From f0de300789adacbf92176910f3b8ab329cc008f9 Mon Sep 17 00:00:00 2001 From: Giacomo Lorenzi <46973382+giacob500@users.noreply.github.com> Date: Thu, 19 Dec 2024 21:27:36 +0000 Subject: [PATCH] ci: disable build provenance by adding comments (#4634) * fixes #4580 --- .github/workflows/build-wheel.yml | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/.github/workflows/build-wheel.yml b/.github/workflows/build-wheel.yml index 3e1f10de2d..67e2da9cb9 100644 --- a/.github/workflows/build-wheel.yml +++ b/.github/workflows/build-wheel.yml @@ -43,12 +43,12 @@ jobs: run: | echo "tar=$(cd dist/ && echo *.tar.gz)" >> $GITHUB_OUTPUT echo "whl=$(cd dist/ && echo *.tar.gz)" >> $GITHUB_OUTPUT - - name: Attest Build Provenance for tar - uses: actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1.0 - with: - subject-path: "dist/${{ steps.filename.outputs.tar }}" - - name: Attest Build Provenance for whl - uses: actions/attest-build-provenance@7668571508540a607bdfd90a87a560489fe372eb # v2.1.0 - with: - subject-path: "dist/${{ steps.filename.outputs.whl }}" + #- name: Attest Build Provenance for tar + # uses: actions/attest-build-provenance@ef244123eb79f2f7a7e75d99086184180e6d0018 # v1.4.4 + # with: + # subject-path: "dist/${{ steps.filename.outputs.tar }}" + #- name: Attest Build Provenance for whl + # uses: actions/attest-build-provenance@ef244123eb79f2f7a7e75d99086184180e6d0018 # v1.4.4 + # with: + # subject-path: "dist/${{ steps.filename.outputs.whl }}" # TODO Upload to pypi on release creation