diff --git a/.github/workflows/pipeline.yml b/.github/workflows/pipeline.yml index 0fe122d..43eb5d8 100644 --- a/.github/workflows/pipeline.yml +++ b/.github/workflows/pipeline.yml @@ -202,7 +202,7 @@ jobs: # against the sigstore community Fulcio instance. run: cosign sign --yes ${{ env.CONTAINER_REGISTRY }}/${{ env.CONTAINER_IMAGE_NAME }}:${{ env.CONTAINER_IMAGE_VERSION }} - name: Download cosign vulnerability scan record - uses: actions/download-artifact@v3 + uses: actions/download-artifact@v4 with: name: "vuln.json" - name: Attest vulnerability scan