.1.0>

###
[`v3.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.0.0...v3.0.0)

#### What's Changed

- Adjust node max-http-header-size setting by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;687](https://redirect.github.com/actions/attest-build-provenance/pull/687)
- Bump actions/attest from v2.4.0 to
[v3.0.0](https://redirect.github.com/actions/attest/releases/tag/v3.0.0)
by [@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;691](https://redirect.github.com/actions/attest-build-provenance/pull/691)
  - Bump to node24 runtime
  - Improved checksum parsing
- Bump attest-build-provenance/predicate to v2.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;693](https://redirect.github.com/actions/attest-build-provenance/pull/693)
- Bump to node24 runtime by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;692](https://redirect.github.com/actions/attest-build-provenance/pull/692)

#### ⚠️ Minimum Compatible Runner Version

v2.327.1
[Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

Make sure your runner is updated to this version or newer to use this
release.

**Full Changelog**:
<actions/attest-build-provenance@v2.4.0...v3.0.0>

###
[`v3`](https://redirect.github.com/actions/attest-build-provenance/compare/v2...v3)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.4.0...v3.0.0)

###
[`v2.4.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.4.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.3.0...v2.4.0)

##### What's Changed

- Bump undici from 5.28.5 to 5.29.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;633](https://redirect.github.com/actions/attest-build-provenance/pull/633)
- Bump actions/attest from 2.3.0 to
[2.4.0](https://redirect.github.com/actions/attest/releases/tag/v2.4.0)
by [@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;654](https://redirect.github.com/actions/attest-build-provenance/pull/654)
- Includes support for the new well-known summary file which will
accumulate paths to all attestations generated in a given workflow run

**Full Changelog**:
<actions/attest-build-provenance@v2.3.0...v2.4.0>

###
[`v2.3.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.3.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.3...v2.3.0)

##### What's Changed

- Bump `actions/attest` from 2.2.1 to 2.3.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;615](https://redirect.github.com/actions/attest-build-provenance/pull/615)
  - Updates `@sigstore/oci` from 0.4.0 to 0.5.0

**Full Changelog**:
<actions/attest-build-provenance@v2.2.3...v2.3.0>

###
[`v2.2.3`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.3)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.2...v2.2.3)

#### What's Changed

- Pin actions/attest reference by commit SHA by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;493](https://redirect.github.com/actions/attest-build-provenance/pull/493)

**Full Changelog**:
<actions/attest-build-provenance@v2.2.2...v2.2.3>

###
[`v2.2.2`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.2)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.1...v2.2.2)

#### What's Changed

- Bump predicate action from 1.1.4 to 1.1.5 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;485](https://redirect.github.com/actions/attest-build-provenance/pull/485)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 1.5.0 to 1.6.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;484](https://redirect.github.com/actions/attest-build-provenance/pull/484)
- Update buildSLSAProvenancePredicate to populate `workflow.ref` field
from the `ref` claim in the OIDC token
([actions/toolkit#1969](https://redirect.github.com/actions/toolkit/pull/1969))

**Full Changelog**:
<actions/attest-build-provenance@v2.2.1...v2.2.2>

###
[`v2.2.1`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.1)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.0...v2.2.1)

#### What's Changed

- Bump undici from 5.28.4 to 5.28.5 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;457](https://redirect.github.com/actions/attest-build-provenance/pull/457)
- Bump
[@&#8203;octokit/request-error](https://redirect.github.com/octokit/request-error)
from 5.0.1 to 5.1.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;469](https://redirect.github.com/actions/attest-build-provenance/pull/469)
- Bump
[@&#8203;octokit/request](https://redirect.github.com/octokit/request)
from 8.2.0 to 8.4.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;478](https://redirect.github.com/actions/attest-build-provenance/pull/478)
- Bump actions/attest from 2.2.0 to 2.2.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;481](https://redirect.github.com/actions/attest-build-provenance/pull/481)
- Includes `@actions/attest`
[v1.6.0](https://redirect.github.com/actions/toolkit/blob/main/packages/attest/RELEASES.md#160)

**Full Changelog**:
<actions/attest-build-provenance@v2.2.0...v2.2.1>

###
[`v2.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.1.0...v2.2.0)

#### What's Changed

- Bump actions/attest from v2.1.0 to v2.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;449](https://redirect.github.com/actions/attest-build-provenance/pull/449)
  - Includes support for now `subject-checksums` input parameter

**Full Changelog**:
<actions/attest-build-provenance@v2.1.0...v2.2.0>

###
[`v2.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.0.1...v2.1.0)

#### What's Changed

- Update README w/ note about GH plans supporting attestations by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;414](https://redirect.github.com/actions/attest-build-provenance/pull/414)
- Add `attestation-id` and `attestation-url` outputs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;415](https://redirect.github.com/actions/attest-build-provenance/pull/415)

**Full Changelog**:
<actions/attest-build-provenance@v2.0.1...v2.1.0>

###
[`v2.0.1`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.0.1)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2...v2.0.1)

#### What's Changed

- Bump actions/attest from 2.0.0 to 2.0.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;406](https://redirect.github.com/actions/attest-build-provenance/pull/406)
  - Deduplicate subjects before adding to in-toto statement

**Full Changelog**:
<actions/attest-build-provenance@v2.0.0...v2.0.1>

</details>

---

### Configuration

📅 **Schedule**: (in timezone America/New_York)

- Branch creation
  - "after 10pm every weekday,before 5am every weekday,every weekend"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/tgrecojr/gmailclassifier).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJtYWpvci11cGRhdGUiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
tgrecojr pushed a commit to tgrecojr/gmailclassifier that referenced this pull request May 23, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/attest-sbom](https://redirect.github.com/actions/attest-sbom)
| action | major | `v2` → `v4` |

---

### Release Notes

<details>
<summary>actions/attest-sbom (actions/attest-sbom)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v4...v4.1.0)

> \[!WARNING]
> As of version 4.0.0 this action is being deprecated in favor of
[`actions/attest`](https://redirect.github.com/action/attest).
`actions/attest-sbom` will continue to function as a wrapper on top of
`actions/attest` for some period of time, but applications should make
plans to migrate.
>
> All of the existing action inputs are compatible with the
`actions/attest` interface.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;254](https://redirect.github.com/actions/attest-sbom/pull/254)
- Bump actions/attest from 4.0.0 to 4.1.0 in the actions-minor group by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;255](https://redirect.github.com/actions/attest-sbom/pull/255)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-sbom@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v4...v4)

> \[!WARNING]
> As of version 4.0.0 this action is being deprecated in favor of
[`actions/attest`](https://redirect.github.com/action/attest).
`actions/attest-sbom` will continue to function as a wrapper on top of
`actions/attest` for some period of time, but applications should make
plans to migrate.
>
> All of the existing action inputs are compatible with the
`actions/attest` interface.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;253](https://redirect.github.com/actions/attest-sbom/pull/253)

**Full Changelog**:
<actions/attest-sbom@v3...v4.0.0>

###
[`v4`](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v4)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v4)

###
[`v3.0.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v3.0.0)

#### What's Changed

- Adjust node max-http-header-size setting by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;201](https://redirect.github.com/actions/attest-sbom/pull/201)
- Bump actions/attest from v2.4.0 to v3.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;202](https://redirect.github.com/actions/attest-sbom/pull/202)
  - Bump runtime to node24
  - Improved checksum parsing
- Bump attest-sbom/predicate to v2.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;206](https://redirect.github.com/actions/attest-sbom/pull/206)
- Bump predicate runtime to node24 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;204](https://redirect.github.com/actions/attest-sbom/pull/204)

#### ⚠️ Minimum Compatible Runner Version

v2.327.1
[Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

Make sure your runner is updated to this version or newer to use this
release.

**Full Changelog**:
<actions/attest-sbom@v2.4.0...v3.0.0>

###
[`v3`](https://redirect.github.com/actions/attest-sbom/compare/v2...v3)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.4.0...v3.0.0)

###
[`v2.4.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.4.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.2.0...v2.4.0)

#### What's Changed

- Bump actions/attest from 2.2.1 to 2.3.0 in the actions-minor group by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;169](https://redirect.github.com/actions/attest-sbom/pull/169)
- Bump undici from 5.28.5 to 5.29.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;172](https://redirect.github.com/actions/attest-sbom/pull/172)
- Bump actions/attest from 2.3.0 to 2.4.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;178](https://redirect.github.com/actions/attest-sbom/pull/178)
- Includes support for the new well-known summary file which will
accumulate paths to all attestations generated in a given workflow run

**Full Changelog**:
<actions/attest-sbom@v2.2.0...v2.4.0>

###
[`v2.2.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.1.0...v2.2.0)

#### What's Changed

- Bump actions/attest from v2.1.0 to v2.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;148](https://redirect.github.com/actions/attest-sbom/pull/148)
  - Includes support for new `subject-checksums` input parameter

**Full Changelog**:
<actions/attest-sbom@v2.1.0...v2.2.0>

###
[`v2.1.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.0.1...v2.1.0)

#### What's Changed

- Update README w/ note about GH plans supporting attestations by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;136](https://redirect.github.com/actions/attest-sbom/pull/136)
- Add `attestation-id` and `attestation-url` outputs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;137](https://redirect.github.com/actions/attest-sbom/pull/137)

**Full Changelog**:
<actions/attest-sbom@v2.0.1...v2.1.0>

###
[`v2.0.1`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.0.1)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2...v2.0.1)

#### What's Changed

- Bump actions/attest from 2.0.0 to 2.0.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;133](https://redirect.github.com/actions/attest-sbom/pull/133)
  - Deduplicate subjects before adding to in-toto statement

**Full Changelog**:
<actions/attest-sbom@v2.0.0...v2.0.1>

</details>

---

### Configuration

📅 **Schedule**: (in timezone America/New_York)

- Branch creation
  - "after 10pm every weekday,before 5am every weekday,every weekend"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/tgrecojr/gmailclassifier).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJtYWpvci11cGRhdGUiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
tgrecojr added a commit to tgrecojr/soildata that referenced this pull request May 23, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/attest-sbom](https://redirect.github.com/actions/attest-sbom)
| action | major | `v2` → `v4` |

---

### Release Notes

<details>
<summary>actions/attest-sbom (actions/attest-sbom)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v4...v4.1.0)

> \[!WARNING]
> As of version 4.0.0 this action is being deprecated in favor of
[`actions/attest`](https://redirect.github.com/action/attest).
`actions/attest-sbom` will continue to function as a wrapper on top of
`actions/attest` for some period of time, but applications should make
plans to migrate.
>
> All of the existing action inputs are compatible with the
`actions/attest` interface.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;254](https://redirect.github.com/actions/attest-sbom/pull/254)
- Bump actions/attest from 4.0.0 to 4.1.0 in the actions-minor group by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;255](https://redirect.github.com/actions/attest-sbom/pull/255)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-sbom@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v4...v4)

> \[!WARNING]
> As of version 4.0.0 this action is being deprecated in favor of
[`actions/attest`](https://redirect.github.com/action/attest).
`actions/attest-sbom` will continue to function as a wrapper on top of
`actions/attest` for some period of time, but applications should make
plans to migrate.
>
> All of the existing action inputs are compatible with the
`actions/attest` interface.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;253](https://redirect.github.com/actions/attest-sbom/pull/253)

**Full Changelog**:
<actions/attest-sbom@v3...v4.0.0>

###
[`v4`](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v4)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v4)

###
[`v3.0.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v3.0.0)

#### What's Changed

- Adjust node max-http-header-size setting by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;201](https://redirect.github.com/actions/attest-sbom/pull/201)
- Bump actions/attest from v2.4.0 to v3.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;202](https://redirect.github.com/actions/attest-sbom/pull/202)
  - Bump runtime to node24
  - Improved checksum parsing
- Bump attest-sbom/predicate to v2.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;206](https://redirect.github.com/actions/attest-sbom/pull/206)
- Bump predicate runtime to node24 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;204](https://redirect.github.com/actions/attest-sbom/pull/204)

#### ⚠️ Minimum Compatible Runner Version

v2.327.1
[Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

Make sure your runner is updated to this version or newer to use this
release.

**Full Changelog**:
<actions/attest-sbom@v2.4.0...v3.0.0>

###
[`v3`](https://redirect.github.com/actions/attest-sbom/compare/v2...v3)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.4.0...v3.0.0)

###
[`v2.4.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.4.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.2.0...v2.4.0)

#### What's Changed

- Bump actions/attest from 2.2.1 to 2.3.0 in the actions-minor group by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;169](https://redirect.github.com/actions/attest-sbom/pull/169)
- Bump undici from 5.28.5 to 5.29.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;172](https://redirect.github.com/actions/attest-sbom/pull/172)
- Bump actions/attest from 2.3.0 to 2.4.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;178](https://redirect.github.com/actions/attest-sbom/pull/178)
- Includes support for the new well-known summary file which will
accumulate paths to all attestations generated in a given workflow run

**Full Changelog**:
<actions/attest-sbom@v2.2.0...v2.4.0>

###
[`v2.2.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.1.0...v2.2.0)

#### What's Changed

- Bump actions/attest from v2.1.0 to v2.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;148](https://redirect.github.com/actions/attest-sbom/pull/148)
  - Includes support for new `subject-checksums` input parameter

**Full Changelog**:
<actions/attest-sbom@v2.1.0...v2.2.0>

###
[`v2.1.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.0.1...v2.1.0)

#### What's Changed

- Update README w/ note about GH plans supporting attestations by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;136](https://redirect.github.com/actions/attest-sbom/pull/136)
- Add `attestation-id` and `attestation-url` outputs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;137](https://redirect.github.com/actions/attest-sbom/pull/137)

**Full Changelog**:
<actions/attest-sbom@v2.0.1...v2.1.0>

###
[`v2.0.1`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.0.1)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2...v2.0.1)

#### What's Changed

- Bump actions/attest from 2.0.0 to 2.0.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;133](https://redirect.github.com/actions/attest-sbom/pull/133)
  - Deduplicate subjects before adding to in-toto statement

**Full Changelog**:
<actions/attest-sbom@v2.0.0...v2.0.1>

</details>

---

### Configuration

📅 **Schedule**: (in timezone America/New_York)

- Branch creation
  - "after 10pm every weekday,before 5am every weekday,every weekend"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/tgrecojr/soildata).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJtYWpvci11cGRhdGUiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: T.J. Greco <tgrecojr@gmail.com>
tgrecojr pushed a commit to tgrecojr/backvault that referenced this pull request May 23, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v2` → `v4` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

###
[`v4`](https://redirect.github.com/actions/attest-build-provenance/compare/v3...v4)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4)

###
[`v3.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.1.0...v3.2.0)

#### What's Changed

- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
from 1.11.1 to 2.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;776](https://redirect.github.com/actions/attest-build-provenance/pull/776)
- Add more documentation on Artifact Metadata Storage Records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;797](https://redirect.github.com/actions/attest-build-provenance/pull/797)
- Update actions/attest to latest version v3.2.0 by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;812](https://redirect.github.com/actions/attest-build-provenance/pull/812)

**Full Changelog**:
<actions/attest-build-provenance@v3.1.0...v3.2.0>

###
[`v3.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.0.0...v3.1.0)

#### What's Changed

- Prepare v3 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;697](https://redirect.github.com/actions/attest-build-provenance/pull/697)
- Bump js-yaml from 3.14.1 to 3.14.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;749](https://redirect.github.com/actions/attest-build-provenance/pull/749)
- Bump tar from 7.5.1 to 7.5.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;753](https://redirect.github.com/actions/attest-build-provenance/pull/753)
- Bump glob from 10.4.5 to 10.5.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;754](https://redirect.github.com/actions/attest-build-provenance/pull/754)
- Bump [@&#8203;types/node](https://redirect.github.com/types/node) from
24.10.1 to 25.0.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;774](https://redirect.github.com/actions/attest-build-provenance/pull/774)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 1.6.0 to 2.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;736](https://redirect.github.com/actions/attest-build-provenance/pull/736)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 2.0.0 to 2.1.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;775](https://redirect.github.com/actions/attest-build-provenance/pull/775)
- Add support for creating artifact metadata storage records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;779](https://redirect.github.com/actions/attest-build-provenance/pull/779)

#### New Contributors

- [@&#8203;malancas](https://redirect.github.com/malancas) made their
first contribution in
[#&#8203;779](https://redirect.github.com/actions/attest-build-provenance/pull/779)

**Full Changelog**:
<actions/attest-build-provenance@v3...v3.1.0>

###
[`v3.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.0.0...v3.0.0)

#### What's Changed

- Adjust node max-http-header-size setting by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;687](https://redirect.github.com/actions/attest-build-provenance/pull/687)
- Bump actions/attest from v2.4.0 to
[v3.0.0](https://redirect.github.com/actions/attest/releases/tag/v3.0.0)
by [@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;691](https://redirect.github.com/actions/attest-build-provenance/pull/691)
  - Bump to node24 runtime
  - Improved checksum parsing
- Bump attest-build-provenance/predicate to v2.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;693](https://redirect.github.com/actions/attest-build-provenance/pull/693)
- Bump to node24 runtime by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;692](https://redirect.github.com/actions/attest-build-provenance/pull/692)

#### ⚠️ Minimum Compatible Runner Version

v2.327.1
[Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

Make sure your runner is updated to this version or newer to use this
release.

**Full Changelog**:
<actions/attest-build-provenance@v2.4.0...v3.0.0>

###
[`v3`](https://redirect.github.com/actions/attest-build-provenance/compare/v2...v3)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.4.0...v3.0.0)

###
[`v2.4.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.4.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.3.0...v2.4.0)

##### What's Changed

- Bump undici from 5.28.5 to 5.29.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;633](https://redirect.github.com/actions/attest-build-provenance/pull/633)
- Bump actions/attest from 2.3.0 to
[2.4.0](https://redirect.github.com/actions/attest/releases/tag/v2.4.0)
by [@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;654](https://redirect.github.com/actions/attest-build-provenance/pull/654)
- Includes support for the new well-known summary file which will
accumulate paths to all attestations generated in a given workflow run

**Full Changelog**:
<actions/attest-build-provenance@v2.3.0...v2.4.0>

###
[`v2.3.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.3.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.3...v2.3.0)

##### What's Changed

- Bump `actions/attest` from 2.2.1 to 2.3.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;615](https://redirect.github.com/actions/attest-build-provenance/pull/615)
  - Updates `@sigstore/oci` from 0.4.0 to 0.5.0

**Full Changelog**:
<actions/attest-build-provenance@v2.2.3...v2.3.0>

###
[`v2.2.3`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.3)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.2...v2.2.3)

#### What's Changed

- Pin actions/attest reference by commit SHA by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;493](https://redirect.github.com/actions/attest-build-provenance/pull/493)

**Full Changelog**:
<actions/attest-build-provenance@v2.2.2...v2.2.3>

###
[`v2.2.2`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.2)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.1...v2.2.2)

#### What's Changed

- Bump predicate action from 1.1.4 to 1.1.5 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;485](https://redirect.github.com/actions/attest-build-provenance/pull/485)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 1.5.0 to 1.6.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;484](https://redirect.github.com/actions/attest-build-provenance/pull/484)
- Update buildSLSAProvenancePredicate to populate `workflow.ref` field
from the `ref` claim in the OIDC token
([actions/toolkit#1969](https://redirect.github.com/actions/toolkit/pull/1969))

**Full Changelog**:
<actions/attest-build-provenance@v2.2.1...v2.2.2>

###
[`v2.2.1`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.1)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.0...v2.2.1)

#### What's Changed

- Bump undici from 5.28.4 to 5.28.5 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;457](https://redirect.github.com/actions/attest-build-provenance/pull/457)
- Bump
[@&#8203;octokit/request-error](https://redirect.github.com/octokit/request-error)
from 5.0.1 to 5.1.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;469](https://redirect.github.com/actions/attest-build-provenance/pull/469)
- Bump
[@&#8203;octokit/request](https://redirect.github.com/octokit/request)
from 8.2.0 to 8.4.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;478](https://redirect.github.com/actions/attest-build-provenance/pull/478)
- Bump actions/attest from 2.2.0 to 2.2.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;481](https://redirect.github.com/actions/attest-build-provenance/pull/481)
- Includes `@actions/attest`
[v1.6.0](https://redirect.github.com/actions/toolkit/blob/main/packages/attest/RELEASES.md#160)

**Full Changelog**:
<actions/attest-build-provenance@v2.2.0...v2.2.1>

###
[`v2.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.1.0...v2.2.0)

#### What's Changed

- Bump actions/attest from v2.1.0 to v2.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;449](https://redirect.github.com/actions/attest-build-provenance/pull/449)
  - Includes support for now `subject-checksums` input parameter

**Full Changelog**:
<actions/attest-build-provenance@v2.1.0...v2.2.0>

###
[`v2.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.0.1...v2.1.0)

#### What's Changed

- Update README w/ note about GH plans supporting attestations by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;414](https://redirect.github.com/actions/attest-build-provenance/pull/414)
- Add `attestation-id` and `attestation-url` outputs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;415](https://redirect.github.com/actions/attest-build-provenance/pull/415)

**Full Changelog**:
<actions/attest-build-provenance@v2.0.1...v2.1.0>

###
[`v2.0.1`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.0.1)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2...v2.0.1)

#### What's Changed

- Bump actions/attest from 2.0.0 to 2.0.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;406](https://redirect.github.com/actions/attest-build-provenance/pull/406)
  - Deduplicate subjects before adding to in-toto statement

**Full Changelog**:
<actions/attest-build-provenance@v2.0.0...v2.0.1>

</details>

---

### Configuration

📅 **Schedule**: (in timezone America/New_York)

- Branch creation
  - "after 10pm every weekday,before 5am every weekday,every weekend"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/tgrecojr/backvault).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJtYWpvci11cGRhdGUiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
tgrecojr pushed a commit to tgrecojr/backvault that referenced this pull request May 23, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/attest-sbom](https://redirect.github.com/actions/attest-sbom)
| action | major | `v2` → `v4` |

---

### Release Notes

<details>
<summary>actions/attest-sbom (actions/attest-sbom)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v4...v4.1.0)

> \[!WARNING]
> As of version 4.0.0 this action is being deprecated in favor of
[`actions/attest`](https://redirect.github.com/action/attest).
`actions/attest-sbom` will continue to function as a wrapper on top of
`actions/attest` for some period of time, but applications should make
plans to migrate.
>
> All of the existing action inputs are compatible with the
`actions/attest` interface.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;254](https://redirect.github.com/actions/attest-sbom/pull/254)
- Bump actions/attest from 4.0.0 to 4.1.0 in the actions-minor group by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;255](https://redirect.github.com/actions/attest-sbom/pull/255)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-sbom@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v4...v4)

> \[!WARNING]
> As of version 4.0.0 this action is being deprecated in favor of
[`actions/attest`](https://redirect.github.com/action/attest).
`actions/attest-sbom` will continue to function as a wrapper on top of
`actions/attest` for some period of time, but applications should make
plans to migrate.
>
> All of the existing action inputs are compatible with the
`actions/attest` interface.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;253](https://redirect.github.com/actions/attest-sbom/pull/253)

**Full Changelog**:
<actions/attest-sbom@v3...v4.0.0>

###
[`v4`](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v4)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v4)

###
[`v3.0.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v3.0.0)

#### What's Changed

- Adjust node max-http-header-size setting by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;201](https://redirect.github.com/actions/attest-sbom/pull/201)
- Bump actions/attest from v2.4.0 to v3.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;202](https://redirect.github.com/actions/attest-sbom/pull/202)
  - Bump runtime to node24
  - Improved checksum parsing
- Bump attest-sbom/predicate to v2.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;206](https://redirect.github.com/actions/attest-sbom/pull/206)
- Bump predicate runtime to node24 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;204](https://redirect.github.com/actions/attest-sbom/pull/204)

#### ⚠️ Minimum Compatible Runner Version

v2.327.1
[Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

Make sure your runner is updated to this version or newer to use this
release.

**Full Changelog**:
<actions/attest-sbom@v2.4.0...v3.0.0>

###
[`v3`](https://redirect.github.com/actions/attest-sbom/compare/v2...v3)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.4.0...v3.0.0)

###
[`v2.4.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.4.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.2.0...v2.4.0)

#### What's Changed

- Bump actions/attest from 2.2.1 to 2.3.0 in the actions-minor group by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;169](https://redirect.github.com/actions/attest-sbom/pull/169)
- Bump undici from 5.28.5 to 5.29.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;172](https://redirect.github.com/actions/attest-sbom/pull/172)
- Bump actions/attest from 2.3.0 to 2.4.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;178](https://redirect.github.com/actions/attest-sbom/pull/178)
- Includes support for the new well-known summary file which will
accumulate paths to all attestations generated in a given workflow run

**Full Changelog**:
<actions/attest-sbom@v2.2.0...v2.4.0>

###
[`v2.2.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.1.0...v2.2.0)

#### What's Changed

- Bump actions/attest from v2.1.0 to v2.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;148](https://redirect.github.com/actions/attest-sbom/pull/148)
  - Includes support for new `subject-checksums` input parameter

**Full Changelog**:
<actions/attest-sbom@v2.1.0...v2.2.0>

###
[`v2.1.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.0.1...v2.1.0)

#### What's Changed

- Update README w/ note about GH plans supporting attestations by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;136](https://redirect.github.com/actions/attest-sbom/pull/136)
- Add `attestation-id` and `attestation-url` outputs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;137](https://redirect.github.com/actions/attest-sbom/pull/137)

**Full Changelog**:
<actions/attest-sbom@v2.0.1...v2.1.0>

###
[`v2.0.1`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.0.1)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2...v2.0.1)

#### What's Changed

- Bump actions/attest from 2.0.0 to 2.0.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;133](https://redirect.github.com/actions/attest-sbom/pull/133)
  - Deduplicate subjects before adding to in-toto statement

**Full Changelog**:
<actions/attest-sbom@v2.0.0...v2.0.1>

</details>

---

### Configuration

📅 **Schedule**: (in timezone America/New_York)

- Branch creation
  - "after 10pm every weekday,before 5am every weekday,every weekend"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/tgrecojr/backvault).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJtYWpvci11cGRhdGUiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
tgrecojr pushed a commit to tgrecojr/slacklistener that referenced this pull request May 23, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v2` → `v4` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

###
[`v4`](https://redirect.github.com/actions/attest-build-provenance/compare/v3...v4)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4)

###
[`v3.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.1.0...v3.2.0)

#### What's Changed

- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
from 1.11.1 to 2.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;776](https://redirect.github.com/actions/attest-build-provenance/pull/776)
- Add more documentation on Artifact Metadata Storage Records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;797](https://redirect.github.com/actions/attest-build-provenance/pull/797)
- Update actions/attest to latest version v3.2.0 by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;812](https://redirect.github.com/actions/attest-build-provenance/pull/812)

**Full Changelog**:
<actions/attest-build-provenance@v3.1.0...v3.2.0>

###
[`v3.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.0.0...v3.1.0)

#### What's Changed

- Prepare v3 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;697](https://redirect.github.com/actions/attest-build-provenance/pull/697)
- Bump js-yaml from 3.14.1 to 3.14.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;749](https://redirect.github.com/actions/attest-build-provenance/pull/749)
- Bump tar from 7.5.1 to 7.5.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;753](https://redirect.github.com/actions/attest-build-provenance/pull/753)
- Bump glob from 10.4.5 to 10.5.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;754](https://redirect.github.com/actions/attest-build-provenance/pull/754)
- Bump [@&#8203;types/node](https://redirect.github.com/types/node) from
24.10.1 to 25.0.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;774](https://redirect.github.com/actions/attest-build-provenance/pull/774)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 1.6.0 to 2.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;736](https://redirect.github.com/actions/attest-build-provenance/pull/736)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 2.0.0 to 2.1.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;775](https://redirect.github.com/actions/attest-build-provenance/pull/775)
- Add support for creating artifact metadata storage records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;779](https://redirect.github.com/actions/attest-build-provenance/pull/779)

#### New Contributors

- [@&#8203;malancas](https://redirect.github.com/malancas) made their
first contribution in
[#&#8203;779](https://redirect.github.com/actions/attest-build-provenance/pull/779)

**Full Changelog**:
<actions/attest-build-provenance@v3...v3.1.0>

###
[`v3.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.0.0...v3.0.0)

#### What's Changed

- Adjust node max-http-header-size setting by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;687](https://redirect.github.com/actions/attest-build-provenance/pull/687)
- Bump actions/attest from v2.4.0 to
[v3.0.0](https://redirect.github.com/actions/attest/releases/tag/v3.0.0)
by [@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;691](https://redirect.github.com/actions/attest-build-provenance/pull/691)
  - Bump to node24 runtime
  - Improved checksum parsing
- Bump attest-build-provenance/predicate to v2.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;693](https://redirect.github.com/actions/attest-build-provenance/pull/693)
- Bump to node24 runtime by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;692](https://redirect.github.com/actions/attest-build-provenance/pull/692)

#### ⚠️ Minimum Compatible Runner Version

v2.327.1
[Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

Make sure your runner is updated to this version or newer to use this
release.

**Full Changelog**:
<actions/attest-build-provenance@v2.4.0...v3.0.0>

###
[`v3`](https://redirect.github.com/actions/attest-build-provenance/compare/v2...v3)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.4.0...v3.0.0)

###
[`v2.4.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.4.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.3.0...v2.4.0)

##### What's Changed

- Bump undici from 5.28.5 to 5.29.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;633](https://redirect.github.com/actions/attest-build-provenance/pull/633)
- Bump actions/attest from 2.3.0 to
[2.4.0](https://redirect.github.com/actions/attest/releases/tag/v2.4.0)
by [@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;654](https://redirect.github.com/actions/attest-build-provenance/pull/654)
- Includes support for the new well-known summary file which will
accumulate paths to all attestations generated in a given workflow run

**Full Changelog**:
<actions/attest-build-provenance@v2.3.0...v2.4.0>

###
[`v2.3.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.3.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.3...v2.3.0)

##### What's Changed

- Bump `actions/attest` from 2.2.1 to 2.3.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;615](https://redirect.github.com/actions/attest-build-provenance/pull/615)
  - Updates `@sigstore/oci` from 0.4.0 to 0.5.0

**Full Changelog**:
<actions/attest-build-provenance@v2.2.3...v2.3.0>

###
[`v2.2.3`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.3)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.2...v2.2.3)

#### What's Changed

- Pin actions/attest reference by commit SHA by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;493](https://redirect.github.com/actions/attest-build-provenance/pull/493)

**Full Changelog**:
<actions/attest-build-provenance@v2.2.2...v2.2.3>

###
[`v2.2.2`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.2)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.1...v2.2.2)

#### What's Changed

- Bump predicate action from 1.1.4 to 1.1.5 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;485](https://redirect.github.com/actions/attest-build-provenance/pull/485)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 1.5.0 to 1.6.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;484](https://redirect.github.com/actions/attest-build-provenance/pull/484)
- Update buildSLSAProvenancePredicate to populate `workflow.ref` field
from the `ref` claim in the OIDC token
([actions/toolkit#1969](https://redirect.github.com/actions/toolkit/pull/1969))

**Full Changelog**:
<actions/attest-build-provenance@v2.2.1...v2.2.2>

###
[`v2.2.1`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.1)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.0...v2.2.1)

#### What's Changed

- Bump undici from 5.28.4 to 5.28.5 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;457](https://redirect.github.com/actions/attest-build-provenance/pull/457)
- Bump
[@&#8203;octokit/request-error](https://redirect.github.com/octokit/request-error)
from 5.0.1 to 5.1.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;469](https://redirect.github.com/actions/attest-build-provenance/pull/469)
- Bump
[@&#8203;octokit/request](https://redirect.github.com/octokit/request)
from 8.2.0 to 8.4.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;478](https://redirect.github.com/actions/attest-build-provenance/pull/478)
- Bump actions/attest from 2.2.0 to 2.2.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;481](https://redirect.github.com/actions/attest-build-provenance/pull/481)
- Includes `@actions/attest`
[v1.6.0](https://redirect.github.com/actions/toolkit/blob/main/packages/attest/RELEASES.md#160)

**Full Changelog**:
<actions/attest-build-provenance@v2.2.0...v2.2.1>

###
[`v2.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.1.0...v2.2.0)

#### What's Changed

- Bump actions/attest from v2.1.0 to v2.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;449](https://redirect.github.com/actions/attest-build-provenance/pull/449)
  - Includes support for now `subject-checksums` input parameter

**Full Changelog**:
<actions/attest-build-provenance@v2.1.0...v2.2.0>

###
[`v2.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.0.1...v2.1.0)

#### What's Changed

- Update README w/ note about GH plans supporting attestations by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;414](https://redirect.github.com/actions/attest-build-provenance/pull/414)
- Add `attestation-id` and `attestation-url` outputs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;415](https://redirect.github.com/actions/attest-build-provenance/pull/415)

**Full Changelog**:
<actions/attest-build-provenance@v2.0.1...v2.1.0>

###
[`v2.0.1`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.0.1)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2...v2.0.1)

#### What's Changed

- Bump actions/attest from 2.0.0 to 2.0.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;406](https://redirect.github.com/actions/attest-build-provenance/pull/406)
  - Deduplicate subjects before adding to in-toto statement

**Full Changelog**:
<actions/attest-build-provenance@v2.0.0...v2.0.1>

</details>

---

### Configuration

📅 **Schedule**: (in timezone America/New_York)

- Branch creation
  - "after 10pm every weekday,before 5am every weekday,every weekend"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/tgrecojr/slacklistener).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJtYWpvci11cGRhdGUiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
tgrecojr pushed a commit to tgrecojr/whoopster that referenced this pull request May 23, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v2` → `v4` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

###
[`v4`](https://redirect.github.com/actions/attest-build-provenance/compare/v3...v4)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4)

###
[`v3.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.1.0...v3.2.0)

#### What's Changed

- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
from 1.11.1 to 2.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;776](https://redirect.github.com/actions/attest-build-provenance/pull/776)
- Add more documentation on Artifact Metadata Storage Records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;797](https://redirect.github.com/actions/attest-build-provenance/pull/797)
- Update actions/attest to latest version v3.2.0 by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;812](https://redirect.github.com/actions/attest-build-provenance/pull/812)

**Full Changelog**:
<actions/attest-build-provenance@v3.1.0...v3.2.0>

###
[`v3.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.0.0...v3.1.0)

#### What's Changed

- Prepare v3 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;697](https://redirect.github.com/actions/attest-build-provenance/pull/697)
- Bump js-yaml from 3.14.1 to 3.14.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;749](https://redirect.github.com/actions/attest-build-provenance/pull/749)
- Bump tar from 7.5.1 to 7.5.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;753](https://redirect.github.com/actions/attest-build-provenance/pull/753)
- Bump glob from 10.4.5 to 10.5.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;754](https://redirect.github.com/actions/attest-build-provenance/pull/754)
- Bump [@&#8203;types/node](https://redirect.github.com/types/node) from
24.10.1 to 25.0.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;774](https://redirect.github.com/actions/attest-build-provenance/pull/774)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 1.6.0 to 2.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;736](https://redirect.github.com/actions/attest-build-provenance/pull/736)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 2.0.0 to 2.1.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;775](https://redirect.github.com/actions/attest-build-provenance/pull/775)
- Add support for creating artifact metadata storage records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;779](https://redirect.github.com/actions/attest-build-provenance/pull/779)

#### New Contributors

- [@&#8203;malancas](https://redirect.github.com/malancas) made their
first contribution in
[#&#8203;779](https://redirect.github.com/actions/attest-build-provenance/pull/779)

**Full Changelog**:
<actions/attest-build-provenance@v3...v3.1.0>

###
[`v3.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.0.0...v3.0.0)

#### What's Changed

- Adjust node max-http-header-size setting by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;687](https://redirect.github.com/actions/attest-build-provenance/pull/687)
- Bump actions/attest from v2.4.0 to
[v3.0.0](https://redirect.github.com/actions/attest/releases/tag/v3.0.0)
by [@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;691](https://redirect.github.com/actions/attest-build-provenance/pull/691)
  - Bump to node24 runtime
  - Improved checksum parsing
- Bump attest-build-provenance/predicate to v2.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;693](https://redirect.github.com/actions/attest-build-provenance/pull/693)
- Bump to node24 runtime by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;692](https://redirect.github.com/actions/attest-build-provenance/pull/692)

#### ⚠️ Minimum Compatible Runner Version

v2.327.1
[Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

Make sure your runner is updated to this version or newer to use this
release.

**Full Changelog**:
<actions/attest-build-provenance@v2.4.0...v3.0.0>

###
[`v3`](https://redirect.github.com/actions/attest-build-provenance/compare/v2...v3)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.4.0...v3.0.0)

###
[`v2.4.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.4.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.3.0...v2.4.0)

##### What's Changed

- Bump undici from 5.28.5 to 5.29.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;633](https://redirect.github.com/actions/attest-build-provenance/pull/633)
- Bump actions/attest from 2.3.0 to
[2.4.0](https://redirect.github.com/actions/attest/releases/tag/v2.4.0)
by [@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;654](https://redirect.github.com/actions/attest-build-provenance/pull/654)
- Includes support for the new well-known summary file which will
accumulate paths to all attestations generated in a given workflow run

**Full Changelog**:
<actions/attest-build-provenance@v2.3.0...v2.4.0>

###
[`v2.3.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.3.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.3...v2.3.0)

##### What's Changed

- Bump `actions/attest` from 2.2.1 to 2.3.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;615](https://redirect.github.com/actions/attest-build-provenance/pull/615)
  - Updates `@sigstore/oci` from 0.4.0 to 0.5.0

**Full Changelog**:
<actions/attest-build-provenance@v2.2.3...v2.3.0>

###
[`v2.2.3`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.3)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.2...v2.2.3)

#### What's Changed

- Pin actions/attest reference by commit SHA by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;493](https://redirect.github.com/actions/attest-build-provenance/pull/493)

**Full Changelog**:
<actions/attest-build-provenance@v2.2.2...v2.2.3>

###
[`v2.2.2`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.2)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.1...v2.2.2)

#### What's Changed

- Bump predicate action from 1.1.4 to 1.1.5 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;485](https://redirect.github.com/actions/attest-build-provenance/pull/485)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 1.5.0 to 1.6.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;484](https://redirect.github.com/actions/attest-build-provenance/pull/484)
- Update buildSLSAProvenancePredicate to populate `workflow.ref` field
from the `ref` claim in the OIDC token
([actions/toolkit#1969](https://redirect.github.com/actions/toolkit/pull/1969))

**Full Changelog**:
<actions/attest-build-provenance@v2.2.1...v2.2.2>

###
[`v2.2.1`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.1)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.0...v2.2.1)

#### What's Changed

- Bump undici from 5.28.4 to 5.28.5 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;457](https://redirect.github.com/actions/attest-build-provenance/pull/457)
- Bump
[@&#8203;octokit/request-error](https://redirect.github.com/octokit/request-error)
from 5.0.1 to 5.1.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;469](https://redirect.github.com/actions/attest-build-provenance/pull/469)
- Bump
[@&#8203;octokit/request](https://redirect.github.com/octokit/request)
from 8.2.0 to 8.4.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;478](https://redirect.github.com/actions/attest-build-provenance/pull/478)
- Bump actions/attest from 2.2.0 to 2.2.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;481](https://redirect.github.com/actions/attest-build-provenance/pull/481)
- Includes `@actions/attest`
[v1.6.0](https://redirect.github.com/actions/toolkit/blob/main/packages/attest/RELEASES.md#160)

**Full Changelog**:
<actions/attest-build-provenance@v2.2.0...v2.2.1>

###
[`v2.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.1.0...v2.2.0)

#### What's Changed

- Bump actions/attest from v2.1.0 to v2.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;449](https://redirect.github.com/actions/attest-build-provenance/pull/449)
  - Includes support for now `subject-checksums` input parameter

**Full Changelog**:
<actions/attest-build-provenance@v2.1.0...v2.2.0>

###
[`v2.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.0.1...v2.1.0)

#### What's Changed

- Update README w/ note about GH plans supporting attestations by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;414](https://redirect.github.com/actions/attest-build-provenance/pull/414)
- Add `attestation-id` and `attestation-url` outputs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;415](https://redirect.github.com/actions/attest-build-provenance/pull/415)

**Full Changelog**:
<actions/attest-build-provenance@v2.0.1...v2.1.0>

###
[`v2.0.1`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.0.1)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2...v2.0.1)

#### What's Changed

- Bump actions/attest from 2.0.0 to 2.0.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;406](https://redirect.github.com/actions/attest-build-provenance/pull/406)
  - Deduplicate subjects before adding to in-toto statement

**Full Changelog**:
<actions/attest-build-provenance@v2.0.0...v2.0.1>

</details>

---

### Configuration

📅 **Schedule**: (in timezone America/New_York)

- Branch creation
  - "after 10pm every weekday,before 5am every weekday,every weekend"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/tgrecojr/whoopster).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJtYWpvci11cGRhdGUiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
tgrecojr pushed a commit to tgrecojr/slacklistener that referenced this pull request May 23, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/attest-sbom](https://redirect.github.com/actions/attest-sbom)
| action | major | `v2` → `v4` |

---

### Release Notes

<details>
<summary>actions/attest-sbom (actions/attest-sbom)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v4...v4.1.0)

> \[!WARNING]
> As of version 4.0.0 this action is being deprecated in favor of
[`actions/attest`](https://redirect.github.com/action/attest).
`actions/attest-sbom` will continue to function as a wrapper on top of
`actions/attest` for some period of time, but applications should make
plans to migrate.
>
> All of the existing action inputs are compatible with the
`actions/attest` interface.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;254](https://redirect.github.com/actions/attest-sbom/pull/254)
- Bump actions/attest from 4.0.0 to 4.1.0 in the actions-minor group by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;255](https://redirect.github.com/actions/attest-sbom/pull/255)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-sbom@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v4...v4)

> \[!WARNING]
> As of version 4.0.0 this action is being deprecated in favor of
[`actions/attest`](https://redirect.github.com/action/attest).
`actions/attest-sbom` will continue to function as a wrapper on top of
`actions/attest` for some period of time, but applications should make
plans to migrate.
>
> All of the existing action inputs are compatible with the
`actions/attest` interface.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;253](https://redirect.github.com/actions/attest-sbom/pull/253)

**Full Changelog**:
<actions/attest-sbom@v3...v4.0.0>

###
[`v4`](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v4)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v4)

###
[`v3.0.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v3.0.0)

#### What's Changed

- Adjust node max-http-header-size setting by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;201](https://redirect.github.com/actions/attest-sbom/pull/201)
- Bump actions/attest from v2.4.0 to v3.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;202](https://redirect.github.com/actions/attest-sbom/pull/202)
  - Bump runtime to node24
  - Improved checksum parsing
- Bump attest-sbom/predicate to v2.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;206](https://redirect.github.com/actions/attest-sbom/pull/206)
- Bump predicate runtime to node24 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;204](https://redirect.github.com/actions/attest-sbom/pull/204)

#### ⚠️ Minimum Compatible Runner Version

v2.327.1
[Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

Make sure your runner is updated to this version or newer to use this
release.

**Full Changelog**:
<actions/attest-sbom@v2.4.0...v3.0.0>

###
[`v3`](https://redirect.github.com/actions/attest-sbom/compare/v2...v3)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.4.0...v3.0.0)

###
[`v2.4.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.4.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.2.0...v2.4.0)

#### What's Changed

- Bump actions/attest from 2.2.1 to 2.3.0 in the actions-minor group by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;169](https://redirect.github.com/actions/attest-sbom/pull/169)
- Bump undici from 5.28.5 to 5.29.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;172](https://redirect.github.com/actions/attest-sbom/pull/172)
- Bump actions/attest from 2.3.0 to 2.4.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;178](https://redirect.github.com/actions/attest-sbom/pull/178)
- Includes support for the new well-known summary file which will
accumulate paths to all attestations generated in a given workflow run

**Full Changelog**:
<actions/attest-sbom@v2.2.0...v2.4.0>

###
[`v2.2.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.1.0...v2.2.0)

#### What's Changed

- Bump actions/attest from v2.1.0 to v2.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;148](https://redirect.github.com/actions/attest-sbom/pull/148)
  - Includes support for new `subject-checksums` input parameter

**Full Changelog**:
<actions/attest-sbom@v2.1.0...v2.2.0>

###
[`v2.1.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.0.1...v2.1.0)

#### What's Changed

- Update README w/ note about GH plans supporting attestations by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;136](https://redirect.github.com/actions/attest-sbom/pull/136)
- Add `attestation-id` and `attestation-url` outputs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;137](https://redirect.github.com/actions/attest-sbom/pull/137)

**Full Changelog**:
<actions/attest-sbom@v2.0.1...v2.1.0>

###
[`v2.0.1`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.0.1)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2...v2.0.1)

#### What's Changed

- Bump actions/attest from 2.0.0 to 2.0.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;133](https://redirect.github.com/actions/attest-sbom/pull/133)
  - Deduplicate subjects before adding to in-toto statement

**Full Changelog**:
<actions/attest-sbom@v2.0.0...v2.0.1>

</details>

---

### Configuration

📅 **Schedule**: (in timezone America/New_York)

- Branch creation
  - "after 10pm every weekday,before 5am every weekday,every weekend"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/tgrecojr/slacklistener).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJtYWpvci11cGRhdGUiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
tgrecojr pushed a commit to tgrecojr/whoopster that referenced this pull request May 23, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/attest-sbom](https://redirect.github.com/actions/attest-sbom)
| action | major | `v2` → `v4` |

---

### Release Notes

<details>
<summary>actions/attest-sbom (actions/attest-sbom)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v4...v4.1.0)

> \[!WARNING]
> As of version 4.0.0 this action is being deprecated in favor of
[`actions/attest`](https://redirect.github.com/action/attest).
`actions/attest-sbom` will continue to function as a wrapper on top of
`actions/attest` for some period of time, but applications should make
plans to migrate.
>
> All of the existing action inputs are compatible with the
`actions/attest` interface.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;254](https://redirect.github.com/actions/attest-sbom/pull/254)
- Bump actions/attest from 4.0.0 to 4.1.0 in the actions-minor group by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;255](https://redirect.github.com/actions/attest-sbom/pull/255)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-sbom@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v4...v4)

> \[!WARNING]
> As of version 4.0.0 this action is being deprecated in favor of
[`actions/attest`](https://redirect.github.com/action/attest).
`actions/attest-sbom` will continue to function as a wrapper on top of
`actions/attest` for some period of time, but applications should make
plans to migrate.
>
> All of the existing action inputs are compatible with the
`actions/attest` interface.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;253](https://redirect.github.com/actions/attest-sbom/pull/253)

**Full Changelog**:
<actions/attest-sbom@v3...v4.0.0>

###
[`v4`](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v4)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v4)

###
[`v3.0.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v3.0.0)

#### What's Changed

- Adjust node max-http-header-size setting by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;201](https://redirect.github.com/actions/attest-sbom/pull/201)
- Bump actions/attest from v2.4.0 to v3.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;202](https://redirect.github.com/actions/attest-sbom/pull/202)
  - Bump runtime to node24
  - Improved checksum parsing
- Bump attest-sbom/predicate to v2.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;206](https://redirect.github.com/actions/attest-sbom/pull/206)
- Bump predicate runtime to node24 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;204](https://redirect.github.com/actions/attest-sbom/pull/204)

#### ⚠️ Minimum Compatible Runner Version

v2.327.1
[Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

Make sure your runner is updated to this version or newer to use this
release.

**Full Changelog**:
<actions/attest-sbom@v2.4.0...v3.0.0>

###
[`v3`](https://redirect.github.com/actions/attest-sbom/compare/v2...v3)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.4.0...v3.0.0)

###
[`v2.4.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.4.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.2.0...v2.4.0)

#### What's Changed

- Bump actions/attest from 2.2.1 to 2.3.0 in the actions-minor group by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;169](https://redirect.github.com/actions/attest-sbom/pull/169)
- Bump undici from 5.28.5 to 5.29.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;172](https://redirect.github.com/actions/attest-sbom/pull/172)
- Bump actions/attest from 2.3.0 to 2.4.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;178](https://redirect.github.com/actions/attest-sbom/pull/178)
- Includes support for the new well-known summary file which will
accumulate paths to all attestations generated in a given workflow run

**Full Changelog**:
<actions/attest-sbom@v2.2.0...v2.4.0>

###
[`v2.2.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.1.0...v2.2.0)

#### What's Changed

- Bump actions/attest from v2.1.0 to v2.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;148](https://redirect.github.com/actions/attest-sbom/pull/148)
  - Includes support for new `subject-checksums` input parameter

**Full Changelog**:
<actions/attest-sbom@v2.1.0...v2.2.0>

###
[`v2.1.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.0.1...v2.1.0)

#### What's Changed

- Update README w/ note about GH plans supporting attestations by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;136](https://redirect.github.com/actions/attest-sbom/pull/136)
- Add `attestation-id` and `attestation-url` outputs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;137](https://redirect.github.com/actions/attest-sbom/pull/137)

**Full Changelog**:
<actions/attest-sbom@v2.0.1...v2.1.0>

###
[`v2.0.1`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.0.1)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2...v2.0.1)

#### What's Changed

- Bump actions/attest from 2.0.0 to 2.0.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;133](https://redirect.github.com/actions/attest-sbom/pull/133)
  - Deduplicate subjects before adding to in-toto statement

**Full Changelog**:
<actions/attest-sbom@v2.0.0...v2.0.1>

</details>

---

### Configuration

📅 **Schedule**: (in timezone America/New_York)

- Branch creation
  - "after 10pm every weekday,before 5am every weekday,every weekend"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/tgrecojr/whoopster).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJtYWpvci11cGRhdGUiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
tgrecojr pushed a commit to tgrecojr/turfops that referenced this pull request May 23, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v2` → `v4` |

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

###
[`v4`](https://redirect.github.com/actions/attest-build-provenance/compare/v3...v4)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4)

###
[`v3.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.1.0...v3.2.0)

#### What's Changed

- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
from 1.11.1 to 2.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;776](https://redirect.github.com/actions/attest-build-provenance/pull/776)
- Add more documentation on Artifact Metadata Storage Records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;797](https://redirect.github.com/actions/attest-build-provenance/pull/797)
- Update actions/attest to latest version v3.2.0 by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;812](https://redirect.github.com/actions/attest-build-provenance/pull/812)

**Full Changelog**:
<actions/attest-build-provenance@v3.1.0...v3.2.0>

###
[`v3.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.0.0...v3.1.0)

#### What's Changed

- Prepare v3 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;697](https://redirect.github.com/actions/attest-build-provenance/pull/697)
- Bump js-yaml from 3.14.1 to 3.14.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;749](https://redirect.github.com/actions/attest-build-provenance/pull/749)
- Bump tar from 7.5.1 to 7.5.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;753](https://redirect.github.com/actions/attest-build-provenance/pull/753)
- Bump glob from 10.4.5 to 10.5.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;754](https://redirect.github.com/actions/attest-build-provenance/pull/754)
- Bump [@&#8203;types/node](https://redirect.github.com/types/node) from
24.10.1 to 25.0.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;774](https://redirect.github.com/actions/attest-build-provenance/pull/774)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 1.6.0 to 2.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;736](https://redirect.github.com/actions/attest-build-provenance/pull/736)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 2.0.0 to 2.1.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;775](https://redirect.github.com/actions/attest-build-provenance/pull/775)
- Add support for creating artifact metadata storage records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;779](https://redirect.github.com/actions/attest-build-provenance/pull/779)

#### New Contributors

- [@&#8203;malancas](https://redirect.github.com/malancas) made their
first contribution in
[#&#8203;779](https://redirect.github.com/actions/attest-build-provenance/pull/779)

**Full Changelog**:
<actions/attest-build-provenance@v3...v3.1.0>

###
[`v3.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.0.0...v3.0.0)

#### What's Changed

- Adjust node max-http-header-size setting by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;687](https://redirect.github.com/actions/attest-build-provenance/pull/687)
- Bump actions/attest from v2.4.0 to
[v3.0.0](https://redirect.github.com/actions/attest/releases/tag/v3.0.0)
by [@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;691](https://redirect.github.com/actions/attest-build-provenance/pull/691)
  - Bump to node24 runtime
  - Improved checksum parsing
- Bump attest-build-provenance/predicate to v2.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;693](https://redirect.github.com/actions/attest-build-provenance/pull/693)
- Bump to node24 runtime by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;692](https://redirect.github.com/actions/attest-build-provenance/pull/692)

#### ⚠️ Minimum Compatible Runner Version

v2.327.1
[Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

Make sure your runner is updated to this version or newer to use this
release.

**Full Changelog**:
<actions/attest-build-provenance@v2.4.0...v3.0.0>

###
[`v3`](https://redirect.github.com/actions/attest-build-provenance/compare/v2...v3)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.4.0...v3.0.0)

###
[`v2.4.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.4.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.3.0...v2.4.0)

##### What's Changed

- Bump undici from 5.28.5 to 5.29.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;633](https://redirect.github.com/actions/attest-build-provenance/pull/633)
- Bump actions/attest from 2.3.0 to
[2.4.0](https://redirect.github.com/actions/attest/releases/tag/v2.4.0)
by [@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;654](https://redirect.github.com/actions/attest-build-provenance/pull/654)
- Includes support for the new well-known summary file which will
accumulate paths to all attestations generated in a given workflow run

**Full Changelog**:
<actions/attest-build-provenance@v2.3.0...v2.4.0>

###
[`v2.3.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.3.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.3...v2.3.0)

##### What's Changed

- Bump `actions/attest` from 2.2.1 to 2.3.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;615](https://redirect.github.com/actions/attest-build-provenance/pull/615)
  - Updates `@sigstore/oci` from 0.4.0 to 0.5.0

**Full Changelog**:
<actions/attest-build-provenance@v2.2.3...v2.3.0>

###
[`v2.2.3`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.3)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.2...v2.2.3)

#### What's Changed

- Pin actions/attest reference by commit SHA by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;493](https://redirect.github.com/actions/attest-build-provenance/pull/493)

**Full Changelog**:
<actions/attest-build-provenance@v2.2.2...v2.2.3>

###
[`v2.2.2`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.2)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.1...v2.2.2)

#### What's Changed

- Bump predicate action from 1.1.4 to 1.1.5 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;485](https://redirect.github.com/actions/attest-build-provenance/pull/485)
- Bump
[@&#8203;actions/attest](https://redirect.github.com/actions/attest)
from 1.5.0 to 1.6.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;484](https://redirect.github.com/actions/attest-build-provenance/pull/484)
- Update buildSLSAProvenancePredicate to populate `workflow.ref` field
from the `ref` claim in the OIDC token
([actions/toolkit#1969](https://redirect.github.com/actions/toolkit/pull/1969))

**Full Changelog**:
<actions/attest-build-provenance@v2.2.1...v2.2.2>

###
[`v2.2.1`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.1)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.2.0...v2.2.1)

#### What's Changed

- Bump undici from 5.28.4 to 5.28.5 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;457](https://redirect.github.com/actions/attest-build-provenance/pull/457)
- Bump
[@&#8203;octokit/request-error](https://redirect.github.com/octokit/request-error)
from 5.0.1 to 5.1.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;469](https://redirect.github.com/actions/attest-build-provenance/pull/469)
- Bump
[@&#8203;octokit/request](https://redirect.github.com/octokit/request)
from 8.2.0 to 8.4.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;478](https://redirect.github.com/actions/attest-build-provenance/pull/478)
- Bump actions/attest from 2.2.0 to 2.2.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;481](https://redirect.github.com/actions/attest-build-provenance/pull/481)
- Includes `@actions/attest`
[v1.6.0](https://redirect.github.com/actions/toolkit/blob/main/packages/attest/RELEASES.md#160)

**Full Changelog**:
<actions/attest-build-provenance@v2.2.0...v2.2.1>

###
[`v2.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.1.0...v2.2.0)

#### What's Changed

- Bump actions/attest from v2.1.0 to v2.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;449](https://redirect.github.com/actions/attest-build-provenance/pull/449)
  - Includes support for now `subject-checksums` input parameter

**Full Changelog**:
<actions/attest-build-provenance@v2.1.0...v2.2.0>

###
[`v2.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2.0.1...v2.1.0)

#### What's Changed

- Update README w/ note about GH plans supporting attestations by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;414](https://redirect.github.com/actions/attest-build-provenance/pull/414)
- Add `attestation-id` and `attestation-url` outputs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;415](https://redirect.github.com/actions/attest-build-provenance/pull/415)

**Full Changelog**:
<actions/attest-build-provenance@v2.0.1...v2.1.0>

###
[`v2.0.1`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v2.0.1)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v2...v2.0.1)

#### What's Changed

- Bump actions/attest from 2.0.0 to 2.0.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;406](https://redirect.github.com/actions/attest-build-provenance/pull/406)
  - Deduplicate subjects before adding to in-toto statement

**Full Changelog**:
<actions/attest-build-provenance@v2.0.0...v2.0.1>

</details>

---

### Configuration

📅 **Schedule**: (in timezone America/New_York)

- Branch creation
  - "after 10pm every weekday,before 5am every weekday,every weekend"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/tgrecojr/turfops).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJtYWpvci11cGRhdGUiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
tgrecojr pushed a commit to tgrecojr/turfops that referenced this pull request May 23, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/attest-sbom](https://redirect.github.com/actions/attest-sbom)
| action | major | `v2` → `v4` |

---

### Release Notes

<details>
<summary>actions/attest-sbom (actions/attest-sbom)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v4...v4.1.0)

> \[!WARNING]
> As of version 4.0.0 this action is being deprecated in favor of
[`actions/attest`](https://redirect.github.com/action/attest).
`actions/attest-sbom` will continue to function as a wrapper on top of
`actions/attest` for some period of time, but applications should make
plans to migrate.
>
> All of the existing action inputs are compatible with the
`actions/attest` interface.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;254](https://redirect.github.com/actions/attest-sbom/pull/254)
- Bump actions/attest from 4.0.0 to 4.1.0 in the actions-minor group by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;255](https://redirect.github.com/actions/attest-sbom/pull/255)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-sbom@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v4...v4)

> \[!WARNING]
> As of version 4.0.0 this action is being deprecated in favor of
[`actions/attest`](https://redirect.github.com/action/attest).
`actions/attest-sbom` will continue to function as a wrapper on top of
`actions/attest` for some period of time, but applications should make
plans to migrate.
>
> All of the existing action inputs are compatible with the
`actions/attest` interface.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;253](https://redirect.github.com/actions/attest-sbom/pull/253)

**Full Changelog**:
<actions/attest-sbom@v3...v4.0.0>

###
[`v4`](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v4)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v4)

###
[`v3.0.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v3.0.0...v3.0.0)

#### What's Changed

- Adjust node max-http-header-size setting by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;201](https://redirect.github.com/actions/attest-sbom/pull/201)
- Bump actions/attest from v2.4.0 to v3.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;202](https://redirect.github.com/actions/attest-sbom/pull/202)
  - Bump runtime to node24
  - Improved checksum parsing
- Bump attest-sbom/predicate to v2.0.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;206](https://redirect.github.com/actions/attest-sbom/pull/206)
- Bump predicate runtime to node24 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;204](https://redirect.github.com/actions/attest-sbom/pull/204)

#### ⚠️ Minimum Compatible Runner Version

v2.327.1
[Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

Make sure your runner is updated to this version or newer to use this
release.

**Full Changelog**:
<actions/attest-sbom@v2.4.0...v3.0.0>

###
[`v3`](https://redirect.github.com/actions/attest-sbom/compare/v2...v3)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.4.0...v3.0.0)

###
[`v2.4.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.4.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.2.0...v2.4.0)

#### What's Changed

- Bump actions/attest from 2.2.1 to 2.3.0 in the actions-minor group by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;169](https://redirect.github.com/actions/attest-sbom/pull/169)
- Bump undici from 5.28.5 to 5.29.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;172](https://redirect.github.com/actions/attest-sbom/pull/172)
- Bump actions/attest from 2.3.0 to 2.4.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;178](https://redirect.github.com/actions/attest-sbom/pull/178)
- Includes support for the new well-known summary file which will
accumulate paths to all attestations generated in a given workflow run

**Full Changelog**:
<actions/attest-sbom@v2.2.0...v2.4.0>

###
[`v2.2.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.1.0...v2.2.0)

#### What's Changed

- Bump actions/attest from v2.1.0 to v2.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;148](https://redirect.github.com/actions/attest-sbom/pull/148)
  - Includes support for new `subject-checksums` input parameter

**Full Changelog**:
<actions/attest-sbom@v2.1.0...v2.2.0>

###
[`v2.1.0`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2.0.1...v2.1.0)

#### What's Changed

- Update README w/ note about GH plans supporting attestations by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;136](https://redirect.github.com/actions/attest-sbom/pull/136)
- Add `attestation-id` and `attestation-url` outputs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;137](https://redirect.github.com/actions/attest-sbom/pull/137)

**Full Changelog**:
<actions/attest-sbom@v2.0.1...v2.1.0>

###
[`v2.0.1`](https://redirect.github.com/actions/attest-sbom/releases/tag/v2.0.1)

[Compare
Source](https://redirect.github.com/actions/attest-sbom/compare/v2...v2.0.1)

#### What's Changed

- Bump actions/attest from 2.0.0 to 2.0.1 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;133](https://redirect.github.com/actions/attest-sbom/pull/133)
  - Deduplicate subjects before adding to in-toto statement

**Full Changelog**:
<actions/attest-sbom@v2.0.0...v2.0.1>

</details>

---

### Configuration

📅 **Schedule**: (in timezone America/New_York)

- Branch creation
  - "after 10pm every weekday,before 5am every weekday,every weekend"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/tgrecojr/turfops).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJtYWpvci11cGRhdGUiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
markrvmurray pushed a commit to markrvmurray/llvm-mc6809 that referenced this pull request Jun 14, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3.1.0` → `v4.1.0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/160328) for more information.

---

### Release Notes

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4.0.0...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4.0.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

###
[`v3.2.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v3.2.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.1.0...v3.2.0)

#### What's Changed

- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
from 1.11.1 to 2.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;776](https://redirect.github.com/actions/attest-build-provenance/pull/776)
- Add more documentation on Artifact Metadata Storage Records by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;797](https://redirect.github.com/actions/attest-build-provenance/pull/797)
- Update actions/attest to latest version v3.2.0 by
[@&#8203;malancas](https://redirect.github.com/malancas) in
[#&#8203;812](https://redirect.github.com/actions/attest-build-provenance/pull/812)

**Full Changelog**:
<actions/attest-build-provenance@v3.1.0...v3.2.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 12:00 AM and 12:59 AM, only on
Monday ( * 0 * * 1 ) (UTC), Automerge - At any time (no schedule
defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/llvm/llvm-project).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNDMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
dylanratcliffe pushed a commit to overmindtech/cli that referenced this pull request Jun 22, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[1password/install-cli-action](https://redirect.github.com/1password/install-cli-action)
| action | major | `v3.0.0` → `v4.0.0` |
|
[1password/install-cli-action](https://redirect.github.com/1password/install-cli-action)
| action | major | `v2.0.2` → `v4.0.0` |
|
[1password/install-cli-action](https://redirect.github.com/1password/install-cli-action)
| action | major | `v3` → `v4` |
|
[1password/load-secrets-action](https://redirect.github.com/1password/load-secrets-action)
| action | major | `v3.2.1` → `v4.0.1` |
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3` → `v4` |
|
[dawidd6/action-download-artifact](https://redirect.github.com/dawidd6/action-download-artifact)
| action | major | `v20` → `v21` |
|
[hoverkraft-tech/compose-action](https://redirect.github.com/hoverkraft-tech/compose-action)
| action | major | `v2.6.0` → `v3.0.0` |
|
[marocchino/sticky-pull-request-comment](https://redirect.github.com/marocchino/sticky-pull-request-comment)
| action | major | `v2` → `v3.0.4` |
| [pnpm/action-setup](https://redirect.github.com/pnpm/action-setup) |
action | major | `v5.0.0` → `v6.0.8` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/370) for more information.

---

### Release Notes

<details>
<summary>1password/install-cli-action
(1password/install-cli-action)</summary>

###
[`v4.0.0`](https://redirect.github.com/1Password/install-cli-action/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/1password/install-cli-action/compare/v4.0.0...v4.0.0)

#### What's Changed

##### Compatibility

⚠️ Linux self-hosted runners must have `gpg` available on PATH in order
to verify CLI signature.
([#&#8203;37](https://redirect.github.com/1Password/install-cli-action/pull/37))

##### Security

- Verify 1Password CLI signatures on install for Linux, macOS, and
Windows before adding the binary to PATH.
([#&#8203;37](https://redirect.github.com/1Password/install-cli-action/pull/37))

##### Documentation

- README now includes a notice that 1Password API usage is governed by
the [1Password API Terms of
Service](https://1password.com/legal/api-sdk-terms-of-service).
([#&#8203;39](https://redirect.github.com/1Password/install-cli-action/pull/39))

##### New Contributors

- [@&#8203;libutcher](https://redirect.github.com/libutcher) made their
first contribution in
[1Password#39](https://redirect.github.com/1Password/install-cli-action/pull/39)

**Full Changelog**:
<1Password/install-cli-action@v3...v4.0.0>

###
[`v4`](https://redirect.github.com/1password/install-cli-action/compare/v3.0.0...v4.0.0)

[Compare
Source](https://redirect.github.com/1password/install-cli-action/compare/v3.0.0...v4.0.0)

</details>

<details>
<summary>1password/load-secrets-action
(1password/load-secrets-action)</summary>

###
[`v4.0.1`](https://redirect.github.com/1Password/load-secrets-action/releases/tag/v4.0.1)

[Compare
Source](https://redirect.github.com/1password/load-secrets-action/compare/v4.0.0...v4.0.1)

#### What's Changed

##### Fix

- Fixed a Windows specific issue where 1Password CLI installation could
fail because the downloaded archive lacked a .zip extension required by
PowerShell’s archive extraction fallback.
([#&#8203;154](https://redirect.github.com/1Password/load-secrets-action/pull/154))
- Bump actions/checkout from v5 to v6 in CI workflows.
([#&#8203;156](https://redirect.github.com/1Password/load-secrets-action/pull/156))

##### Security

- Harden GitHub Actions workflows by pinning external actions to
immutable commit SHAs.
([#&#8203;157](https://redirect.github.com/1Password/load-secrets-action/pull/157))

##### Docs

- Add 1Password API Terms of Service notice to the README
([#&#8203;166](https://redirect.github.com/1Password/load-secrets-action/pull/166))

##### New Contributors

- [@&#8203;dagecko](https://redirect.github.com/dagecko) made their
first contribution in
[1Password#157](https://redirect.github.com/1Password/load-secrets-action/pull/157)
- [@&#8203;superteppo](https://redirect.github.com/superteppo) made
their first contribution in
[1Password#154](https://redirect.github.com/1Password/load-secrets-action/pull/154)
- [@&#8203;libutcher](https://redirect.github.com/libutcher) made their
first contribution in
[1Password#166](https://redirect.github.com/1Password/load-secrets-action/pull/166)

**Full Changelog**:
<1Password/load-secrets-action@v4.0.0...v4.0.1>

###
[`v4.0.0`](https://redirect.github.com/1Password/load-secrets-action/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/1password/load-secrets-action/compare/v4.0.0...v4.0.0)

#### What's Changed

- Clear **npm audit** / **Dependabot** findings via **`npm audit fix`**
where safe (e.g. **ajv**, **flatted**, **undici**, and other resolvable
**minimatch** updates).
[#&#8203;151](https://redirect.github.com/1password/load-secrets-action/issues/151)
- Action runtime updated from Node 20 to **Node 24** for GitHub Actions
compatibility ([deprecation
notice](https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/)).
[#&#8203;148](https://redirect.github.com/1password/load-secrets-action/issues/148).

#### New Contributors

- [@&#8203;jjavieralv](https://redirect.github.com/jjavieralv) made
their first contribution in
[1Password#149](https://redirect.github.com/1Password/load-secrets-action/pull/149)

**Full Changelog**:
<1Password/load-secrets-action@v3...v4.0.0>

###
[`v4`](https://redirect.github.com/1password/load-secrets-action/compare/v3.2.1...v4.0.0)

[Compare
Source](https://redirect.github.com/1password/load-secrets-action/compare/v3.2.1...v4.0.0)

</details>

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

###
[`v4`](https://redirect.github.com/actions/attest-build-provenance/compare/v3...v4)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4)

</details>

<details>
<summary>dawidd6/action-download-artifact
(dawidd6/action-download-artifact)</summary>

###
[`v21`](https://redirect.github.com/dawidd6/action-download-artifact/releases/tag/v21)

[Compare
Source](https://redirect.github.com/dawidd6/action-download-artifact/compare/v20...v21)

#### What's Changed

- build(deps): bump
[@&#8203;actions/github](https://redirect.github.com/actions/github)
from 9.0.0 to 9.1.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;396](https://redirect.github.com/dawidd6/action-download-artifact/pull/396)
- build(deps): bump filesize from 11.0.15 to 11.0.16 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;399](https://redirect.github.com/dawidd6/action-download-artifact/pull/399)
- build(deps): bump fast-xml-parser from 5.5.7 to 5.7.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;402](https://redirect.github.com/dawidd6/action-download-artifact/pull/402)
- build(deps): bump
[@&#8203;actions/github](https://redirect.github.com/actions/github)
from 9.1.0 to 9.1.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;400](https://redirect.github.com/dawidd6/action-download-artifact/pull/400)
- build(deps): bump
[@&#8203;actions/core](https://redirect.github.com/actions/core) from
3.0.0 to 3.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;401](https://redirect.github.com/dawidd6/action-download-artifact/pull/401)
- build(deps): bump filesize from 11.0.16 to 11.0.17 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;404](https://redirect.github.com/dawidd6/action-download-artifact/pull/404)
- Download artifacts in creation order by
[@&#8203;matejdro](https://redirect.github.com/matejdro) in
[#&#8203;398](https://redirect.github.com/dawidd6/action-download-artifact/pull/398)
- node\_modules: update by
[@&#8203;dawidd6](https://redirect.github.com/dawidd6) in
[#&#8203;405](https://redirect.github.com/dawidd6/action-download-artifact/pull/405)

#### New Contributors

- [@&#8203;matejdro](https://redirect.github.com/matejdro) made their
first contribution in
[#&#8203;398](https://redirect.github.com/dawidd6/action-download-artifact/pull/398)

**Full Changelog**:
<dawidd6/action-download-artifact@v20...v21>

</details>

<details>
<summary>hoverkraft-tech/compose-action
(hoverkraft-tech/compose-action)</summary>

###
[`v3.0.0`](https://redirect.github.com/hoverkraft-tech/compose-action/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/hoverkraft-tech/compose-action/compare/v3.0.0...v3.0.0)

##### Release Summary

The action now runs on Node 24, modernizing its execution runtime.

No user-facing bug fixes are included in this release.

Internal changes include refreshed Actions/workflows documentation and
dependency maintenance for GitHub Actions, npm, devcontainer Node,
Docker-in-Docker, and fast-uri.
Migrate Dev tools: Biome and Vitest

##### Breaking changes

This release is breaking because the action runtime now runs on Node 24.

##### What's Changed

- docs: update actions and workflows documentation by
[@&#8203;hoverkraft-bot](https://redirect.github.com/hoverkraft-bot)\[bot]
in
[#&#8203;264](https://redirect.github.com/hoverkraft-tech/compose-action/pull/264)
- chore(deps): bump ghcr.io/devcontainers/features/node from 1.7.1 to
2.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;269](https://redirect.github.com/hoverkraft-tech/compose-action/pull/269)
- chore(deps-dev): bump fast-uri from 3.1.0 to 3.1.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;271](https://redirect.github.com/hoverkraft-tech/compose-action/pull/271)
- chore(deps): bump ghcr.io/devcontainers/features/docker-in-docker from
2.17.0 to 3.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;272](https://redirect.github.com/hoverkraft-tech/compose-action/pull/272)
- docs: update actions and workflows documentation by
[@&#8203;hoverkraft-bot](https://redirect.github.com/hoverkraft-bot)\[bot]
in
[#&#8203;275](https://redirect.github.com/hoverkraft-tech/compose-action/pull/275)
- chore(deps): bump the github-actions-dependencies group across 1
directory with 15 updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;274](https://redirect.github.com/hoverkraft-tech/compose-action/pull/274)
- chore(deps): bump the npm-actions-dependencies group across 1
directory with 2 updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;266](https://redirect.github.com/hoverkraft-tech/compose-action/pull/266)
- chore(deps): bump the github-actions-dependencies group with 6 updates
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;277](https://redirect.github.com/hoverkraft-tech/compose-action/pull/277)
- feat!: Update to Node 24 by
[@&#8203;neilime](https://redirect.github.com/neilime) in
[#&#8203;278](https://redirect.github.com/hoverkraft-tech/compose-action/pull/278)

**Full Changelog**:
<hoverkraft-tech/compose-action@v2...v3.0.0>

###
[`v3`](https://redirect.github.com/hoverkraft-tech/compose-action/compare/v2.6.0...v3.0.0)

[Compare
Source](https://redirect.github.com/hoverkraft-tech/compose-action/compare/v2.6.0...v3.0.0)

</details>

<details>
<summary>marocchino/sticky-pull-request-comment
(marocchino/sticky-pull-request-comment)</summary>

###
[`v3.0.4`](https://redirect.github.com/marocchino/sticky-pull-request-comment/releases/tag/v3.0.4)

[Compare
Source](https://redirect.github.com/marocchino/sticky-pull-request-comment/compare/v3.0.3...v3.0.4)

##### What's Changed

- build(deps-dev): Bump vite from 8.0.3 to 8.0.5 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1679](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1679)
- build(deps-dev): Bump vitest from 4.1.2 to 4.1.3 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1680](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1680)
- build(deps-dev): Bump
[@&#8203;types/node](https://redirect.github.com/types/node) from 25.5.2
to 25.6.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1684](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1684)
- build(deps): Bump
[@&#8203;actions/github](https://redirect.github.com/actions/github)
from 9.0.0 to 9.1.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1683](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1683)
- build(deps-dev): Bump vitest from 4.1.3 to 4.1.4 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1682](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1682)
- build(deps-dev): Bump
[@&#8203;biomejs/biome](https://redirect.github.com/biomejs/biome) from
2.4.10 to 2.4.11 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1681](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1681)

**Full Changelog**:
<marocchino/sticky-pull-request-comment@v3.0.3...v3.0.4>

###
[`v3.0.3`](https://redirect.github.com/marocchino/sticky-pull-request-comment/releases/tag/v3.0.3)

[Compare
Source](https://redirect.github.com/marocchino/sticky-pull-request-comment/compare/v3.0.2...v3.0.3)

#### What's Changed

- Move validateExclusiveModes before getBody for fail-fast validation by
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;1663](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1663)
- Add `number_force` that overrides pull\_request number by
[@&#8203;rossjrw](https://redirect.github.com/rossjrw) in
[#&#8203;1652](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1652)
- build(deps-dev): Bump
[@&#8203;biomejs/biome](https://redirect.github.com/biomejs/biome) from
2.4.6 to 2.4.7 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1666](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1666)
- build(deps): Bump picomatch from 4.0.3 to 4.0.4 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1673](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1673)
- build(deps-dev): Bump vitest from 4.1.0 to 4.1.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1674](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1674)
- build(deps-dev): Bump rollup from 4.59.0 to 4.60.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1676](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1676)
- build(deps-dev): Bump
[@&#8203;types/node](https://redirect.github.com/types/node) from 25.5.0
to 25.5.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1677](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1677)
- build(deps-dev): Bump
[@&#8203;biomejs/biome](https://redirect.github.com/biomejs/biome) from
2.4.7 to 2.4.10 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1675](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1675)
- build(deps): Bump brace-expansion by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1678](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1678)
- build(deps-dev): Bump typescript from 5.9.3 to 6.0.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1670](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1670)

#### New Contributors

- [@&#8203;rossjrw](https://redirect.github.com/rossjrw) made their
first contribution in
[#&#8203;1652](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1652)

**Full Changelog**:
<marocchino/sticky-pull-request-comment@v3.0.2...v3.0.3>

###
[`v3.0.2`](https://redirect.github.com/marocchino/sticky-pull-request-comment/releases/tag/v3.0.2)

[Compare
Source](https://redirect.github.com/marocchino/sticky-pull-request-comment/compare/v3.0.1...v3.0.2)

#### What's Changed

- Add comprehensive tests for main.ts covering all branches by
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;1660](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1660)
- Don't create a comment with hide: true by
[@&#8203;marocchino](https://redirect.github.com/marocchino) in
[#&#8203;1661](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1661)

**Full Changelog**:
<marocchino/sticky-pull-request-comment@v3.0.1...v3.0.2>

###
[`v3.0.1`](https://redirect.github.com/marocchino/sticky-pull-request-comment/releases/tag/v3.0.1)

[Compare
Source](https://redirect.github.com/marocchino/sticky-pull-request-comment/compare/v3.0.0...v3.0.1)

##### What's Changed

- Update deps
- Change build system from ncc to rollup
- Use pull\_request trigger in github action

**Full Changelog**:
<marocchino/sticky-pull-request-comment@v3.0.0...v3.0.1>

###
[`v3.0.0`](https://redirect.github.com/marocchino/sticky-pull-request-comment/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/marocchino/sticky-pull-request-comment/compare/v2.9.4...v3.0.0)

#### What's Changed

- Update node to 24
- Update deps

#### New Contributors

**Full Changelog**:
<marocchino/sticky-pull-request-comment@v2.9.4...v3.0.0>

</details>

<details>
<summary>pnpm/action-setup (pnpm/action-setup)</summary>

###
[`v6.0.8`](https://redirect.github.com/pnpm/action-setup/compare/v6.0.7...v6.0.8)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6.0.7...v6.0.8)

###
[`v6.0.7`](https://redirect.github.com/pnpm/action-setup/compare/v6.0.6...v6.0.7)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6.0.6...v6.0.7)

###
[`v6.0.6`](https://redirect.github.com/pnpm/action-setup/releases/tag/v6.0.6)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6.0.5...v6.0.6)

##### What's Changed

- fix: bin\_dest output points to self-updated pnpm, not bootstrap by
[@&#8203;zkochan](https://redirect.github.com/zkochan) in
[#&#8203;249](https://redirect.github.com/pnpm/action-setup/pull/249)

**Full Changelog**:
<pnpm/action-setup@v6.0.5...v6.0.6>

###
[`v6.0.5`](https://redirect.github.com/pnpm/action-setup/releases/tag/v6.0.5)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6.0.4...v6.0.5)

