Skip to content

Bump the actions group with 5 updates - #100

Merged
carole-lavillonniere merged 1 commit into
mainfrom
dependabot/github_actions/actions-4ef91543cb
Sep 2, 2026
Merged

Bump the actions group with 5 updates#100
carole-lavillonniere merged 1 commit into
mainfrom
dependabot/github_actions/actions-4ef91543cb

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 27, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions group with 5 updates:

Package From To
actions/checkout 3 7
docker/setup-buildx-action 1 4
docker/login-action 2 4
docker/metadata-action 4 6
docker/build-push-action 3 7

Updates actions/checkout from 3 to 7

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

... (truncated)

Commits

Updates docker/setup-buildx-action from 1 to 4

Release notes

Sourced from docker/setup-buildx-action's releases.

v4.0.0

Full Changelog: docker/setup-buildx-action@v3.12.0...v4.0.0

v3.12.0

Full Changelog: docker/setup-buildx-action@v3.11.1...v3.12.0

v3.11.1

Full Changelog: docker/setup-buildx-action@v3.11.0...v3.11.1

v3.11.0

Full Changelog: docker/setup-buildx-action@v3.10.0...v3.11.0

v3.10.0

Full Changelog: docker/setup-buildx-action@v3.9.0...v3.10.0

v3.9.0

Full Changelog: docker/setup-buildx-action@v3.8.0...v3.9.0

v3.8.0

Full Changelog: docker/setup-buildx-action@v3.7.1...v3.8.0

... (truncated)

Commits
  • 37fe631 Merge pull request #595 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • b5c4f91 [dependabot skip] chore: update generated content
  • 3e93b63 build(deps): bump @​docker/actions-toolkit from 0.92.0 to 0.95.0
  • e527031 Merge pull request #600 from docker/dependabot/npm_and_yarn/brace-expansion-1...
  • c68814b [dependabot skip] chore: update generated content
  • 3f891b0 build(deps): bump brace-expansion from 1.1.13 to 1.1.18
  • 787db26 Merge pull request #585 from docker/dependabot/npm_and_yarn/js-yaml-5.2.1
  • f779368 [dependabot skip] chore: update generated content
  • 7d5e604 build(deps): bump js-yaml from 5.2.0 to 5.3.0
  • 292c2fb Merge pull request #590 from docker/dependabot/github_actions/actions/setup-n...
  • Additional commits viewable in compare view

Updates docker/login-action from 2 to 4

Release notes

Sourced from docker/login-action's releases.

v4.0.0

Full Changelog: docker/login-action@v3.7.0...v4.0.0

v3.7.0

Full Changelog: docker/login-action@v3.6.0...v3.7.0

v3.6.0

Full Changelog: docker/login-action@v3.5.0...v3.6.0

v3.5.0

Full Changelog: docker/login-action@v3.4.0...v3.5.0

v3.4.0

Full Changelog: docker/login-action@v3.3.0...v3.4.0

... (truncated)

Commits
  • dbcb813 Merge pull request #1051 from docker/dependabot/npm_and_yarn/aws-sdk-dependen...
  • 5bcb015 [dependabot skip] chore: update generated content
  • b30b2f2 build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...
  • 9087f1e Merge pull request #1057 from docker/dependabot/npm_and_yarn/js-yaml-5.2.2
  • 0009830 [dependabot skip] chore: update generated content
  • 2325523 build(deps): bump js-yaml from 5.2.1 to 5.2.2
  • 4ec1d4a Merge pull request #1056 from docker/dependabot/npm_and_yarn/postcss-8.5.22
  • 5fc99ba Merge pull request #1053 from docker/dependabot/github_actions/aws-actions/co...
  • e512bd5 Merge pull request #1052 from docker/dependabot/github_actions/codeql-actions...
  • a146c91 Merge pull request #1059 from crazy-max/harden-buildx-scope-paths
  • Additional commits viewable in compare view

Updates docker/metadata-action from 4 to 6

Release notes

Sourced from docker/metadata-action's releases.

v6.0.0

Full Changelog: docker/metadata-action@v5.10.0...v6.0.0

v5.10.0

Full Changelog: docker/metadata-action@v5.9.0...v5.10.0

v5.9.0

Full Changelog: docker/metadata-action@v5.8.0...v5.9.0

v5.8.0

Full Changelog: docker/metadata-action@v5.7.0...v5.8.0

v5.7.0

Full Changelog: docker/metadata-action@v5.6.1...v5.7.0

... (truncated)

