Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
54 commits
Select commit Hold shift + click to select a range
6a80438
Create generator-generic-ossf-slsa3-publish.yml
Rose2161 Dec 18, 2023
bfdbe86
chore(deps): bump github.com/docker/docker
dependabot[bot] Dec 27, 2023
152364c
Merge pull request #3 from Rose2161/dependabot/go_modules/github.com/…
Rose2161 Jan 1, 2024
d5157f6
chore(deps-dev): bump @babel/traverse in /.github/actions/tscommon
dependabot[bot] Jan 1, 2024
f0d5d4c
chore(deps): bump org.json:json
dependabot[bot] Jan 1, 2024
020823d
Merge pull request #4 from Rose2161/dependabot/npm_and_yarn/dot-githu…
Rose2161 Jan 1, 2024
b39df05
chore(deps): bump google.golang.org/grpc from 1.56.0 to 1.56.3
dependabot[bot] Jan 1, 2024
c1bd853
chore(deps): bump golang.org/x/crypto from 0.12.0 to 0.17.0
dependabot[bot] Jan 1, 2024
d9607c7
chore(deps-dev): bump @babel/traverse
dependabot[bot] Jan 1, 2024
abc9ab6
chore(deps): bump golang.org/x/net from 0.12.0 to 0.17.0
dependabot[bot] Jan 1, 2024
8dc148a
chore(deps): bump github.com/sigstore/cosign/v2 from 2.1.1 to 2.2.1
dependabot[bot] Jan 1, 2024
1ad6918
chore(deps): bump github.com/cloudflare/circl from 1.3.3 to 1.3.7
dependabot[bot] Jan 8, 2024
82bd96d
chore(deps-dev): bump ip from 2.0.0 to 2.0.1
dependabot[bot] Feb 21, 2024
f4b8bc0
chore(deps): bump ip in /.github/actions/verify-token
dependabot[bot] Feb 21, 2024
e615c6b
chore(deps): bump ip in /.github/actions/sign-attestations
dependabot[bot] Feb 21, 2024
eca406e
chore(deps): bump ip in /actions/delegator/setup-generic
dependabot[bot] Feb 21, 2024
25d5dab
fix: upgrade org.apache.maven:maven-plugin-api from 3.6.3 to 3.9.6
snyk-bot Mar 13, 2024
0e7a218
fix: upgrade org.apache.maven.plugin-tools:maven-plugin-annotations f…
snyk-bot Mar 13, 2024
a28d083
fix: upgrade sigstore from 1.8.0 to 1.9.0
snyk-bot Mar 14, 2024
426b603
Merge pull request #5 from Rose2161/dependabot/maven/actions/maven/pu…
Rose2161 Mar 17, 2024
e198d05
Merge pull request #6 from Rose2161/dependabot/go_modules/google.gola…
Rose2161 Mar 17, 2024
412e115
Merge pull request #7 from Rose2161/dependabot/go_modules/golang.org/…
Rose2161 Mar 17, 2024
c385958
Merge pull request #8 from Rose2161/dependabot/npm_and_yarn/dot-githu…
Rose2161 Mar 17, 2024
3299339
chore(deps): bump google.golang.org/protobuf from 1.31.0 to 1.33.0
dependabot[bot] Mar 17, 2024
4e92273
chore(deps): bump github.com/go-jose/go-jose/v3 from 3.0.0 to 3.0.3
dependabot[bot] Mar 17, 2024
7089eb6
Merge pull request #17 from Rose2161/dependabot/npm_and_yarn/actions/…
Rose2161 Mar 17, 2024
054e34e
Merge pull request #15 from Rose2161/dependabot/npm_and_yarn/dot-gith…
Rose2161 Mar 17, 2024
8467b8e
Merge pull request #22 from Rose2161/snyk-upgrade-8f9039c792b9fe3573e…
Rose2161 Mar 17, 2024
8f31980
Merge pull request #21 from Rose2161/dependabot/go_modules/google.gol…
Rose2161 Mar 17, 2024
4208fbd
Merge pull request #16 from Rose2161/dependabot/npm_and_yarn/dot-gith…
Rose2161 Mar 17, 2024
087e6c1
chore(deps-dev): bump @babel/traverse
dependabot[bot] Mar 17, 2024
981d68e
Merge pull request #12 from Rose2161/dependabot/go_modules/github.com…
Rose2161 Mar 17, 2024
172552a
Merge pull request #19 from Rose2161/snyk-upgrade-e24c937f9b204fd24ad…
Rose2161 Mar 17, 2024
d030335
chore(deps-dev): bump @babel/traverse
dependabot[bot] Mar 17, 2024
35bb96c
Merge pull request #13 from slsa-framework/main
Rose2161 Mar 17, 2024
52fe087
Merge pull request #18 from Rose2161/dependabot/go_modules/github.com…
Rose2161 Mar 17, 2024
704bffd
Merge pull request #14 from Rose2161/dependabot/npm_and_yarn/ip-2.0.1
Rose2161 Mar 17, 2024
9e39b30
Merge pull request #20 from Rose2161/snyk-upgrade-8985957eb106368afe6…
Rose2161 Mar 17, 2024
82a7b8b
Merge pull request #23 from Rose2161/dependabot/npm_and_yarn/dot-gith…
Rose2161 Mar 17, 2024
475eeb4
Merge pull request #24 from Rose2161/dependabot/npm_and_yarn/dot-gith…
Rose2161 Mar 17, 2024
5558e46
Merge branch 'main' into dependabot/go_modules/golang.org/x/net-0.17.0
Rose2161 Mar 17, 2024
eff97bc
Merge pull request #9 from Rose2161/dependabot/go_modules/golang.org/…
Rose2161 Mar 17, 2024
95fed05
Merge branch 'main' into dependabot/go_modules/github.com/sigstore/co…
Rose2161 Mar 17, 2024
b3d4278
Merge pull request #11 from Rose2161/dependabot/go_modules/github.com…
Rose2161 Mar 17, 2024
69c7d2c
chore(deps): bump github.com/lestrrat-go/jwx/v2 from 2.0.16 to 2.0.21…
dependabot[bot] Apr 9, 2026
fbb2200
ci(Mergify): configuration update (#29)
Rose2161 May 11, 2026
53fc3f8
Update mergify configuration for queue rules
Rose2161 May 11, 2026
6a2addf
Fix: Correct invalid Mergify configuration schema
Rose2161 May 11, 2026
b4d0568
Fix YAML syntax errors in SLSA workflow
Rose2161 May 11, 2026
dbf4c69
fix: Improve workflow with better error handling and updated action v…
Rose2161 May 11, 2026
5f882f6
ci(mergify): upgrade configuration to current format (#40)
mergify[bot] May 13, 2026
45b14f6
chore(deps): bump the go_modules group across 1 directory with 12 upd…
dependabot[bot] May 13, 2026
a5bb60f
Delete .github/workflows/generator-generic-ossf-slsa3-publish.yml
Rose2161 May 13, 2026
a7ea9fb
Merge branch 'main' into Rose2161-patch-1
Rose2161 May 13, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5,155 changes: 5,154 additions & 1 deletion .github/actions/create-container_based-predicate/package-lock.json

Large diffs are not rendered by default.

71 changes: 71 additions & 0 deletions .github/actions/detect-workflow-js/package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

71 changes: 71 additions & 0 deletions .github/actions/generate-attestations/package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

71 changes: 71 additions & 0 deletions .github/actions/tscommon/package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

5 changes: 5 additions & 0 deletions .mergify.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
queue_rules:
- name: 'default'
merge_method: fast-forward
merge_protections_settings:
reporting_method: check-runs
13 changes: 13 additions & 0 deletions actions/delegator/setup-generic/package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

6 changes: 3 additions & 3 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ require (
github.com/go-openapi/swag v0.23.0
github.com/google/go-cmp v0.6.0
github.com/google/go-github/v57 v57.0.0
github.com/in-toto/in-toto-golang v0.9.0
github.com/in-toto/in-toto-golang v0.11.0
github.com/pelletier/go-toml v1.9.5
github.com/secure-systems-lab/go-securesystemslib v0.8.0
github.com/sigstore/cosign/v2 v2.4.1
Expand All @@ -28,6 +28,7 @@ require (
filippo.io/edwards25519 v1.1.0 // indirect
github.com/AliyunContainerService/ack-ram-tool/pkg/credentials/provider v0.14.0 // indirect
github.com/Azure/azure-sdk-for-go v68.0.0+incompatible // indirect
github.com/Azure/go-ansiterm v0.0.0-20250102033503-faa5f7b0171c // indirect
github.com/Azure/go-autorest v14.2.0+incompatible // indirect
github.com/Azure/go-autorest/autorest v0.11.29 // indirect
github.com/Azure/go-autorest/autorest/adal v0.9.23 // indirect
Expand Down Expand Up @@ -132,7 +133,7 @@ require (
github.com/mailru/easyjson v0.7.7 // indirect
github.com/miekg/pkcs11 v1.1.1 // indirect
github.com/mitchellh/go-homedir v1.1.0 // indirect
github.com/mitchellh/mapstructure v1.5.0 // indirect
github.com/moby/term v0.5.2 // indirect
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
github.com/modern-go/reflect2 v1.0.2 // indirect
github.com/mozillazg/docker-credential-acr-helper v0.4.0 // indirect
Expand All @@ -149,7 +150,6 @@ require (
github.com/sagikazarmark/locafero v0.4.0 // indirect
github.com/sagikazarmark/slog-shim v0.1.0 // indirect
github.com/sassoftware/relic v7.2.1+incompatible // indirect
github.com/segmentio/ksuid v1.0.4 // indirect
github.com/shibumi/go-pathspec v1.3.0 // indirect
github.com/sigstore/fulcio v1.6.3 // indirect
github.com/sigstore/protobuf-specs v0.3.2 // indirect
Expand Down
11 changes: 4 additions & 7 deletions go.sum
Original file line number Diff line number Diff line change
@@ -1,3 +1,5 @@
al.essio.dev/pkg/shellescape v1.6.0 h1:NxFcEqzFSEVCGN2yq7Huv/9hyCEGVa/TncnOOBBeXHA=
al.essio.dev/pkg/shellescape v1.6.0/go.mod h1:6sIqp7X2P6mThCQ7twERpZTuigpr6KbZWtls1U8I890=
cloud.google.com/go v0.26.0/go.mod h1:aQUYkXzVsufM+DwF1aE+0xfcU+56JwCaLick0ClmMTw=
cloud.google.com/go v0.115.1 h1:Jo0SM9cQnSkYfp44+v+NQXHpcHqlnRJk2qxh6yvxxxQ=
cloud.google.com/go v0.115.1/go.mod h1:DuujITeaufu3gL68/lOFIirVNJwQeyf5UXyi+Wbgknc=
Expand Down Expand Up @@ -229,7 +231,6 @@ github.com/emicklei/go-restful/v3 v3.11.0/go.mod h1:6n3XBCmQQb25CM2LCACGz8ukIrRr
github.com/emicklei/proto v1.12.1 h1:6n/Z2pZAnBwuhU66Gs8160B8rrrYKo7h2F2sCOnNceE=
github.com/emicklei/proto v1.12.1/go.mod h1:rn1FgRS/FANiZdD2djyH7TMA9jdRDcYQ9IEN9yvjX0A=
github.com/envoyproxy/go-control-plane v0.9.0/go.mod h1:YTl/9mNaCwkRvm6d1a2C3ymFceY/DCBVvsKhRF0iEA4=
github.com/envoyproxy/go-control-plane v0.9.1-0.20191026205805-5f8ba28d4473/go.mod h1:YTl/9mNaCwkRvm6d1a2C3ymFceY/DCBVvsKhRF0iEA4=
github.com/envoyproxy/go-control-plane v0.9.4/go.mod h1:6rpuAdCZL397s3pYoYcLgu1mIlRU8Am5FuJP05cCM98=
github.com/envoyproxy/protoc-gen-validate v0.1.0/go.mod h1:iSmxcyjqTsJpI2R4NaDN7+kN2VEUnK/pcBlmesArF7c=
github.com/fatih/color v1.16.0 h1:zmkK9Ngbjj+K0yRhTVONQh1p/HknKYSlNT+vZCzyokM=
Expand Down Expand Up @@ -313,9 +314,7 @@ github.com/golang/protobuf v1.4.0-rc.1.0.20200221234624-67d41d38c208/go.mod h1:x
github.com/golang/protobuf v1.4.0-rc.2/go.mod h1:LlEzMj4AhA7rCAGe4KMBDvJI+AwstrUpVNzEA03Pprs=
github.com/golang/protobuf v1.4.0-rc.4.0.20200313231945-b860323f09d0/go.mod h1:WU3c8KckQ9AFe+yFwt9sWVRKCVIyN9cPHBJSNnbL67w=
github.com/golang/protobuf v1.4.0/go.mod h1:jodUvKwWbYaEsadDk5Fwe5c77LiNKVO9IDvqG2KuDX0=
github.com/golang/protobuf v1.4.1/go.mod h1:U8fpvMrcmy5pZrNK1lt4xCsGvpyWQ/VVv6QDs8UjoX8=
github.com/golang/protobuf v1.4.2/go.mod h1:oDoupMAO8OvCJWAcko0GGGIgR6R6ocIYbsSw735rRwI=
github.com/golang/protobuf v1.4.3/go.mod h1:oDoupMAO8OvCJWAcko0GGGIgR6R6ocIYbsSw735rRwI=
github.com/golang/protobuf v1.5.0/go.mod h1:FsONVRAS9T7sI+LIUmWTfcYkHO4aIWwzhcaSAoJOfIk=
github.com/golang/protobuf v1.5.2/go.mod h1:XVQd3VNwM+JqD3oG2Ue2ip4fOMUkwXdXDdiuN0vRsmY=
github.com/golang/protobuf v1.5.4 h1:i7eJL8qZTpSEXOPTxNKhASYpMn+8e5Q6AdndVa1dWek=
Expand Down Expand Up @@ -344,6 +343,8 @@ github.com/google/go-github/v55 v55.0.0 h1:4pp/1tNMB9X/LuAhs5i0KQAE40NmiR/y6prLN
github.com/google/go-github/v55 v55.0.0/go.mod h1:JLahOTA1DnXzhxEymmFF5PP2tSS9JVNj68mSZNDwskA=
github.com/google/go-github/v57 v57.0.0 h1:L+Y3UPTY8ALM8x+TV0lg+IEBI+upibemtBD8Q9u7zHs=
github.com/google/go-github/v57 v57.0.0/go.mod h1:s0omdnye0hvK/ecLvpsGfJMiRt85PimQh4oygmLIxHw=
github.com/google/go-github/v73 v73.0.0 h1:aR+Utnh+Y4mMkS+2qLQwcQ/cF9mOTpdwnzlaw//rG24=
github.com/google/go-github/v73 v73.0.0/go.mod h1:fa6w8+/V+edSU0muqdhCVY7Beh1M8F1IlQPZIANKIYw=
github.com/google/go-querystring v1.1.0 h1:AnCroh3fv4ZBgVIf1Iwtovgjaw/GiKJo8M8yD/fhyJ8=
github.com/google/go-querystring v1.1.0/go.mod h1:Kcdr2DB4koayq7X8pmAG4sNG59So17icRSOU623lUBU=
github.com/google/gofuzz v1.0.0/go.mod h1:dBl0BpW6vV/+mYPU4Po3pmUjxk6FQPldtuIdl/M65Eg=
Expand Down Expand Up @@ -459,7 +460,6 @@ github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd h1:TRLaZ9cD/w