##### What's Changed

- fix: append (not prepend) action node dir to PATH for npm bootstrap by
[@&#8203;zkochan](https://redirect.github.com/zkochan) in
[#&#8203;241](https://redirect.github.com/pnpm/action-setup/pull/241)

**Full Changelog**:
<pnpm/action-setup@v6.0.4...v6.0.5>

###
[`v6.0.4`](https://redirect.github.com/pnpm/action-setup/releases/tag/v6.0.4)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6.0.3...v6.0.4)

##### What's Changed

- fix: use npm co-located with the action node binary by
[@&#8203;benquarmby](https://redirect.github.com/benquarmby) in
[#&#8203;239](https://redirect.github.com/pnpm/action-setup/pull/239)

##### New Contributors

- [@&#8203;benquarmby](https://redirect.github.com/benquarmby) made
their first contribution in
[#&#8203;239](https://redirect.github.com/pnpm/action-setup/pull/239)

**Full Changelog**:
<pnpm/action-setup@v6.0.3...v6.0.4>

###
[`v6.0.3`](https://redirect.github.com/pnpm/action-setup/releases/tag/v6.0.3)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6.0.2...v6.0.3)

Updated pnpm to v11.0.0-rc.5

**Full Changelog**:
<pnpm/action-setup@v6.0.2...v6.0.3>

###
[`v6.0.2`](https://redirect.github.com/pnpm/action-setup/releases/tag/v6.0.2)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6.0.1...v6.0.2)

##### What's Changed

- fix: pnpm self-update binary shadowed by bootstrap on PATH by
[@&#8203;oniani1](https://redirect.github.com/oniani1) in
[#&#8203;230](https://redirect.github.com/pnpm/action-setup/pull/230)

##### New Contributors

- [@&#8203;oniani1](https://redirect.github.com/oniani1) made their
first contribution in
[#&#8203;230](https://redirect.github.com/pnpm/action-setup/pull/230)

**Full Changelog**:
<pnpm/action-setup@v6.0.1...v6.0.2>

###
[`v6.0.1`](https://redirect.github.com/pnpm/action-setup/releases/tag/v6.0.1)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6...v6.0.1)

Update pnpm to v11.0.0-rc.2. `pnpm-lock.yaml` will not be saved with two
documents unless the `packageManager` is set via
`devEngines.packageManager`. Related issue:
[#&#8203;228](https://redirect.github.com/pnpm/action-setup/issues/228)

### [`v6.0.0`]()

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6...v6)

###
[`v6`](https://redirect.github.com/pnpm/action-setup/compare/v5...v6)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v5.0.0...v6)

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/London)

- Branch creation
  - "after 6pm on thursday,before 10am on friday"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/overmindtech/workspace).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMTkuMCIsInVwZGF0ZWRJblZlciI6IjQzLjIxOS4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Wide CI surface area including 1Password secret loading and Docker
Compose-backed integration tests; failures would block merges but do not
change runtime product code.
>
> **Overview**
> Renovate-style **major bumps** across GitHub Actions workflows and one
composite action, with no application code changes.
>
> **Secrets & tooling:** `1password/install-cli-action` moves to
**v4.0.0** everywhere (including Copybara sync and devcontainer build,
from older v2/v3 lines). Devcontainer build also bumps
`1password/load-secrets-action` from v3 to **v4.0.1**.
**pnpm/action-setup** goes from v5 to **v6.0.8** on all Node/pnpm jobs
(still pinned to pnpm **11.6.0**).
>
> **CI integration tests:** `hoverkraft-tech/compose-action` upgrades
**v2.6.0 → v3.0.0** for Docker Compose steps in `ci.yml` (api-server,
gateway, discovery, sdp-go, revlink).
>
> **Artifacts & PR UX:** `dawidd6/action-download-artifact` **v20 →
v21** (SHA-pinned) for bundle baselines and Terraform plan downloads.
`marocchino/sticky-pull-request-comment` **v2 → v3.0.4** in
`actions/submit-plan` for Overmind plan sticky comments.
>
> **Release:** CLI release workflow uses
`actions/attest-build-provenance` **v3 → v4** for SLSA attestations.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
d6e014a91ee0c60926699956955308d8038e39ed. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

GitOrigin-RevId: f12f2e71f1780d126ba39b1e8b7e82fe1ce57a26
tphoney pushed a commit to overmindtech/cli that referenced this pull request Jun 22, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[1password/install-cli-action](https://redirect.github.com/1password/install-cli-action)
| action | major | `v3.0.0` → `v4.0.0` |
|
[1password/install-cli-action](https://redirect.github.com/1password/install-cli-action)
| action | major | `v2.0.2` → `v4.0.0` |
|
[1password/install-cli-action](https://redirect.github.com/1password/install-cli-action)
| action | major | `v3` → `v4` |
|
[1password/load-secrets-action](https://redirect.github.com/1password/load-secrets-action)
| action | major | `v3.2.1` → `v4.0.1` |
|
[actions/attest-build-provenance](https://redirect.github.com/actions/attest-build-provenance)
| action | major | `v3` → `v4` |
|
[dawidd6/action-download-artifact](https://redirect.github.com/dawidd6/action-download-artifact)
| action | major | `v20` → `v21` |
|
[hoverkraft-tech/compose-action](https://redirect.github.com/hoverkraft-tech/compose-action)
| action | major | `v2.6.0` → `v3.0.0` |
|
[marocchino/sticky-pull-request-comment](https://redirect.github.com/marocchino/sticky-pull-request-comment)
| action | major | `v2` → `v3.0.4` |
| [pnpm/action-setup](https://redirect.github.com/pnpm/action-setup) |
action | major | `v5.0.0` → `v6.0.8` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/370) for more information.

---

### Release Notes

<details>
<summary>1password/install-cli-action
(1password/install-cli-action)</summary>

###
[`v4.0.0`](https://redirect.github.com/1Password/install-cli-action/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/1password/install-cli-action/compare/v4.0.0...v4.0.0)

#### What's Changed

##### Compatibility

⚠️ Linux self-hosted runners must have `gpg` available on PATH in order
to verify CLI signature.
([#&#8203;37](https://redirect.github.com/1Password/install-cli-action/pull/37))

##### Security

- Verify 1Password CLI signatures on install for Linux, macOS, and
Windows before adding the binary to PATH.
([#&#8203;37](https://redirect.github.com/1Password/install-cli-action/pull/37))

##### Documentation

- README now includes a notice that 1Password API usage is governed by
the [1Password API Terms of
Service](https://1password.com/legal/api-sdk-terms-of-service).
([#&#8203;39](https://redirect.github.com/1Password/install-cli-action/pull/39))

##### New Contributors

- [@&#8203;libutcher](https://redirect.github.com/libutcher) made their
first contribution in
[1Password#39](https://redirect.github.com/1Password/install-cli-action/pull/39)

**Full Changelog**:
<1Password/install-cli-action@v3...v4.0.0>

###
[`v4`](https://redirect.github.com/1password/install-cli-action/compare/v3.0.0...v4.0.0)

[Compare
Source](https://redirect.github.com/1password/install-cli-action/compare/v3.0.0...v4.0.0)

</details>

<details>
<summary>1password/load-secrets-action
(1password/load-secrets-action)</summary>

###
[`v4.0.1`](https://redirect.github.com/1Password/load-secrets-action/releases/tag/v4.0.1)

[Compare
Source](https://redirect.github.com/1password/load-secrets-action/compare/v4.0.0...v4.0.1)

#### What's Changed

##### Fix

- Fixed a Windows specific issue where 1Password CLI installation could
fail because the downloaded archive lacked a .zip extension required by
PowerShell’s archive extraction fallback.
([#&#8203;154](https://redirect.github.com/1Password/load-secrets-action/pull/154))
- Bump actions/checkout from v5 to v6 in CI workflows.
([#&#8203;156](https://redirect.github.com/1Password/load-secrets-action/pull/156))

##### Security

- Harden GitHub Actions workflows by pinning external actions to
immutable commit SHAs.
([#&#8203;157](https://redirect.github.com/1Password/load-secrets-action/pull/157))

##### Docs

- Add 1Password API Terms of Service notice to the README
([#&#8203;166](https://redirect.github.com/1Password/load-secrets-action/pull/166))

##### New Contributors

- [@&#8203;dagecko](https://redirect.github.com/dagecko) made their
first contribution in
[1Password#157](https://redirect.github.com/1Password/load-secrets-action/pull/157)
- [@&#8203;superteppo](https://redirect.github.com/superteppo) made
their first contribution in
[1Password#154](https://redirect.github.com/1Password/load-secrets-action/pull/154)
- [@&#8203;libutcher](https://redirect.github.com/libutcher) made their
first contribution in
[1Password#166](https://redirect.github.com/1Password/load-secrets-action/pull/166)

**Full Changelog**:
<1Password/load-secrets-action@v4.0.0...v4.0.1>

###
[`v4.0.0`](https://redirect.github.com/1Password/load-secrets-action/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/1password/load-secrets-action/compare/v4.0.0...v4.0.0)

#### What's Changed

- Clear **npm audit** / **Dependabot** findings via **`npm audit fix`**
where safe (e.g. **ajv**, **flatted**, **undici**, and other resolvable
**minimatch** updates).
[#&#8203;151](https://redirect.github.com/1password/load-secrets-action/issues/151)
- Action runtime updated from Node 20 to **Node 24** for GitHub Actions
compatibility ([deprecation
notice](https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/)).
[#&#8203;148](https://redirect.github.com/1password/load-secrets-action/issues/148).

#### New Contributors

- [@&#8203;jjavieralv](https://redirect.github.com/jjavieralv) made
their first contribution in
[1Password#149](https://redirect.github.com/1Password/load-secrets-action/pull/149)

**Full Changelog**:
<1Password/load-secrets-action@v3...v4.0.0>

###
[`v4`](https://redirect.github.com/1password/load-secrets-action/compare/v3.2.1...v4.0.0)

[Compare
Source](https://redirect.github.com/1password/load-secrets-action/compare/v3.2.1...v4.0.0)

</details>

<details>
<summary>actions/attest-build-provenance
(actions/attest-build-provenance)</summary>

###
[`v4.1.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.1.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4.1.0)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Update RELEASE.md docs by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;836](https://redirect.github.com/actions/attest-build-provenance/pull/836)
- Bump `actions/attest` from 4.0.0 to 4.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;838](https://redirect.github.com/actions/attest-build-provenance/pull/838)
- Bump `@actions/attest` from 3.0.0 to 3.1.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#362](https://redirect.github.com/actions/attest/pull/362)
- Bump `@actions/attest` from 3.1.0 to 3.2.0 by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#365](https://redirect.github.com/actions/attest/pull/365)
- Add new `subject-version` input for inclusion in storage record by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#364](https://redirect.github.com/actions/attest/pull/364)
- Add storage record content to README by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[actions/attest#366](https://redirect.github.com/actions/attest/pull/366)

**Full Changelog**:
<actions/attest-build-provenance@v4.0.0...v4.1.0>

###
[`v4.0.0`](https://redirect.github.com/actions/attest-build-provenance/releases/tag/v4.0.0)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v4...v4)

> \[!NOTE]
> As of version 4, `actions/attest-build-provenance` is simply a wrapper
on top of
[`actions/attest`](https://redirect.github.com/actions/attest).
>
> Existing applications may continue to use the
`attest-build-provenance` action, but new implementations should use
`actions/attest` instead.

#### What's Changed

- Prepare v4 release by
[@&#8203;bdehamer](https://redirect.github.com/bdehamer) in
[#&#8203;835](https://redirect.github.com/actions/attest-build-provenance/pull/835)

**Full Changelog**:
<actions/attest-build-provenance@v3.2.0...v4.0.0>

###
[`v4`](https://redirect.github.com/actions/attest-build-provenance/compare/v3...v4)

[Compare
Source](https://redirect.github.com/actions/attest-build-provenance/compare/v3.2.0...v4)

</details>

<details>
<summary>dawidd6/action-download-artifact
(dawidd6/action-download-artifact)</summary>

###
[`v21`](https://redirect.github.com/dawidd6/action-download-artifact/releases/tag/v21)

[Compare
Source](https://redirect.github.com/dawidd6/action-download-artifact/compare/v20...v21)

#### What's Changed

- build(deps): bump
[@&#8203;actions/github](https://redirect.github.com/actions/github)
from 9.0.0 to 9.1.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;396](https://redirect.github.com/dawidd6/action-download-artifact/pull/396)
- build(deps): bump filesize from 11.0.15 to 11.0.16 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;399](https://redirect.github.com/dawidd6/action-download-artifact/pull/399)
- build(deps): bump fast-xml-parser from 5.5.7 to 5.7.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;402](https://redirect.github.com/dawidd6/action-download-artifact/pull/402)
- build(deps): bump
[@&#8203;actions/github](https://redirect.github.com/actions/github)
from 9.1.0 to 9.1.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;400](https://redirect.github.com/dawidd6/action-download-artifact/pull/400)
- build(deps): bump
[@&#8203;actions/core](https://redirect.github.com/actions/core) from
3.0.0 to 3.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;401](https://redirect.github.com/dawidd6/action-download-artifact/pull/401)
- build(deps): bump filesize from 11.0.16 to 11.0.17 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;404](https://redirect.github.com/dawidd6/action-download-artifact/pull/404)
- Download artifacts in creation order by
[@&#8203;matejdro](https://redirect.github.com/matejdro) in
[#&#8203;398](https://redirect.github.com/dawidd6/action-download-artifact/pull/398)
- node\_modules: update by
[@&#8203;dawidd6](https://redirect.github.com/dawidd6) in
[#&#8203;405](https://redirect.github.com/dawidd6/action-download-artifact/pull/405)

#### New Contributors

- [@&#8203;matejdro](https://redirect.github.com/matejdro) made their
first contribution in
[#&#8203;398](https://redirect.github.com/dawidd6/action-download-artifact/pull/398)

**Full Changelog**:
<dawidd6/action-download-artifact@v20...v21>

</details>

<details>
<summary>hoverkraft-tech/compose-action
(hoverkraft-tech/compose-action)</summary>

###
[`v3.0.0`](https://redirect.github.com/hoverkraft-tech/compose-action/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/hoverkraft-tech/compose-action/compare/v3.0.0...v3.0.0)

##### Release Summary

The action now runs on Node 24, modernizing its execution runtime.

No user-facing bug fixes are included in this release.

Internal changes include refreshed Actions/workflows documentation and
dependency maintenance for GitHub Actions, npm, devcontainer Node,
Docker-in-Docker, and fast-uri.
Migrate Dev tools: Biome and Vitest

##### Breaking changes

This release is breaking because the action runtime now runs on Node 24.

##### What's Changed

- docs: update actions and workflows documentation by
[@&#8203;hoverkraft-bot](https://redirect.github.com/hoverkraft-bot)\[bot]
in
[#&#8203;264](https://redirect.github.com/hoverkraft-tech/compose-action/pull/264)
- chore(deps): bump ghcr.io/devcontainers/features/node from 1.7.1 to
2.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;269](https://redirect.github.com/hoverkraft-tech/compose-action/pull/269)
- chore(deps-dev): bump fast-uri from 3.1.0 to 3.1.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;271](https://redirect.github.com/hoverkraft-tech/compose-action/pull/271)
- chore(deps): bump ghcr.io/devcontainers/features/docker-in-docker from
2.17.0 to 3.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;272](https://redirect.github.com/hoverkraft-tech/compose-action/pull/272)
- docs: update actions and workflows documentation by
[@&#8203;hoverkraft-bot](https://redirect.github.com/hoverkraft-bot)\[bot]
in
[#&#8203;275](https://redirect.github.com/hoverkraft-tech/compose-action/pull/275)
- chore(deps): bump the github-actions-dependencies group across 1
directory with 15 updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;274](https://redirect.github.com/hoverkraft-tech/compose-action/pull/274)
- chore(deps): bump the npm-actions-dependencies group across 1
directory with 2 updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;266](https://redirect.github.com/hoverkraft-tech/compose-action/pull/266)
- chore(deps): bump the github-actions-dependencies group with 6 updates
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;277](https://redirect.github.com/hoverkraft-tech/compose-action/pull/277)
- feat!: Update to Node 24 by
[@&#8203;neilime](https://redirect.github.com/neilime) in
[#&#8203;278](https://redirect.github.com/hoverkraft-tech/compose-action/pull/278)

**Full Changelog**:
<hoverkraft-tech/compose-action@v2...v3.0.0>

###
[`v3`](https://redirect.github.com/hoverkraft-tech/compose-action/compare/v2.6.0...v3.0.0)

[Compare
Source](https://redirect.github.com/hoverkraft-tech/compose-action/compare/v2.6.0...v3.0.0)

</details>

<details>
<summary>marocchino/sticky-pull-request-comment
(marocchino/sticky-pull-request-comment)</summary>

###
[`v3.0.4`](https://redirect.github.com/marocchino/sticky-pull-request-comment/releases/tag/v3.0.4)

[Compare
Source](https://redirect.github.com/marocchino/sticky-pull-request-comment/compare/v3.0.3...v3.0.4)

##### What's Changed

- build(deps-dev): Bump vite from 8.0.3 to 8.0.5 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1679](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1679)
- build(deps-dev): Bump vitest from 4.1.2 to 4.1.3 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1680](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1680)
- build(deps-dev): Bump
[@&#8203;types/node](https://redirect.github.com/types/node) from 25.5.2
to 25.6.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1684](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1684)
- build(deps): Bump
[@&#8203;actions/github](https://redirect.github.com/actions/github)
from 9.0.0 to 9.1.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1683](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1683)
- build(deps-dev): Bump vitest from 4.1.3 to 4.1.4 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1682](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1682)
- build(deps-dev): Bump
[@&#8203;biomejs/biome](https://redirect.github.com/biomejs/biome) from
2.4.10 to 2.4.11 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1681](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1681)

**Full Changelog**:
<marocchino/sticky-pull-request-comment@v3.0.3...v3.0.4>

###
[`v3.0.3`](https://redirect.github.com/marocchino/sticky-pull-request-comment/releases/tag/v3.0.3)

[Compare
Source](https://redirect.github.com/marocchino/sticky-pull-request-comment/compare/v3.0.2...v3.0.3)

#### What's Changed

- Move validateExclusiveModes before getBody for fail-fast validation by
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;1663](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1663)
- Add `number_force` that overrides pull\_request number by
[@&#8203;rossjrw](https://redirect.github.com/rossjrw) in
[#&#8203;1652](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1652)
- build(deps-dev): Bump
[@&#8203;biomejs/biome](https://redirect.github.com/biomejs/biome) from
2.4.6 to 2.4.7 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1666](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1666)
- build(deps): Bump picomatch from 4.0.3 to 4.0.4 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1673](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1673)
- build(deps-dev): Bump vitest from 4.1.0 to 4.1.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1674](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1674)
- build(deps-dev): Bump rollup from 4.59.0 to 4.60.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1676](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1676)
- build(deps-dev): Bump
[@&#8203;types/node](https://redirect.github.com/types/node) from 25.5.0
to 25.5.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1677](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1677)
- build(deps-dev): Bump
[@&#8203;biomejs/biome](https://redirect.github.com/biomejs/biome) from
2.4.7 to 2.4.10 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1675](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1675)
- build(deps): Bump brace-expansion by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1678](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1678)
- build(deps-dev): Bump typescript from 5.9.3 to 6.0.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1670](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1670)

#### New Contributors

- [@&#8203;rossjrw](https://redirect.github.com/rossjrw) made their
first contribution in
[#&#8203;1652](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1652)

**Full Changelog**:
<marocchino/sticky-pull-request-comment@v3.0.2...v3.0.3>

###
[`v3.0.2`](https://redirect.github.com/marocchino/sticky-pull-request-comment/releases/tag/v3.0.2)

[Compare
Source](https://redirect.github.com/marocchino/sticky-pull-request-comment/compare/v3.0.1...v3.0.2)

#### What's Changed

- Add comprehensive tests for main.ts covering all branches by
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;1660](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1660)
- Don't create a comment with hide: true by
[@&#8203;marocchino](https://redirect.github.com/marocchino) in
[#&#8203;1661](https://redirect.github.com/marocchino/sticky-pull-request-comment/pull/1661)

**Full Changelog**:
<marocchino/sticky-pull-request-comment@v3.0.1...v3.0.2>

###
[`v3.0.1`](https://redirect.github.com/marocchino/sticky-pull-request-comment/releases/tag/v3.0.1)

[Compare
Source](https://redirect.github.com/marocchino/sticky-pull-request-comment/compare/v3.0.0...v3.0.1)

##### What's Changed

- Update deps
- Change build system from ncc to rollup
- Use pull\_request trigger in github action

**Full Changelog**:
<marocchino/sticky-pull-request-comment@v3.0.0...v3.0.1>

###
[`v3.0.0`](https://redirect.github.com/marocchino/sticky-pull-request-comment/releases/tag/v3.0.0)

[Compare
Source](https://redirect.github.com/marocchino/sticky-pull-request-comment/compare/v2.9.4...v3.0.0)

#### What's Changed

- Update node to 24
- Update deps

#### New Contributors

**Full Changelog**:
<marocchino/sticky-pull-request-comment@v2.9.4...v3.0.0>

</details>

<details>
<summary>pnpm/action-setup (pnpm/action-setup)</summary>

###
[`v6.0.8`](https://redirect.github.com/pnpm/action-setup/compare/v6.0.7...v6.0.8)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6.0.7...v6.0.8)

###
[`v6.0.7`](https://redirect.github.com/pnpm/action-setup/compare/v6.0.6...v6.0.7)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6.0.6...v6.0.7)

###
[`v6.0.6`](https://redirect.github.com/pnpm/action-setup/releases/tag/v6.0.6)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6.0.5...v6.0.6)

##### What's Changed

- fix: bin\_dest output points to self-updated pnpm, not bootstrap by
[@&#8203;zkochan](https://redirect.github.com/zkochan) in
[#&#8203;249](https://redirect.github.com/pnpm/action-setup/pull/249)

**Full Changelog**:
<pnpm/action-setup@v6.0.5...v6.0.6>

###
[`v6.0.5`](https://redirect.github.com/pnpm/action-setup/releases/tag/v6.0.5)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6.0.4...v6.0.5)

##### What's Changed

- fix: append (not prepend) action node dir to PATH for npm bootstrap by
[@&#8203;zkochan](https://redirect.github.com/zkochan) in
[#&#8203;241](https://redirect.github.com/pnpm/action-setup/pull/241)

**Full Changelog**:
<pnpm/action-setup@v6.0.4...v6.0.5>

###
[`v6.0.4`](https://redirect.github.com/pnpm/action-setup/releases/tag/v6.0.4)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6.0.3...v6.0.4)

##### What's Changed

- fix: use npm co-located with the action node binary by
[@&#8203;benquarmby](https://redirect.github.com/benquarmby) in
[#&#8203;239](https://redirect.github.com/pnpm/action-setup/pull/239)

##### New Contributors

- [@&#8203;benquarmby](https://redirect.github.com/benquarmby) made
their first contribution in
[#&#8203;239](https://redirect.github.com/pnpm/action-setup/pull/239)

**Full Changelog**:
<pnpm/action-setup@v6.0.3...v6.0.4>

###
[`v6.0.3`](https://redirect.github.com/pnpm/action-setup/releases/tag/v6.0.3)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6.0.2...v6.0.3)

Updated pnpm to v11.0.0-rc.5

**Full Changelog**:
<pnpm/action-setup@v6.0.2...v6.0.3>

###
[`v6.0.2`](https://redirect.github.com/pnpm/action-setup/releases/tag/v6.0.2)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6.0.1...v6.0.2)

##### What's Changed

- fix: pnpm self-update binary shadowed by bootstrap on PATH by
[@&#8203;oniani1](https://redirect.github.com/oniani1) in
[#&#8203;230](https://redirect.github.com/pnpm/action-setup/pull/230)

##### New Contributors

- [@&#8203;oniani1](https://redirect.github.com/oniani1) made their
first contribution in
[#&#8203;230](https://redirect.github.com/pnpm/action-setup/pull/230)

**Full Changelog**:
<pnpm/action-setup@v6.0.1...v6.0.2>

###
[`v6.0.1`](https://redirect.github.com/pnpm/action-setup/releases/tag/v6.0.1)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6...v6.0.1)

Update pnpm to v11.0.0-rc.2. `pnpm-lock.yaml` will not be saved with two
documents unless the `packageManager` is set via
`devEngines.packageManager`. Related issue:
[#&#8203;228](https://redirect.github.com/pnpm/action-setup/issues/228)

### [`v6.0.0`]()

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v6...v6)

###
[`v6`](https://redirect.github.com/pnpm/action-setup/compare/v5...v6)

[Compare
Source](https://redirect.github.com/pnpm/action-setup/compare/v5.0.0...v6)

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/London)

- Branch creation
  - "after 6pm on thursday,before 10am on friday"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/overmindtech/workspace).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMTkuMCIsInVwZGF0ZWRJblZlciI6IjQzLjIxOS4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Wide CI surface area including 1Password secret loading and Docker
Compose-backed integration tests; failures would block merges but do not
change runtime product code.
>
> **Overview**
> Renovate-style **major bumps** across GitHub Actions workflows and one
composite action, with no application code changes.
>
> **Secrets & tooling:** `1password/install-cli-action` moves to
**v4.0.0** everywhere (including Copybara sync and devcontainer build,
from older v2/v3 lines). Devcontainer build also bumps
`1password/load-secrets-action` from v3 to **v4.0.1**.
**pnpm/action-setup** goes from v5 to **v6.0.8** on all Node/pnpm jobs
(still pinned to pnpm **11.6.0**).
>
> **CI integration tests:** `hoverkraft-tech/compose-action` upgrades
**v2.6.0 → v3.0.0** for Docker Compose steps in `ci.yml` (api-server,
gateway, discovery, sdp-go, revlink).
>
> **Artifacts & PR UX:** `dawidd6/action-download-artifact` **v20 →
v21** (SHA-pinned) for bundle baselines and Terraform plan downloads.
`marocchino/sticky-pull-request-comment` **v2 → v3.0.4** in
`actions/submit-plan` for Overmind plan sticky comments.
>
> **Release:** CLI release workflow uses
`actions/attest-build-provenance` **v3 → v4** for SLSA attestations.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
d6e014a91ee0c60926699956955308d8038e39ed. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

GitOrigin-RevId: f12f2e71f1780d126ba39b1e8b7e82fe1ce57a26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants