Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

github-action: use actions/attest-build-provenance #313

Merged
merged 1 commit into from
May 15, 2024

Conversation

v1v
Copy link
Member

@v1v v1v commented May 14, 2024

Details

⚠️ This PR was created by an automated tool. Please review the changes carefully. ⚠️

NOTE: github-early-access/generate-build-provenance has been deprecated in favor of
actions/attest-build-provenance.

If there are any questions, please reach out to the @elastic/observablt-ci

@v1v v1v self-assigned this May 14, 2024
@v1v v1v requested a review from a team May 14, 2024 15:58
@v1v v1v added the dependencies Pull requests that update a dependency file label May 15, 2024
@v1v v1v merged commit 7838098 into main May 15, 2024
7 checks passed
@v1v v1v deleted the gh-oblt/replace-step-build-provenance branch May 15, 2024 07:29
LikeTheSalad added a commit that referenced this pull request May 20, 2024
* Bump the github-actions group with 1 update (#250)

Bumps the github-actions group with 1 update: [actions/upload-artifact](https://github.com/actions/upload-artifact).

- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v3...v4)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Add sample app (#249)

* Created sample app dir

* Adding code from sample-app-android-apm

* Setting latest lib version on sample app

* Updating the sample app README

* Adding doc comment

* ci(release): use new set of credentials for GPG and Maven Central (#255)

* ci(buildkite): vault context switch (#256)

* Revert "Bump the github-actions group with 1 update" (#257)

* ci(release): use the new vault secret path (#258)

* ci(release): fetch field in plain format (#259)

* Sim operator fix (#261)

* Calling getSimOperator once

* Validating simOperator calls

* Updated changelog

* Using short key id (#262)

* Release 0.13.1 (#263)

* Preparing for the next release

* Update gradle.properties

* Update CHANGELOG.asciidoc

* Update CHANGELOG.asciidoc

---------

Co-authored-by: apmmachine <apmmachine@users.noreply.github.com>
Co-authored-by: César <56847527+LikeTheSalad@users.noreply.github.com>

* backstage: add tags for the obltmachine/apmmachine and other things (#266)

* Release/0.14.0 (#267)

* Using gradle version catalog

* Clean up

* Upgrading dependencies

* Updating notice files

* Removing okhttp auto-instrumentation

* Moving okhttp android test network call to the test

* Testing okhttp async calls

* Moving all okhttp tests to NetworkCallingActivityTest

* Clean up

* Adding OTel OkHttp auto-instrumentation

* Clean up common dependencies

* Removing android-instrumentation module

* Adding OTel Android dependency

* Initializing OpenTelemetryRum

* Created LaunchTimeApplicationListener

* Clean up

* Adding OTelRumConfig

* Updating tests

* Preventing compileSdk > 33 to be enforced

* Updating app launch metrics test

* Updating UI span tests

* Adding fragment destruction span UI tests

* Updated coroutines context preservation

* Updating sample-app

* Cleaning up okhttp version lookup

* Adding OTel Android note to the README

* Updating the OTel Android note

* Updated the setup.asciidoc file

* Updated notice files

* Update docs/setup.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Update docs/setup.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Update docs/setup.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Update docs/setup.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Update docs/setup.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Updating OTel Android note

---------

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Preparing for the next release (#268)

Co-authored-by: apmmachine <apmmachine@users.noreply.github.com>

* Updated the changelog (#269)

* Make resources configurable (#276)

* Making OTel resource configurable

* Validating configured resource

* Adding resource config docs

* Updated the CHANGELOG.asciidoc

* ci: use VM with the installed tools and fallback otherwise (#274)

* Preparing for the next release (#277)

Co-authored-by: apmmachine <apmmachine@users.noreply.github.com>

* github-action: listen for all the github workflows (#279)

* security: add permissions block to workflows (#272)

* security: add permissions block to workflows

* Add permissions

* Documentation update (#281)

* Removing links to latest version of artifacts

* Adding note to warn users about version 1.13.1

* Update docs/setup.asciidoc

Co-authored-by: Emily S <emily.s@elastic.co>

* Updating note

* Removing 1.13.1 notes

---------

Co-authored-by: Emily S <emily.s@elastic.co>

* Cicd version validation (#282)

* Validating version override format and major/minor values

* Reorganizing code

* Reorganizing code

* Providing clearer function name

* Updating setup doc versions in post deploy process (#283)

* Cicd release messages update (#284)

* Enhancing slack messages when a release is triggered

* Showing release input params in slack message

* Github action to automatically update version branch after a release (#285)

* Created action to automatically update version branch with the latest changes from main after a release

* Update .github/workflows/updateVersionBranch.yml

Co-authored-by: Victor Martinez <victormartinezrubio@gmail.com>

---------

Co-authored-by: Victor Martinez <victormartinezrubio@gmail.com>

* Remove compilesdk validation (#292)

* Removing androidx libs version constraints

* Updating tests

* Updating sample app compileSdk version

* Updating notice files

* Updated the changelog

* Preparing for the next release (#294)

Co-authored-by: apmmachine <apmmachine@users.noreply.github.com>

* Resolving main to release-branch conflicts before creating PR from main (#299)

* Upgrade gradle version (#300)

* Upgrading to gradle 8.4

* Bumping up gradle env

* Using MaxMetaspaceSize

* Enabling desugaring

* Using new env var mocking lib

* Adding buildconfg fields for tests

* Updating tests

* Using Java 17

* github-action: enable provenance for jar/aar files (#288)

* Documentation changes (#302)

* Bumping Kotlin min version

* Adding signals examples for manual instrumentation

* Explaining sessions in the docs

* Clean up

* github-action: add attestations scope (#305)

* Bump upstream version (#304)

* Bumping OTel deps and addressing Event api changes

* Addressing app listener interface issue

* Sorting lifecycle instrumentation

* Using new disk buffering api

* Adjusting tests to api changes

* Bumping up semconv and contrib versions

* Making CreateNoticeTask output a dir

* Updating jar notice tasks

* Adding notice file to repo for android libs

* Fixing jar create notice file resources dependency

* Bump actions/download-artifact from 3 to 4 in the github-actions group (#306)

Bumps the github-actions group with 1 update: [actions/download-artifact](https://github.com/actions/download-artifact).


Updates `actions/download-artifact` from 3 to 4
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@v3...v4)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Revert "Bump actions/download-artifact from 3 to 4 in the github-actions grou…" (#307)

This reverts commit b7d76f4.

* github-action: use setup composite action for jdk conf (#311)

* Addressing r8 issues (#309)

* Updating build-tools processor to not leak compile-only annotation

* Bumping up gradle in sample app

* Adding R8 common rules

* Updating changelog

* github-action: delete opentelemetry workflow (#312)

* github-action: use actions/attest-build-provenance (#313)

* Adding faq on SSL/TLS config (#310)

* Adding faq on SSL/TLS

* Fixing typo

* Update docs/faq.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Update docs/faq.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Update docs/faq.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Update docs/faq.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

---------

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Preparing for the next release (#314)

Co-authored-by: apmmachine <apmmachine@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Victor Martinez <victormartinezrubio@gmail.com>
Co-authored-by: apmmachine <58790750+apmmachine@users.noreply.github.com>
Co-authored-by: apmmachine <apmmachine@users.noreply.github.com>
Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>
Co-authored-by: Jan Calanog <jan.calanog@elastic.co>
Co-authored-by: Emily S <emily.s@elastic.co>
LikeTheSalad added a commit that referenced this pull request May 30, 2024
* Bump the github-actions group with 1 update (#250)

Bumps the github-actions group with 1 update: [actions/upload-artifact](https://github.com/actions/upload-artifact).

- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v3...v4)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Add sample app (#249)

* Created sample app dir

* Adding code from sample-app-android-apm

* Setting latest lib version on sample app

* Updating the sample app README

* Adding doc comment

* ci(release): use new set of credentials for GPG and Maven Central (#255)

* ci(buildkite): vault context switch (#256)

* Revert "Bump the github-actions group with 1 update" (#257)

* ci(release): use the new vault secret path (#258)

* ci(release): fetch field in plain format (#259)

* Sim operator fix (#261)

* Calling getSimOperator once

* Validating simOperator calls

* Updated changelog

* Using short key id (#262)

* Release 0.13.1 (#263)

* Preparing for the next release

* Update gradle.properties

* Update CHANGELOG.asciidoc

* Update CHANGELOG.asciidoc

---------

Co-authored-by: apmmachine <apmmachine@users.noreply.github.com>
Co-authored-by: César <56847527+LikeTheSalad@users.noreply.github.com>

* backstage: add tags for the obltmachine/apmmachine and other things (#266)

* Release/0.14.0 (#267)

* Using gradle version catalog

* Clean up

* Upgrading dependencies

* Updating notice files

* Removing okhttp auto-instrumentation

* Moving okhttp android test network call to the test

* Testing okhttp async calls

* Moving all okhttp tests to NetworkCallingActivityTest

* Clean up

* Adding OTel OkHttp auto-instrumentation

* Clean up common dependencies

* Removing android-instrumentation module

* Adding OTel Android dependency

* Initializing OpenTelemetryRum

* Created LaunchTimeApplicationListener

* Clean up

* Adding OTelRumConfig

* Updating tests

* Preventing compileSdk > 33 to be enforced

* Updating app launch metrics test

* Updating UI span tests

* Adding fragment destruction span UI tests

* Updated coroutines context preservation

* Updating sample-app

* Cleaning up okhttp version lookup

* Adding OTel Android note to the README

* Updating the OTel Android note

* Updated the setup.asciidoc file

* Updated notice files

* Update docs/setup.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Update docs/setup.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Update docs/setup.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Update docs/setup.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Update docs/setup.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Updating OTel Android note

---------

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Preparing for the next release (#268)

Co-authored-by: apmmachine <apmmachine@users.noreply.github.com>

* Updated the changelog (#269)

* Make resources configurable (#276)

* Making OTel resource configurable

* Validating configured resource

* Adding resource config docs

* Updated the CHANGELOG.asciidoc

* ci: use VM with the installed tools and fallback otherwise (#274)

* Preparing for the next release (#277)

Co-authored-by: apmmachine <apmmachine@users.noreply.github.com>

* github-action: listen for all the github workflows (#279)

* security: add permissions block to workflows (#272)

* security: add permissions block to workflows

* Add permissions

* Documentation update (#281)

* Removing links to latest version of artifacts

* Adding note to warn users about version 1.13.1

* Update docs/setup.asciidoc

Co-authored-by: Emily S <emily.s@elastic.co>

* Updating note

* Removing 1.13.1 notes

---------

Co-authored-by: Emily S <emily.s@elastic.co>

* Cicd version validation (#282)

* Validating version override format and major/minor values

* Reorganizing code

* Reorganizing code

* Providing clearer function name

* Updating setup doc versions in post deploy process (#283)

* Cicd release messages update (#284)

* Enhancing slack messages when a release is triggered

* Showing release input params in slack message

* Github action to automatically update version branch after a release (#285)

* Created action to automatically update version branch with the latest changes from main after a release

* Update .github/workflows/updateVersionBranch.yml

Co-authored-by: Victor Martinez <victormartinezrubio@gmail.com>

---------

Co-authored-by: Victor Martinez <victormartinezrubio@gmail.com>

* Remove compilesdk validation (#292)

* Removing androidx libs version constraints

* Updating tests

* Updating sample app compileSdk version

* Updating notice files

* Updated the changelog

* Preparing for the next release (#294)

Co-authored-by: apmmachine <apmmachine@users.noreply.github.com>

* Resolving main to release-branch conflicts before creating PR from main (#299)

* Upgrade gradle version (#300)

* Upgrading to gradle 8.4

* Bumping up gradle env

* Using MaxMetaspaceSize

* Enabling desugaring

* Using new env var mocking lib

* Adding buildconfg fields for tests

* Updating tests

* Using Java 17

* github-action: enable provenance for jar/aar files (#288)

* Documentation changes (#302)

* Bumping Kotlin min version

* Adding signals examples for manual instrumentation

* Explaining sessions in the docs

* Clean up

* github-action: add attestations scope (#305)

* Bump upstream version (#304)

* Bumping OTel deps and addressing Event api changes

* Addressing app listener interface issue

* Sorting lifecycle instrumentation

* Using new disk buffering api

* Adjusting tests to api changes

* Bumping up semconv and contrib versions

* Making CreateNoticeTask output a dir

* Updating jar notice tasks

* Adding notice file to repo for android libs

* Fixing jar create notice file resources dependency

* Bump actions/download-artifact from 3 to 4 in the github-actions group (#306)

Bumps the github-actions group with 1 update: [actions/download-artifact](https://github.com/actions/download-artifact).


Updates `actions/download-artifact` from 3 to 4
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@v3...v4)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Revert "Bump actions/download-artifact from 3 to 4 in the github-actions grou…" (#307)

This reverts commit b7d76f4.

* github-action: use setup composite action for jdk conf (#311)

* Addressing r8 issues (#309)

* Updating build-tools processor to not leak compile-only annotation

* Bumping up gradle in sample app

* Adding R8 common rules

* Updating changelog

* github-action: delete opentelemetry workflow (#312)

* github-action: use actions/attest-build-provenance (#313)

* Adding faq on SSL/TLS config (#310)

* Adding faq on SSL/TLS

* Fixing typo

* Update docs/faq.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Update docs/faq.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Update docs/faq.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Update docs/faq.asciidoc

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

---------

Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>

* Preparing for the next release (#314)

Co-authored-by: apmmachine <apmmachine@users.noreply.github.com>

* Bump actions/attest-build-provenance from 1.1.1 to 1.1.2 in the github-actions group (#317)

Bumps the github-actions group with 1 update: [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance).
Updates `actions/attest-build-provenance` from 1.1.1 to 1.1.2
- [Release notes](https://github.com/actions/attest-build-provenance/releases)
- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md)
- [Commits](actions/attest-build-provenance@951c0c5...173725a)

* Fetching remote branches before switching to version branch (#316)

* Fetching remote branches before switching to version branch

* Using checkout action params to fetch all git branches

* Adding http exporting path (#319)

* Adding http exporting path

* Updated changelog

* Preparing for the next release (#320)

Co-authored-by: apmmachine <apmmachine@users.noreply.github.com>

* Adding write permissions to updateVersionBranch.yml (#322)

* Upgrading byte buddy plugin (#324)

* Upgrading byte buddy plugin

* Updated chagelog

* Updating notice files metadata

* Preparing for the next release (#325)

Co-authored-by: apmmachine <apmmachine@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: César <56847527+LikeTheSalad@users.noreply.github.com>
Co-authored-by: Victor Martinez <victormartinezrubio@gmail.com>
Co-authored-by: apmmachine <apmmachine@users.noreply.github.com>
Co-authored-by: Brandon Morelli <brandon.morelli@elastic.co>
Co-authored-by: Jan Calanog <jan.calanog@elastic.co>
Co-authored-by: Emily S <emily.s@elastic.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
agent-android agent-mobile dependencies Pull requests that update a dependency file
Projects
Status: Done
Development

Successfully merging this pull request may close these issues.

2 participants