diff --git a/.github/workflows/package_sandbox_kit.yaml b/.github/workflows/package_sandbox_kit.yaml index d39427f51..3457fc47c 100644 --- a/.github/workflows/package_sandbox_kit.yaml +++ b/.github/workflows/package_sandbox_kit.yaml @@ -128,8 +128,11 @@ jobs: # governed by the connection's ruleset, which matches the subject claim # repo:chainloop-dev/chainloop:ref:refs/heads/main - adding an `environment:` # to this job would change that claim and stop it matching. + # Docker Hub OIDC landed in login-action v4.5.0; anything older ignores + # DOCKERHUB_OIDC_CONNECTIONID and fails with "Password required", so this + # pin must not be moved backwards. - name: Docker login to Docker Hub - uses: docker/login-action@af1e73f918a031802d376d3c8bbc3fe56130a9b0 # v4.4.0 + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 env: DOCKERHUB_OIDC_CONNECTIONID: 361a9222-f648-4f62-baf4-5f500f7fbf54 with: @@ -142,8 +145,11 @@ jobs: - name: Add Attestation (Sandbox Kit) and Push Kit run: | - # KIT_VERSION arrives through env, not ${{ }} interpolation, so the value - # is never expanded into this script's source. + # KIT_VERSION arrives through env, not template interpolation, so the + # value is never expanded into this script's source. Do not write the + # literal expression syntax here either: GitHub expands it inside run + # bodies, shell comments included, and an empty one makes the whole + # workflow file fail to parse. # Force the version declared in the kit spec and make sure it exists in # the project by passing --existing-version; if it does not exist the