github-actions: bump docker/login-action from 3 to 4#578
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
@dependabot rebase |
Bumps [docker/login-action](https://github.com/docker/login-action) from 3 to 4. - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@v3...v4) --- updated-dependencies: - dependency-name: docker/login-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
be9f169 to
dc44d2a
Compare
bgentry
left a comment
There was a problem hiding this comment.
🤖 Codex review: Security review looks good to me.
I reviewed this as a dependency-upgrade supply-chain/security pass for the docker/login-action update from v3 to v4 at PR head dc44d2a34a0b63ff8aad0a615e1351ae0e1d7722.
Scope reviewed:
- Confirmed the rebased PR only updates
docker/login-actionreferences in Docker workflows. - Compared upstream action metadata and source for the current
v4line, including the Node 24 runtime move and the switch todist/index.cjs. - Reviewed credential-sensitive behavior: the action still consumes the configured registry username/password or
registry-authinput and passes passwords todocker login --password-stdin, with post-job logout behavior unchanged at the workflow interface. - Checked for unexpected broad env harvesting, new credential sources, dynamic code execution, new install hooks, or unrelated network behavior. The sensitive behavior remains the expected Docker/ECR login path.
Local validation completed on the rebased head:
npm run lintnpm run test:oncenpm run buildmake lintmake test
No blocking findings. Residual risk is that these workflow steps intentionally pass registry credentials (GITHUB_TOKEN for GHCR and the River Pro registry credential for riverqueue.com) to the action, and the workflow still trusts a moving major-version action reference rather than a pinned commit SHA.
Bumps docker/login-action from 3 to 4.
Release notes
Sourced from docker/login-action's releases.
... (truncated)
Commits
650006cMerge pull request #960 from docker/dependabot/npm_and_yarn/aws-sdk-dependenc...99df1a3chore: update generated content3ab375fbuild(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...39d8580Merge pull request #970 from docker/dependabot/npm_and_yarn/docker/actions-to...4eefcd3chore: update generated content56d092cbuild(deps): bump@docker/actions-toolkitfrom 0.86.0 to 0.90.0e2e31caMerge pull request #976 from docker/dependabot/npm_and_yarn/actions/core-3.0.10bced94chore: update generated content3e75a0fbuild(deps): bump@actions/corefrom 3.0.0 to 3.0.1365bebdMerge pull request #984 from docker/dependabot/github_actions/aws-actions/con...