Skip to content

Bump docker/setup-buildx-action to v4 and docker/build-push-action to v7 - #24

Merged
dmccoystephenson merged 1 commit into
mainfrom
feature/bump-docker-action-pins
Sep 19, 2026
Merged

dmccoystephenson merged 1 commit into
mainfrom
feature/bump-docker-action-pins

Conversation

@dmccoystephenson

Copy link
Copy Markdown
Member

Summary

  • docker/setup-buildx-action is bumped from v3 to v4 and docker/build-push-action from v5 to v7 in the docker-build job of .github/workflows/build.yml. After PR Bump deprecated CI action pins and drop phantom develop branch references #19, these were the only two actions in the workflow still declared on the deprecated Node.js 20 runtime; the runner currently forces them onto Node.js 24 as a transitional measure, so the job is green today but would go red once that measure is withdrawn.
  • CHANGELOG.md's [Unreleased] section records the change.

No application code is changed by this pull request; the entire diff is two CI pin lines and one changelog line.

Verification of the new pins

Issue #20 asked that the current major of each action be confirmed against upstream before the pins are moved. Since the GitHub releases API was not reachable from this session, the confirmation was done by fetching the tags themselves and reading each action.yml:

  • git ls-remote --tags on both repositories shows v4 (v4.4.1) as the highest major of docker/setup-buildx-action and v7 (v7.4.0) as the highest major of docker/build-push-action.
  • docker/build-push-action: the action.yml diff from the pinned v5 to v7 is one added optional input (call) and the runs block moving from node20/dist/index.js to node24/dist/index.cjs. Every input build.yml passes — context, push, tags, cache-from, cache-to — is present and unchanged. The v6 tag is still node20, which is why v6 was not chosen.
  • docker/setup-buildx-action: the action.yml diff from the pinned v3 to v4 removes the long-deprecated config, config-inline and install inputs and moves runs to node24. build.yml passes no inputs to this action, so none of the removals apply.

CI on this pull request is the anchor for the rest: an unresolvable action reference fails its job immediately, so a green docker-build job confirms both tags resolve and the image still builds. The remaining Node.js 20 deprecation annotation on the docker-build job is expected to disappear with this change; that can be checked on the run for this PR's head against the docker-build: docker/build-push-action@v5, docker/setup-buildx-action@v3 annotation quoted in #20.

Test plan

  • mvn test — 84 tests executed, 0 failures, 0 errors, 1 skipped (pre-existing), BUILD SUCCESS. No Java is changed, so this only confirms the tree is unaffected.
  • The docker-build job passes on this pull request, confirming docker/setup-buildx-action@v4 and docker/build-push-action@v7 resolve and the image builds with the GHA cache configuration unchanged
  • The build job passes (unchanged by this PR)
  • No Node.js 20 deprecation annotation remains on the run

Merge handling

This pull request modifies .github/workflows/*, which is on this loop's do-not-auto-merge list because CI configuration changes affect the review and automation gates that everything else is verified against. It is therefore left open for maintainer review rather than merged autonomously, even though merging was pre-authorized for this session in general.

Issues not selected this cycle

Also observed, not fixed here

The remote branch feature/docs-accuracy-sweep, noted in PR #19 as left over from PR #10, was not checked or deleted this cycle either.

Closes #20

This PR description was drafted during a Gardener session (https://github.com/Stephenson-Software/gardener).


drafted by Claude on behalf of Daniel Stephenson

The docker-build job's two docker/* pins were the last actions in
build.yml still declared on the deprecated Node.js 20 runtime; the
runner forces them onto Node.js 24 as a transitional measure, so the
job is green today but would go red once that measure is withdrawn.
Each tag was fetched and its action.yml compared against the pinned
one: both new majors switch to node24 and the only interface change
is setup-buildx-action@v4 dropping the long-deprecated config,
config-inline and install inputs, none of which build.yml uses. The
build-push-action inputs build.yml does use (context, push, tags,
cache-from, cache-to) are unchanged.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@dmccoystephenson

Copy link
Copy Markdown
Member Author

Self-review rubric (run 35429038176 on the PR head):

  • Scope: PASS — only .github/workflows/build.yml (two pin lines) and CHANGELOG.md (one line) are modified; git diff --name-only origin/main...HEAD lists nothing else.
  • Tests-new: no signal — no new public method or function; no Java is touched.
  • Tests-fix: no signal — not a bug fix; nothing to stash-and-run. The behavioral check is the CI annotation comparison below.
  • Sibling structure: PASS — the changelog line sits under [Unreleased] › Changed directly after the sibling entry for the actions/* bump from PR Bump deprecated CI action pins and drop phantom develop branch references #19 and follows the same shape.
  • Sibling renames: no signal — nothing renamed.
  • Docs: PASS — README.md, COMMANDS.md, CONFIG.md and USER_GUIDE.md were grepped for build-push, buildx, setup-java and actions/checkout; the only reference anywhere in the Markdown is the CHANGELOG.md entry, which is updated.
  • Issue resolution: PASS — CI still pins deprecated docker/build-push-action@v5 and docker/setup-buildx-action@v3 #20 names exactly the two pins at build.yml lines 39 and 42 and asks that the current major of each be confirmed upstream before bumping; both were confirmed by fetching the tags and diffing action.yml (details in the PR body), and both are bumped.
  • CI: PASS — build and docker-build both green on the PR head. The annotation on the latest main run (35054115817) reads Node.js 20 is deprecated … docker/build-push-action@v5, docker/setup-buildx-action@v3; on this PR's run that annotation is absent, which is the outcome CI still pins deprecated docker/build-push-action@v5 and docker/setup-buildx-action@v3 #20 asked for.
  • Config-doc parity: no signal — no properties or @Value fields changed.
  • Command-doc parity: no signal — no CLI flag, system property or endpoint changed.
  • Package placement: no signal — no Java changed.
  • No credential leakage: PASS — no logging, printing or output path is touched.

One finding outside the diff, not addressed here: with docker/build-push-action@v7, the run now surfaces a Dockerfile lint annotation that the v5 action did not report — SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ENV "GITHUB_TOKEN") at Dockerfile#25. It is a warning, not a failure, and the ENV GITHUB_TOKEN="" line bakes no secret into the image (it only declares an empty default), so it is pre-existing rather than introduced by this change. GitHubService treats a null and an empty GITHUB_TOKEN identically (token != null && !token.isEmpty()), so the line could be dropped without a behavior change; that is a Dockerfile edit outside #20's scope and is filed as a separate issue.

Summary: two-line CI pin bump with the deprecation annotation confirmed gone; left open for maintainer review because .github/workflows/* is on the do-not-auto-merge list.

This comment was drafted during a Gardener session (https://github.com/Stephenson-Software/gardener).


drafted by Claude on behalf of Daniel Stephenson

@dmccoystephenson
dmccoystephenson merged commit e0449e1 into main Sep 19, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CI still pins deprecated docker/build-push-action@v5 and docker/setup-buildx-action@v3

1 participant