Commits
  • dc80280 Merge pull request #696 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • 2b9fe83 [dependabot skip] chore: update generated content
  • 8128ce3 chore(deps): Bump @​docker/actions-toolkit from 0.91.0 to 0.92.0
  • 1d1c895 Merge pull request #695 from docker/dependabot/npm_and_yarn/semver-7.8.5
  • 7f0c2dd Merge pull request #694 from docker/dependabot/npm_and_yarn/sigstore-4.1.1
  • 025f8c5 [dependabot skip] chore: update generated content
  • e98d63c chore(deps): Bump semver from 7.8.1 to 7.8.5
  • 37d9379 chore(deps): Bump sigstore from 4.1.0 to 4.1.1
  • a1b8072 Merge pull request #690 from docker/dependabot/npm_and_yarn/sigstore/core-3.2.1
  • e0e3381 [dependabot skip] chore: update generated content
  • Additional commits viewable in compare view

Updates docker/build-push-action from 3 to 7

Release notes

Sourced from docker/build-push-action's releases.

v7.0.0

Full Changelog: docker/build-push-action@v6.19.2...v7.0.0

v6.19.2

Full Changelog: docker/build-push-action@v6.19.1...v6.19.2

v6.19.1

Full Changelog: docker/build-push-action@v6.19.0...v6.19.1

v6.19.0

Full Changelog: docker/build-push-action@v6.18.0...v6.19.0

v6.18.0

[!NOTE] Build summary is now supported with Docker Build Cloud.

Full Changelog: docker/build-push-action@v6.17.0...v6.18.0

v6.17.0

[!NOTE] Build record is now exported using the buildx history export command instead of the legacy export-build tool.

Full Changelog: docker/build-push-action@v6.16.0...v6.17.0

v6.16.0

... (truncated)

Commits
  • 53b7df9 Merge pull request #1572 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 154298c [dependabot skip] chore: update generated content
  • cb1238b chore(deps): Bump @​docker/actions-toolkit from 0.91.0 to 0.92.0
  • 24f845d Merge pull request #1566 from docker/dependabot/npm_and_yarn/js-yaml-4.2.0
  • 9c69730 [dependabot skip] chore: update generated content
  • bc3a3a5 Merge pull request #1574 from docker/dependabot/github_actions/aws-actions/co...
  • a82c504 chore(deps): Bump js-yaml from 4.1.1 to 4.3.0
  • 0285a75 Merge pull request #1573 from docker/dependabot/github_actions/actions/cache-...
  • c6ad2a3 Merge pull request #1575 from docker/dependabot/github_actions/actions/checko...
  • d37484f Merge pull request #1564 from docker/dependabot/npm_and_yarn/undici-6.27.0
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `3` | `7` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `1` | `4` |
| [docker/login-action](https://github.com/docker/login-action) | `2` | `4` |
| [docker/metadata-action](https://github.com/docker/metadata-action) | `4` | `6` |
| [docker/build-push-action](https://github.com/docker/build-push-action) | `3` | `7` |


Updates `actions/checkout` from 3 to 7
- [Release notes](https://github.com/actions/checkout/releases)
- [Commits](actions/checkout@v3...v7)

Updates `docker/setup-buildx-action` from 1 to 4
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@v1...v4)

Updates `docker/login-action` from 2 to 4
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@v2...v4)

Updates `docker/metadata-action` from 4 to 6
- [Release notes](https://github.com/docker/metadata-action/releases)
- [Commits](docker/metadata-action@v4...v6)

Updates `docker/build-push-action` from 3 to 7
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@v3...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: docker/setup-buildx-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: docker/login-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: docker/metadata-action
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: docker/build-push-action
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 27, 2026
carole-lavillonniere added a commit that referenced this pull request Sep 2, 2026
The rebuild published only IMAGE:$NEW, so latest stayed on 2026.8.0 while the
fix shipped as 2026.9.0. Normally the v* git tag reaches build-push-docker.yml,
whose metadata-action mints $NEW, v$NEW, sha-* and moves latest (latest=auto) --
but the bot pushes that tag with GITHUB_TOKEN, which does not trigger workflows.
The secops scanner and `docker extension install` both read latest, so it refiled
CVE-2026-14456 (BEE-1172, BEE-1173) against the image we had already fixed.

Mint the same tag set here instead. type=sha is left out: the candidate is built
from the commit before the version bump, so sha-* would point at the wrong tree.

Also SHA-pin build-push-docker.yml's five actions, at the versions Dependabot
proposes in #100 -- that file has always used floating tags, and it is the one
holding the Docker Hub credentials. Both tags already ship provenance
attestations, so the major bumps do not change the published index shape.
carole-lavillonniere added a commit that referenced this pull request Sep 2, 2026
Yesterday's rebuild cleared CVE-2026-14456 and published 2026.9.0, and the scan
refiled that same CVE this morning (BEE-1172, BEE-1173). It never looked at the
rebuilt image: secops resolves this product from our last two GitHub *releases*
(localstack/secops, localstack_products.json: type=github,
github_releases_fetch_limit=2), looking each release's tag_name up verbatim on
Docker Hub. We pushed a bare git tag and no release, so the scan window stayed on
v2026.8.0 -- and Docker Hub had no v2026.9.0 tag for it to resolve either, since
the publish step minted only the bare version.

