Bump slsa-framework/slsa-github-generator from 1.6.0 to 1.10.0
Bumps slsa-framework/slsa-github-generator from 1.6.0 to 1.10.0.
Release notes
Sourced from slsa-framework/slsa-github-generator's releases.
v1.10.0
See the CHANGELOG for details.
v1.9.1
This is an un-finalized release.
See the CHANGELOG for details.
v1.9.1-rc.0
See the CHANGELOG for details.
v1.9.0
See the CHANGELOG for details.
v1.9.0-rc.0
This is an un-finalized pre-release.
See the CHANGELOG for details.
v1.8.0
See the CHANGELOG for details.
v1.8.0-rc.2
See the CHANGELOG for details.
v1.8.0-rc.1
See the CHANGELOG for details.
v1.8.0-rc.0
See the CHANGELOG for details.
v1.7.0
See the CHANGELOG for details.
v1.7.0-rc.1
See the CHANGELOG for details.
v1.7.0-rc.0
See the CHANGELOG for details.
This is UNFINALIZED.
Commits
c747fe7chore: Update ref for v1.10.0 release (#3420)d97d88echore: v1.10.0-rc.0 (#3418)6ff2c75chore: Amend readme text before release (#3402)2cf77fachore: Revert "fix: remove attestation-name input and output" (#3399)5c347c0chore: ref builders at main (#3417)e4fc9a0chore: fix release workflow (#3414)6953299chore: v1.9.1-rc.0 (#3413)a2540a1chore: Update changelog for #3350 (#3401)90f2eb1chore: Revert "fix: upload-artifact and download-artifact v4" (#3398)1fee7c6fix: Bump Cosign to latest v2.2.3 (#3355)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)