github-actions: bump docker/build-push-action from 6 to 7 - #638
Conversation
Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 6 to 7. - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@v6...v7) --- updated-dependencies: - dependency-name: docker/build-push-action dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
bgentry
left a comment
There was a problem hiding this comment.
Security gate: clear. Compatibility gate: clear with a required-check gap.
Reviewed head b025ac0fef55fdc95df2dfd09a22d39f55736fb1.
docker/build-push-action@v7 currently resolves to the valid-signed upstream
v7.3.0 commit 53b7df96c91f9c12dcc8a07bcb9ccacbed38856a.
The Node 24/ESM migration, toolkit upgrade, and build-history changes are
coherent with upstream source. Exact npm tarballs matched registry integrity,
and the high-risk Docker toolkit release has npm provenance plus a verified
signed upstream tag. I found no unexpected secret, credential, network,
filesystem, process, or native-code behavior reachable from these workflows.
The exact action commit ran successfully for both public image architectures
and the manifest job. The Pro job fails before this action, when Dependabot
cannot assume the AWS role with OIDC, so its ECR cache, private BuildKit
secret, record upload, and manifest path remain unexercised on this head.
That is a repository required-check gap rather than evidence of a v7 failure.
Residual risk includes the mutable major tag, a non-reproduced committed
bundle, and advisory-affected js-yaml/brace-expansion copies whose
vulnerable operations are not attacker-controlled in River's action paths.
The Pro workflow should be run from a trusted context before merge, and the
major tag should be replaced with the reviewed full SHA in a follow-up.
Bumps docker/build-push-action from 6 to 7.
Release notes
Sourced from docker/build-push-action's releases.
... (truncated)
Commits
53b7df9Merge pull request #1572 from docker/dependabot/npm_and_yarn/docker/actions-t...154298c[dependabot skip] chore: update generated contentcb1238bchore(deps): Bump@docker/actions-toolkitfrom 0.91.0 to 0.92.024f845dMerge pull request #1566 from docker/dependabot/npm_and_yarn/js-yaml-4.2.09c69730[dependabot skip] chore: update generated contentbc3a3a5Merge pull request #1574 from docker/dependabot/github_actions/aws-actions/co...a82c504chore(deps): Bump js-yaml from 4.1.1 to 4.3.00285a75Merge pull request #1573 from docker/dependabot/github_actions/actions/cache-...c6ad2a3Merge pull request #1575 from docker/dependabot/github_actions/actions/checko...d37484fMerge pull request #1564 from docker/dependabot/npm_and_yarn/undici-6.27.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)