diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml
index 61bf9af519c178fae4ac7a3081b5d60657a52247..dc740a461c9b8368bddad4ecaffb2ac15463de9f 100644
--- a/.github/workflows/build.yml
+++ b/.github/workflows/build.yml
@@ -700,7 +700,7 @@ jobs:
           node-version: ${{ needs.setup-build.outputs.node-version }}
           os: ${{ runner.os }}
 
-      - uses: sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da # v3.7.0
+      - uses: sigstore/cosign-installer@c56c2d3e59e4281cc41dea2217323ba5694b171e # v3.8.0
 
       - name: Docker registry login
         run: |