diff --git a/.github/workflows/tag-and-build-release.yaml b/.github/workflows/tag-and-build-release.yaml index 421f9792..954cccb8 100644 --- a/.github/workflows/tag-and-build-release.yaml +++ b/.github/workflows/tag-and-build-release.yaml @@ -82,7 +82,7 @@ jobs: id-token: write # To sign the provenance. contents: write # To add assets to a release. # use tags here: https://github.com/slsa-framework/slsa-github-generator#referencing-slsa-builders-and-generators - uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v1.7.0 + uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v1.9.0 with: attestation-name: "sigstore-java-${{ github.event.inputs.release_version }}.attestation.intoto.jsonl" base64-subjects: "${{ needs.build.outputs.hashes }}"