chore(deps): Bump actions/attest from 4.1.1 to 4.2.0#237
Merged
mergify[bot] merged 1 commit intoJul 23, 2026
Conversation
Contributor
Merge Protections🟢 All 3 merge protections satisfied — ready to merge. Show 3 satisfied protections🟢 Full CI must passAll CI checks must pass. This protection prevents manual merges that bypass the merge queue.
🟢 Do not merge outdated PRsMake sure PRs are within 10 commits of the base branch before merging
🟢 🚦 Auto-queueWhen all merge protections are satisfied and these conditions match, this pull request will be queued automatically.
|
Contributor
Merge Queue Status
This pull request spent 13 minutes 45 seconds in the queue, with no time running CI. Waiting for
All conditions
ReasonThe pull request #237 has been manually updated Failing checks: Requeued — the merge queue status continues in this comment ↓. |
55 tasks
Bumps [actions/attest](https://github.com/actions/attest) from 4.1.1 to 4.2.0. - [Release notes](https://github.com/actions/attest/releases) - [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md) - [Commits](actions/attest@a1948c3...f7c74d2) --- updated-dependencies: - dependency-name: actions/attest dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/github_actions/actions/attest-4.2.0
branch
from
July 23, 2026 07:22
0cb84ed to
56faf28
Compare
This was referenced Jul 23, 2026
Contributor
Merge Queue Status
This pull request spent 19 minutes 5 seconds in the queue, including 18 minutes 34 seconds running CI. Required conditions to merge
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps actions/attest from 4.1.1 to 4.2.0.
Release notes
Sourced from actions/attest's releases.
Commits
f7c74d2feat: support SHA-2 subject digests (#446)88633d1Bump js-yaml from 4.2.0 to 5.2.1 (#452)5dff824Bump the actions-minor group with 3 updates (#453)e67e539Bump the npm-development group across 1 directory with 2 updates (#448)95f6155Bump@types/nodefrom 25.9.2 to 26.1.1 (#449)b644c72Read subjects from GITHUB_ARTIFACTS_LIST (#447)7d3af28Bump csv-parse from 6.2.1 to 7.0.1 (#437)52cbb4dBump@actions/globfrom 0.6.1 to 0.7.0 in the npm-production group across 1 d...a5ce33eci: download rebuilt dist/ artifact outside the checkout workspace (#445)4c65731ci: auto-rebuild dist/ for Dependabot production bumps (#444)