File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 2020
2121jobs :
2222 publish :
23- uses : bazel-contrib/publish-to-bcr/.github/workflows/publish.yaml@c316f1611511a40423572303f66c80bb30bfe2f8 # v1.4.1
23+ uses : bazel-contrib/publish-to-bcr/.github/workflows/publish.yaml@v1.4.1
2424 with :
2525 tag_name : ${{ inputs.tag_name }}
2626 registry_fork : stackb/bazel-central-registry
Original file line number Diff line number Diff line change @@ -18,7 +18,7 @@ permissions:
1818
1919jobs :
2020 release :
21- uses : bazel-contrib/.github/.github/workflows/release_ruleset.yaml@1d798ff015ed0696433e01e2c3ccbb2abefadad7 # v7.7.0
21+ uses : bazel-contrib/.github/.github/workflows/release_ruleset.yaml@v7.7.0
2222 with :
2323 release_files : jvm_image-*.tar.gz
2424 prerelease : false
Original file line number Diff line number Diff line change @@ -31,9 +31,19 @@ The tag starts `.github/workflows/release.yml`. If BCR publication needs to be
3131retried without recreating the GitHub release, run the ** Publish to BCR**
3232workflow manually and supply the existing tag.
3333
34+ If the source-archive attestation itself must be regenerated, run the full
35+ ** Release** workflow with the existing tag instead. The publish-only workflow
36+ regenerates ` source.json ` and ` MODULE.bazel ` attestations, but not the release
37+ archive attestation.
38+
3439The BCR pull request is intentionally opened as a draft. The token owner must
3540mark it ready for review, which serves as the maintainer approval recognized by
3641the BCR.
3742
43+ The two attestation-producing reusable workflows are referenced by release tag,
44+ not commit SHA. BCR's SLSA verifier requires the builder attestation to contain
45+ a ` refs/tags/... ` workflow ref and rejects a bare SHA as an unknown ref type.
46+ Other third-party Actions remain pinned by commit SHA.
47+
3848The release preparation step rejects malformed tags and refuses to publish
3949until a ` LICENSE ` , ` LICENSE.txt ` , or ` LICENSE.md ` file exists.
You can’t perform that action at this time.
0 commit comments