So: publish v${NEW} alongside ${NEW}, and cut the release. Also move latest, which
nothing in the scan reads but `docker pull` and the marketplace do -- it still
points at the superseded 2026.8.0. type=sha stays dropped: the candidate is built
from the commit before the version bump.

This does not stop a *new* Alpine CVE being ticketed. localstack_products.json
still has docker-desktop as rebuild_model=on-release, so classify_findings.py
rule 3 tickets OS-layer findings instead of leaving them to the rebuild; that
entry wants flipping to scheduled now that this workflow exists.

Also SHA-pin build-push-docker.yml's five actions, at the versions Dependabot
proposes in #100 -- that file has always used floating tags, and it is the one
holding the Docker Hub credentials. Both tags already ship provenance
attestations, so the major bumps do not change the published index shape.
carole-lavillonniere added a commit that referenced this pull request Sep 2, 2026
Yesterday's rebuild cleared CVE-2026-14456 and published 2026.9.0, and the scan
refiled that same CVE this morning (BEE-1172, BEE-1173). It never looked at the
rebuilt image: secops resolves this product from our last two GitHub *releases*
(localstack/secops, localstack_products.json: type=github,
github_releases_fetch_limit=2), looking each release's tag_name up verbatim on
Docker Hub. We pushed a bare git tag and no release, so the scan window stayed on
v2026.8.0 -- and Docker Hub had no v2026.9.0 tag for it to resolve either, since
the publish step minted only the bare version.

So: publish v${NEW} alongside ${NEW}, and cut the release. Also move latest, which
nothing in the scan reads but `docker pull` and the marketplace do -- it still
points at the superseded 2026.8.0. type=sha stays dropped: the candidate is built
from the commit before the version bump.

This does not stop a *new* Alpine CVE being ticketed. localstack_products.json
still has docker-desktop as rebuild_model=on-release, so classify_findings.py
rule 3 tickets OS-layer findings instead of leaving them to the rebuild; that
entry wants flipping to scheduled now that this workflow exists.

Also SHA-pin build-push-docker.yml's five actions, at the versions Dependabot
proposes in #100 -- that file has always used floating tags, and it is the one
holding the Docker Hub credentials. Both tags already ship provenance
attestations, so the major bumps do not change the published index shape.
@carole-lavillonniere
carole-lavillonniere merged commit ca04c9c into main Sep 2, 2026
1 check passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/actions-4ef91543cb branch September 2, 2026 08:33
carole-lavillonniere added a commit that referenced this pull request Sep 2, 2026
The repo has no CODEOWNERS in any of the three locations GitHub reads, and
nothing in dependabot.yml fills in for it (`reviewers` is gone from Dependabot's
options reference; we set no `assignees`). So Dependabot PRs open with no
reviewer and no assignee -- #100 has been sitting that way -- and every other PR
depends on someone noticing it.

@localstack/saas matches where secops already routes this image's CVE findings
(localstack_products.json, team: SaaS), and the one collaborator with push access
who has been reviewing here is in that team.

Same single-glob pattern as secops' CODEOWNERS, which is what auto-requests
core-systems on its Dependabot PRs (e.g. localstack/secops#110), so this is
proven to work for bot PRs in this org.

Note it only auto-requests: main has no branch protection or rulesets, so
nothing blocks a merge without review. Enforcing that needs a ruleset with
"Require review from Code Owners".
carole-lavillonniere added a commit that referenced this pull request Sep 3, 2026
…101)

Yesterday's rebuild cleared CVE-2026-14456 and published 2026.9.0, and the scan
refiled that same CVE this morning (BEE-1172, BEE-1173). It never looked at the
rebuilt image: secops resolves this product from our last two GitHub *releases*
(localstack/secops, localstack_products.json: type=github,
github_releases_fetch_limit=2), looking each release's tag_name up verbatim on
Docker Hub. We pushed a bare git tag and no release, so the scan window stayed on
v2026.8.0 -- and Docker Hub had no v2026.9.0 tag for it to resolve either, since
the publish step minted only the bare version.

So: publish v${NEW} alongside ${NEW}, and cut the release. Also move latest, which
nothing in the scan reads but `docker pull` and the marketplace do -- it still
points at the superseded 2026.8.0. type=sha stays dropped: the candidate is built
from the commit before the version bump.

This does not stop a *new* Alpine CVE being ticketed. localstack_products.json
still has docker-desktop as rebuild_model=on-release, so classify_findings.py
rule 3 tickets OS-layer findings instead of leaving them to the rebuild; that
entry wants flipping to scheduled now that this workflow exists.

Also SHA-pin build-push-docker.yml's five actions, at the versions Dependabot
proposes in #100 -- that file has always used floating tags, and it is the one
holding the Docker Hub credentials. Both tags already ship provenance
attestations, so the major bumps do not change the published index shape.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant