diff --git a/.github/workflows/release-skill.yml b/.github/workflows/release-skill.yml index 918e132..8d9e84b 100644 --- a/.github/workflows/release-skill.yml +++ b/.github/workflows/release-skill.yml @@ -51,7 +51,7 @@ jobs: uses: aquasecurity/setup-trivy@3fb12ec12f41e471780db15c232d5dd185dcb514 - name: Install Cosign - uses: sigstore/cosign-installer@3454372f43399081ed03b604cb2d021dabca52bb + uses: sigstore/cosign-installer@ba7bc0a3fef59531c69a25acd34668d6d3fe6f22 - name: Generate SPDX SBOM run: syft dir:./dist -o spdx-json > dist/sbom.spdx.json