Skip to content

build(deps): Bump docker/login-action from 4.5.2 to 4.6.0 - #1407

Merged
lklimek merged 1 commit into
v1.7-devfrom
dependabot/github_actions/docker/login-action-4.6.0
Aug 25, 2026
Merged

lklimek merged 1 commit into
v1.7-devfrom
dependabot/github_actions/docker/login-action-4.6.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 4, 2026

Copy link
Copy Markdown
Contributor

Bumps docker/login-action from 4.5.2 to 4.6.0.

Release notes

Sourced from docker/login-action's releases.

v4.6.0

Full Changelog: docker/login-action@v4.5.2...v4.6.0

Commits
  • dbcb813 Merge pull request #1051 from docker/dependabot/npm_and_yarn/aws-sdk-dependen...
  • 5bcb015 [dependabot skip] chore: update generated content
  • b30b2f2 build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...
  • 9087f1e Merge pull request #1057 from docker/dependabot/npm_and_yarn/js-yaml-5.2.2
  • 0009830 [dependabot skip] chore: update generated content
  • 2325523 build(deps): bump js-yaml from 5.2.1 to 5.2.2
  • 4ec1d4a Merge pull request #1056 from docker/dependabot/npm_and_yarn/postcss-8.5.22
  • 5fc99ba Merge pull request #1053 from docker/dependabot/github_actions/aws-actions/co...
  • e512bd5 Merge pull request #1052 from docker/dependabot/github_actions/codeql-actions...
  • a146c91 Merge pull request #1059 from crazy-max/harden-buildx-scope-paths
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [docker/login-action](https://github.com/docker/login-action) from 4.5.2 to 4.6.0.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@v4.5.2...v4.6.0)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 4.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code labels Aug 4, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code labels Aug 4, 2026
@dependabot
dependabot Bot changed the base branch from v1.6-dev to v1.7-dev August 25, 2026 08:36
@Claudius-Maginificent

Copy link
Copy Markdown
Collaborator

Dependency Audit — docker/login-action 4.5.2 → 4.6.0

Verdict: Safe — merging. Right-o, I went and poked this one properly instead of rubber-stamping it, and it came back clean as a whistle.

Change Summary

Package docker/login-action (GitHub Actions)
Versions v4.5.2 (371161bb) → v4.6.0 (dbcb8138)
Upstream delta 15 commits, 9 files
Nature 1 security hardening + 3 dependency bumps (2 npm, 1 action) + regenerated dist/
Our diff 1 line, .github/workflows/docker.yml:43

Diff Integrity (step 2d)

Clean. Every commit is accounted for by the published release notes:

  • Tag integrity — both tags are lightweight refs to commits on origin/master; v4.6.0 and the floating v4 resolve to the same commit dbcb8138; release object targets master, not a draft, published by crazy-max (long-standing maintainer). No moved/orphan tag.
  • Undocumented content — none. 4 substantive changes, 4 matching release-note entries; the remainder are merge commits and [dependabot skip] chore: update generated content bot commits.
  • Lifecycle/install hooks — none added or modified.
  • Network/exfiltration — every new URL string in the dist/index.cjs diff traces to the AWS SDK ECR clients or @actions/toolkit (api.ecr.*, 169.254.169.254 IMDS, api.github.com). No novel domains, no new credential/env reads.
  • Obfuscation — none. dist/ is bundled build output, as it was before; it regenerates consistently with source (the new guard's error string is present in the bundle).
  • Diff shape — proportionate. The 119/-119 dist churn is the aws-sdk minor bump, exactly what you'd expect.

The one real source change

src/context.ts → scopeToConfigDir() (docker/login-action#1059, "harden buildx scoped config path handling") is a path-traversal fix (CWE-22), and a decent one: it swaps path.join for path.resolve + an explicit isChildPath() containment check on both the registry dir and the scope dir, caps the scope at one @ separator, and validates scope actions against /^[a-z]+(,[a-z]+)*$/. Covered by 81 new lines of tests. This bump makes us strictly better off, not worse.

Known Vulnerabilities

Source Result
OSV.dev (docker/login-action, all + v4.6.0) None
GitHub Advisory DB (ecosystem=actions) None
js-yaml 5.2.2 (runtime dep) None
postcss 8.5.22 GHSA-fxqj-rqcc-2cmp — not applicable, see below

INFO — postcss is a transitive dev-only dependency (vitest/esbuild toolchain); grep postcss dist/index.cjs = 0, so it is not bundled into the artifact we consume. The advisory (CVSS 4.0 low, attacker-controlled sourceMappingURL reading local .map files, fixed in 8.5.23) affects upstream's build box at most, never a login-action consumer.

Codebase Compliance

Check Status
Hardened scope code path reachable from our usage? No — we pass only username/password; scope unset, so scopeToConfigDir() short-circuits
Secret exposure to fork PRs Safe — workflow triggers are workflow_dispatch + release: published, and the step is additionally gated on github.event_name != 'pull_request'
Credentials source secrets.DOCKERHUB_USERNAME / DOCKERHUB_TOKEN — trusted, not interpolated into run: shell
Behavioural change for us None. Pure no-op upgrade that banks a security fix for free

Pre-existing observations (NOT introduced here, NOT blocking)

  1. LOW — .github/workflows/docker.yml:33: docker/setup-qemu-action@master pins a floating branch ref. Whatever lands on that branch runs with our workflow's trust; that's the genuinely soft spot in this file, not the thing Dependabot just bumped. Worth pinning to a tag or SHA in a follow-up.
  2. INFO — Actions across this repo are tag-pinned rather than SHA-pinned (CWE-1357, mutable third-party reference). Defensible convention given Dependabot keeps them current; noted for completeness, no action requested in this PR.

Risk Assessment

Overall: Safe. Diff integrity clean, no applicable advisories, the only source change is a hardening, the changed code path isn't even reachable from our configuration, and CI is green. Nothing here floors the rating.

Recommendations

  1. Merge this PR. (Doing so now.)
  2. Follow-up, separate PR: pin docker/setup-qemu-action@master to a released tag.

🤖 Co-authored by Claudius the Magnificent AI Agent

@lklimek
lklimek merged commit 908e396 into v1.7-dev Aug 25, 2026
17 checks passed
@lklimek
lklimek deleted the dependabot/github_actions/docker/login-action-4.6.0 branch August 25, 2026 08:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants