diff --git a/.github/workflows/github-attest-predicate.yaml b/.github/workflows/github-attest-predicate.yaml index 2cffef5..c8eb4a8 100644 --- a/.github/workflows/github-attest-predicate.yaml +++ b/.github/workflows/github-attest-predicate.yaml @@ -22,15 +22,15 @@ jobs: - uses: actions/attest@v1 id: attest with: - subject-path: 'aenguerrand-examplepackage12-0.2.0.tgz' - subject-name: 'pkg:npm/%40aenguerrand/examplepackage12@0.2.0' + subject-path: 'aenguerrand-examplepackage12-0.3.0.tgz' + subject-name: 'pkg:npm/%40aenguerrand/examplepackage12@0.3.0' predicate-type: 'https://slsa.dev/provenance/v0.2' predicate: '{"builder":{"id":"https://github.com/slsa-framework/slsa-github-generator/.github/workflows/builder_nodejs_slsa3.yml@refs/tags/v2.0.0"}}' - name: Upload artifact (build) uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3 with: - name: aenguerrand-examplepackage12-0.2.0.tgz - path: aenguerrand-examplepackage12-0.2.0.tgz + name: aenguerrand-examplepackage12-0.3.0.tgz + path: aenguerrand-examplepackage12-0.3.0.tgz - name: Upload artifact (build) uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3 with: @@ -39,4 +39,4 @@ jobs: - name: Upload to npmjs.com run: | npm config set //registry.npmjs.org/:_authToken "${{ secrets.NPM_TOKEN }}" - npm publish aenguerrand-examplepackage12-0.2.0.tgz --access public --provenance-file ${{ steps.attest.outputs.bundle-path }} --access public \ No newline at end of file + npm publish aenguerrand-examplepackage12-0.3.0.tgz --access public --provenance-file ${{ steps.attest.outputs.bundle-path }} --access public \ No newline at end of file diff --git a/.github/workflows/github-attest.yaml b/.github/workflows/github-attest.yaml index 8ee1a5f..626d725 100644 --- a/.github/workflows/github-attest.yaml +++ b/.github/workflows/github-attest.yaml @@ -22,13 +22,13 @@ jobs: - uses: actions/attest-build-provenance@v1 id: attest with: - subject-path: 'aenguerrand-examplepackage12-0.2.0.tgz' - subject-name: 'pkg:npm/%40aenguerrand/examplepackage12@0.2.0' + subject-path: 'aenguerrand-examplepackage12-0.3.0.tgz' + subject-name: 'pkg:npm/%40aenguerrand/examplepackage12@0.3.0' - name: Upload artifact (build) uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3 with: - name: aenguerrand-examplepackage12-0.2.0.tgz - path: aenguerrand-examplepackage12-0.2.0.tgz + name: aenguerrand-examplepackage12-0.3.0.tgz + path: aenguerrand-examplepackage12-0.3.0.tgz - name: Upload artifact (build) uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3 with: @@ -37,4 +37,4 @@ jobs: - name: Upload to npmjs.com run: | npm config set //registry.npmjs.org/:_authToken "${{ secrets.NPM_TOKEN }}" - npm publish aenguerrand-examplepackage12-0.2.0.tgz --access public --provenance-file ${{ steps.attest.outputs.bundle-path }} --access public \ No newline at end of file + npm publish aenguerrand-examplepackage12-0.3.0.tgz --access public --provenance-file ${{ steps.attest.outputs.bundle-path }} --access public \ No newline at end of file diff --git a/.github/workflows/sigtstorejs.yaml b/.github/workflows/sigtstorejs.yaml index 4cdb93d..2294ea5 100644 --- a/.github/workflows/sigtstorejs.yaml +++ b/.github/workflows/sigtstorejs.yaml @@ -20,7 +20,7 @@ jobs: - name: Generate dummy package run: npm pack - name: Generate provenance statement with package as attestation subject - run: npx @npmcli/provenance-cli generate aenguerrand-examplepackage12-0.2.0.tgz -o provenance-statement.json --subject-name="pkg:npm/%40aenguerrand/examplepackage12@0.2.0" + run: npx @npmcli/provenance-cli generate aenguerrand-examplepackage12-0.3.0.tgz -o provenance-statement.json --subject-name="pkg:npm/%40aenguerrand/examplepackage12@0.3.0" - name: Sign provenance statement run: npx @sigstore/cli attest ./provenance-statement.json -o provenance.sigstore.json - name: "Verify provenance statement (TODO: Verify source identity)" @@ -33,8 +33,8 @@ jobs: - name: Upload artifact (build) uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3 with: - name: aenguerrand-examplepackage12-0.2.0.tgz - path: aenguerrand-examplepackage12-0.2.0.tgz + name: aenguerrand-examplepackage12-0.3.0.tgz + path: aenguerrand-examplepackage12-0.3.0.tgz - name: Install Cosign uses: sigstore/cosign-installer@v3.7.0 - name: debug @@ -44,4 +44,4 @@ jobs: - name: Upload to npmjs.com run: | npm config set //registry.npmjs.org/:_authToken "${{ secrets.NPM_TOKEN }}" - npm publish aenguerrand-examplepackage12-0.2.0.tgz --access public --provenance-file provenance.sigstore.json --access public \ No newline at end of file + npm publish aenguerrand-examplepackage12-0.3.0.tgz --access public --provenance-file provenance.sigstore.json --access public \ No newline at end of file diff --git a/package.json b/package.json index 01ed19c..078445d 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@aenguerrand/examplepackage12", - "version": "0.2.0", + "version": "0.3.0", "description": "An example npm package for demonstration purposes.", "main": "index.js", "scripts": {