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd/go.mod h1:6dJC0mAP4ikYIbvyc7fijjWJddQyLn8Ig3JB5CqoB9Q=
github.com/modern-go/reflect2 v0.0.0-20180701023420-4b7aa43c6742/go.mod h1:bx2lNnkwVCuqBIxFjflWJWanXIb3RllmbCylyMrvgv0=
github.com/modern-go/reflect2 v1.0.1/go.mod h1:bx2lNnkwVCuqBIxFjflWJWanXIb3RllmbCylyMrvgv0=
github.com/modern-go/reflect2 v1.0.2 h1:xBagoLtFs94CBntxluKeaWgTMpvLxC4ur3nMaC9Gz0M=
github.com/modern-go/reflect2 v1.0.2/go.mod h1:yWuevngMOJpCy52FWWMvUC8ws7m/LJsjYzDa0/r8luk=
github.com/mozillazg/docker-credential-acr-helper v0.4.0 h1:Uoh3Z9CcpEDnLiozDx+D7oDgRq7X+R296vAqAumnOcw=
github.com/mozillazg/docker-credential-acr-helper v0.4.0/go.mod h1:2kiicb3OlPytmlNC9XGkLvVC+f0qTiJw3f/mhmeeQBg=
Expand Down Expand Up @@ -602,7 +602,6 @@ github.com/stretchr/testify v1.7.0/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/
github.com/stretchr/testify v1.7.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
github.com/stretchr/testify v1.7.2/go.mod h1:R6va5+xMeoiuVRoj+gSkQ7d3FALtqAAGI1FQKckRals=
github.com/stretchr/testify v1.8.0/go.mod h1:yNjHg4UonilssWZ8iaSj1OCr/vHnekPRkoO+kdMU+MU=
github.com/stretchr/testify v1.8.1/go.mod h1:w2LPCIKwWwSfY2zedu0+kehJoqGctiVI29o6fzry7u4=
github.com/stretchr/testify v1.8.2/go.mod h1:w2LPCIKwWwSfY2zedu0+kehJoqGctiVI29o6fzry7u4=
github.com/stretchr/testify v1.8.4/go.mod h1:sz/lmYIOXD/1dqDmKjjqLyZ2RngseejIcXlSw2iwfAo=
github.com/stretchr/testify v1.9.0 h1:HtqpIVDClZ4nwg75+f6Lvsy/wHu+3BoSGCbBAcpTsTg=
Expand Down Expand Up @@ -851,7 +850,6 @@ google.golang.org/protobuf v0.0.0-20200221191635-4d8936d0db64/go.mod h1:kwYJMbMJ
google.golang.org/protobuf v0.0.0-20200228230310-ab0ca4ff8a60/go.mod h1:cfTl7dwQJ+fmap5saPgwCLgHXTUD7jkjRqWcaiX5VyM=
google.golang.org/protobuf v1.20.1-0.20200309200217-e05f789c0967/go.mod h1:A+miEFZTKqfCUM6K7xSMQL9OKL/b6hQv+e19PK+JZNE=
google.golang.org/protobuf v1.21.0/go.mod h1:47Nbq4nVaFHyn7ilMalzfO3qCViNmqZ2kzikPIcrTAo=
google.golang.org/protobuf v1.22.0/go.mod h1:EGpADcykh3NcUnDUJcl1+ZksZNG86OlYog2l/sGQquU=
google.golang.org/protobuf v1.23.0/go.mod h1:EGpADcykh3NcUnDUJcl1+ZksZNG86OlYog2l/sGQquU=
google.golang.org/protobuf v1.23.1-0.20200526195155-81db48ad09cc/go.mod h1:EGpADcykh3NcUnDUJcl1+ZksZNG86OlYog2l/sGQquU=
google.golang.org/protobuf v1.25.0/go.mod h1:9JNX74DMeImyA3h4bdi1ymwjUzf21/xIlbajtzgsN7c=
Expand All @@ -875,7 +873,6 @@ gopkg.in/yaml.v2 v2.2.2/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
gopkg.in/yaml.v2 v2.2.4/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
gopkg.in/yaml.v2 v2.2.8/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
gopkg.in/yaml.v2 v2.3.0/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
gopkg.in/yaml.v2 v2.4.0 h1:D8xgwECY7CYvx+Y2n4sBz93Jn9JRvxdiyyo8CTfuKaY=
gopkg.in/yaml.v2 v2.4.0/go.mod h1:RDklbk79AGWmwhnvt/jBztapEOGDOx6ZbXqjP6csGnQ=
gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
Expand Down