diff --git a/.github/workflows/publish-package.yml b/.github/workflows/publish-package.yml
index 7f798b3616..9803c69663 100644
--- a/.github/workflows/publish-package.yml
+++ b/.github/workflows/publish-package.yml
@@ -109,7 +109,7 @@ jobs:
         (github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v') && github.repository == 'scikit-hep/pyhf')
         || (github.event_name == 'workflow_dispatch' && github.event.inputs.publish == 'true' && github.repository == 'scikit-hep/pyhf')
         || (github.event_name == 'release' && github.event.action == 'published' && github.repository == 'scikit-hep/pyhf')
-      uses: actions/attest-build-provenance@173725a1209d09b31f9d30a3890cf2757ebbff0d # v1.1.2
+      uses: actions/attest-build-provenance@49df96e17e918a15956db358890b08e61c704919 # v1.2.0
       with:
         subject-path: "dist/pyhf-*"