From 6fc16ec401a784149f18c46b1e2a095647a4ff31 Mon Sep 17 00:00:00 2001 From: Remi Gacogne Date: Tue, 9 Jan 2024 12:40:29 +0100 Subject: [PATCH] build-packages: Fix the handling of provenance artifacts The current version of the SLSA framework uses upload-artifact v3 which is not compatible with download-artifact v4 (don't ask me). --- .github/workflows/build-packages.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/build-packages.yml b/.github/workflows/build-packages.yml index e593ea7706..13ab3a36b3 100644 --- a/.github/workflows/build-packages.yml +++ b/.github/workflows/build-packages.yml @@ -187,12 +187,12 @@ jobs: steps: - name: Download source tarball provenance for ${{ inputs.product }} (${{ inputs.ref }}) id: download-src-provenance - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v3 # we need v3, see https://github.com/slsa-framework/slsa-github-generator/pull/3067/files with: name: "${{ inputs.product }}-${{ needs.build.outputs.version }}-src.intoto.jsonl" - name: Download provenance for ${{ inputs.product }} (${{ inputs.ref }}) for ${{ matrix.os }} id: download-provenance - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v3 # we need v3, see https://github.com/slsa-framework/slsa-github-generator/pull/3067/files with: name: "${{ inputs.product }}-${{ needs.build.outputs.version }}-${{ matrix.os}}.intoto.jsonl" - name: Upload provenance artifacts to downloads.powerdns.com -- 2.47.2