Skip to content

Commit 247c514

Browse files
committed
Update release pipeline versions
1 parent d0b72f0 commit 247c514

3 files changed

Lines changed: 12 additions & 2 deletions

File tree

‎.github/workflows/publish.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ on:
2020

2121
jobs:
2222
publish:
23-
uses: bazel-contrib/publish-to-bcr/.github/workflows/publish.yaml@c316f1611511a40423572303f66c80bb30bfe2f8 # v1.4.1
23+
uses: bazel-contrib/publish-to-bcr/.github/workflows/publish.yaml@v1.4.1
2424
with:
2525
tag_name: ${{ inputs.tag_name }}
2626
registry_fork: stackb/bazel-central-registry

‎.github/workflows/release.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ permissions:
1818

1919
jobs:
2020
release:
21-
uses: bazel-contrib/.github/.github/workflows/release_ruleset.yaml@1d798ff015ed0696433e01e2c3ccbb2abefadad7 # v7.7.0
21+
uses: bazel-contrib/.github/.github/workflows/release_ruleset.yaml@v7.7.0
2222
with:
2323
release_files: jvm_image-*.tar.gz
2424
prerelease: false

‎RELEASING.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,9 +31,19 @@ The tag starts `.github/workflows/release.yml`. If BCR publication needs to be
3131
retried without recreating the GitHub release, run the **Publish to BCR**
3232
workflow manually and supply the existing tag.
3333

34+
If the source-archive attestation itself must be regenerated, run the full
35+
**Release** workflow with the existing tag instead. The publish-only workflow
36+
regenerates `source.json` and `MODULE.bazel` attestations, but not the release
37+
archive attestation.
38+
3439
The BCR pull request is intentionally opened as a draft. The token owner must
3540
mark it ready for review, which serves as the maintainer approval recognized by
3641
the BCR.
3742

43+
The two attestation-producing reusable workflows are referenced by release tag,
44+
not commit SHA. BCR's SLSA verifier requires the builder attestation to contain
45+
a `refs/tags/...` workflow ref and rejects a bare SHA as an unknown ref type.
46+
Other third-party Actions remain pinned by commit SHA.
47+
3848
The release preparation step rejects malformed tags and refuses to publish
3949
until a `LICENSE`, `LICENSE.txt`, or `LICENSE.md` file exists.

0 commit comments

Comments
 (0)