Skip to content

ci: bump cilock-action to v1.0.1#3

Merged
colek42 merged 1 commit intomainfrom
ck/bump-cilock-action-v1.0.1
Apr 14, 2026
Merged

ci: bump cilock-action to v1.0.1#3
colek42 merged 1 commit intomainfrom
ck/bump-cilock-action-v1.0.1

Conversation

@colek42
Copy link
Copy Markdown
Member

@colek42 colek42 commented Apr 14, 2026

Summary

Bumps aflock-ai/cilock-action@v1.0.0@v1.0.1 across all 5 pipeline steps.

Why

v1.0.0 failed our build + sbom and docker-build steps with:

cilock-action: failed to build attestors: unknown attestor "sbom"

v1.0.1 includes 8 new attestor plugins (sbom, docker, oci, k8smanifest, lockfiles, system-packages, vex, policyverify) — exactly what a production CI pipeline needs.

Test plan

  • After merge, workflow triggers on push: main and completes all 5 steps
  • 5 DSSE envelopes land in Archivista with OIDC auth
  • SecureVault SSP picks up at least one as SSPEvidence after rescan

🤖 Generated with Claude Code

v1.0.1 adds sbom, docker, oci, k8smanifest, lockfiles, system-packages,
vex, policyverify — unblocks the build+sbom and docker-build steps
that previously errored with `unknown attestor "sbom"` on v1.0.0.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@colek42 colek42 merged commit e12ebdf into main Apr 14, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant