build(deps): Bump docker/login-action from 4.5.2 to 4.6.0 - #1407
Conversation
Bumps [docker/login-action](https://github.com/docker/login-action) from 4.5.2 to 4.6.0. - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@v4.5.2...v4.6.0) --- updated-dependencies: - dependency-name: docker/login-action dependency-version: 4.6.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
Dependency Audit —
|
| Package | docker/login-action (GitHub Actions) |
| Versions | v4.5.2 (371161bb) → v4.6.0 (dbcb8138) |
| Upstream delta | 15 commits, 9 files |
| Nature | 1 security hardening + 3 dependency bumps (2 npm, 1 action) + regenerated dist/ |
| Our diff | 1 line, .github/workflows/docker.yml:43 |
Diff Integrity (step 2d)
Clean. Every commit is accounted for by the published release notes:
- Tag integrity — both tags are lightweight refs to commits on
origin/master;v4.6.0and the floatingv4resolve to the same commitdbcb8138; release object targetsmaster, not a draft, published bycrazy-max(long-standing maintainer). No moved/orphan tag. - Undocumented content — none. 4 substantive changes, 4 matching release-note entries; the remainder are merge commits and
[dependabot skip] chore: update generated contentbot commits. - Lifecycle/install hooks — none added or modified.
- Network/exfiltration — every new URL string in the
dist/index.cjsdiff traces to the AWS SDK ECR clients or@actions/toolkit(api.ecr.*,169.254.169.254IMDS,api.github.com). No novel domains, no new credential/env reads. - Obfuscation — none.
dist/is bundled build output, as it was before; it regenerates consistently with source (the new guard's error string is present in the bundle). - Diff shape — proportionate. The 119/-119
distchurn is the aws-sdk minor bump, exactly what you'd expect.
The one real source change
src/context.ts → scopeToConfigDir() (docker/login-action#1059, "harden buildx scoped config path handling") is a path-traversal fix (CWE-22), and a decent one: it swaps path.join for path.resolve + an explicit isChildPath() containment check on both the registry dir and the scope dir, caps the scope at one @ separator, and validates scope actions against /^[a-z]+(,[a-z]+)*$/. Covered by 81 new lines of tests. This bump makes us strictly better off, not worse.
Known Vulnerabilities
| Source | Result |
|---|---|
OSV.dev (docker/login-action, all + v4.6.0) |
None |
GitHub Advisory DB (ecosystem=actions) |
None |
js-yaml 5.2.2 (runtime dep) |
None |
postcss 8.5.22 |
GHSA-fxqj-rqcc-2cmp — not applicable, see below |
INFO — postcss is a transitive dev-only dependency (vitest/esbuild toolchain); grep postcss dist/index.cjs = 0, so it is not bundled into the artifact we consume. The advisory (CVSS 4.0 low, attacker-controlled sourceMappingURL reading local .map files, fixed in 8.5.23) affects upstream's build box at most, never a login-action consumer.
Codebase Compliance
| Check | Status |
|---|---|
Hardened scope code path reachable from our usage? |
No — we pass only username/password; scope unset, so scopeToConfigDir() short-circuits |
| Secret exposure to fork PRs | Safe — workflow triggers are workflow_dispatch + release: published, and the step is additionally gated on github.event_name != 'pull_request' |
| Credentials source | secrets.DOCKERHUB_USERNAME / DOCKERHUB_TOKEN — trusted, not interpolated into run: shell |
| Behavioural change for us | None. Pure no-op upgrade that banks a security fix for free |
Pre-existing observations (NOT introduced here, NOT blocking)
- LOW —
.github/workflows/docker.yml:33:docker/setup-qemu-action@masterpins a floating branch ref. Whatever lands on that branch runs with our workflow's trust; that's the genuinely soft spot in this file, not the thing Dependabot just bumped. Worth pinning to a tag or SHA in a follow-up. - INFO — Actions across this repo are tag-pinned rather than SHA-pinned (CWE-1357, mutable third-party reference). Defensible convention given Dependabot keeps them current; noted for completeness, no action requested in this PR.
Risk Assessment
Overall: Safe. Diff integrity clean, no applicable advisories, the only source change is a hardening, the changed code path isn't even reachable from our configuration, and CI is green. Nothing here floors the rating.
Recommendations
- Merge this PR. (Doing so now.)
- Follow-up, separate PR: pin
docker/setup-qemu-action@masterto a released tag.
🤖 Co-authored by Claudius the Magnificent AI Agent
Bumps docker/login-action from 4.5.2 to 4.6.0.
Release notes
Sourced from docker/login-action's releases.
Commits
dbcb813Merge pull request #1051 from docker/dependabot/npm_and_yarn/aws-sdk-dependen...5bcb015[dependabot skip] chore: update generated contentb30b2f2build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...9087f1eMerge pull request #1057 from docker/dependabot/npm_and_yarn/js-yaml-5.2.20009830[dependabot skip] chore: update generated content2325523build(deps): bump js-yaml from 5.2.1 to 5.2.24ec1d4aMerge pull request #1056 from docker/dependabot/npm_and_yarn/postcss-8.5.225fc99baMerge pull request #1053 from docker/dependabot/github_actions/aws-actions/co...e512bd5Merge pull request #1052 from docker/dependabot/github_actions/codeql-actions...a146c91Merge pull request #1059 from crazy-max/harden-buildx-scope-pathsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)