Skip to content

Migrate to actions/attest#2952

Merged
martincostello merged 1 commit intomainfrom
migrate-to-actions-attest
Feb 28, 2026
Merged

Migrate to actions/attest#2952
martincostello merged 1 commit intomainfrom
migrate-to-actions-attest

Conversation

@martincostello
Copy link
Member

Migrate from now-deprecated attestation action to actions/attest.

Migrate from now-deprecated attestation action to `actions/attest`.
Copilot AI review requested due to automatic review settings February 28, 2026 11:54
@martincostello martincostello added enhancement dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Feb 28, 2026
@martincostello martincostello enabled auto-merge (squash) February 28, 2026 11:54
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Migrates the repository’s GitHub Actions artifact attestation step from the deprecated actions/attest-build-provenance action to the consolidated actions/attest action, and updates the Dependabot auto-approval allowlist accordingly.

Changes:

  • Update build workflow to use actions/attest for artifact attestations.
  • Update Dependabot approval workflow allowlist to recognize actions/attest updates.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
.github/workflows/dependabot-approve.yml Updates the Dependabot dependency-name allowlist entry to actions/attest.
.github/workflows/build.yml Switches the attestation step to actions/attest while keeping the same subject-path inputs and required permissions.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@codecov
Copy link

codecov bot commented Feb 28, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 96.15%. Comparing base (24d12d2) to head (6b72c05).
⚠️ Report is 1 commits behind head on main.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #2952   +/-   ##
=======================================
  Coverage   96.15%   96.15%           
=======================================
  Files         309      309           
  Lines        7128     7128           
  Branches     1005     1005           
=======================================
  Hits         6854     6854           
  Misses        221      221           
  Partials       53       53           
Flag Coverage Δ
linux 96.15% <ø> (ø)
macos 96.15% <ø> (ø)
windows 96.14% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@martincostello martincostello merged commit 779aa83 into main Feb 28, 2026
48 of 52 checks passed
@martincostello martincostello deleted the migrate-to-actions-attest branch February 28, 2026 12:31
This was referenced Mar 6, 2026
github-merge-queue bot pushed a commit to DFE-Digital/teaching-record-system that referenced this pull request Mar 9, 2026
Updated [Polly.Core](https://github.com/App-vNext/Polly) from 8.6.5 to
8.6.6.

<details>
<summary>Release notes</summary>

_Sourced from [Polly.Core's
releases](https://github.com/App-vNext/Polly/releases)._

## 8.6.6

## Highlights

* Fix `ScheduledTaskExecutor` deadlock when `TrySetResult` runs
continuations inline by @​crnhrv in
App-vNext/Polly#2953

## What's Changed

* Add specification tests for jitter by @​martincostello in
App-vNext/Polly#2830
* Refactor property-based tests by @​martincostello in
App-vNext/Polly#2831
* .NET 10 preparation by @​martincostello in
App-vNext/Polly#2842
* Fix CS7035 warning in dependabot jobs by @​martincostello in
App-vNext/Polly#2849
* Remove codecov/test-results-action by @​martincostello in
App-vNext/Polly#2872
* Update to .NET 10 SDK by @​martincostello in
App-vNext/Polly#2531
* Bump zizmor to v1.19.0 by @​martincostello in
App-vNext/Polly#2882
* Fix typo by @​martincostello in
App-vNext/Polly#2886
* Add RateLimitHeaders library to community resources by @​alexis- in
App-vNext/Polly#2887
* Bump zizmor to 1.21.0 by @​martincostello in
App-vNext/Polly#2905
* .NET 11 preparation by @​martincostello in
App-vNext/Polly#2932
* Remove Stryker workaround by @​martincostello in
App-vNext/Polly#2933
* Group .NET dependency updates by @​martincostello in
App-vNext/Polly#2944
* Migrate to actions/attest by @​martincostello in
App-vNext/Polly#2952

## New Contributors

* @​alexis- made their first contribution in
App-vNext/Polly#2887
* @​crnhrv made their first contribution in
App-vNext/Polly#2953

**Full Changelog**:
App-vNext/Polly@8.6.5...8.6.6


Commits viewable in [compare
view](App-vNext/Polly@8.6.5...8.6.6).
</details>

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=Polly.Core&package-manager=nuget&previous-version=8.6.5&new-version=8.6.6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: James Gunn <james@gunn.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file enhancement github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants