Skip to content

chore(ci): bump docker/setup-qemu-action from 4.2.0 to 4.3.0 in the docker-actions group across 1 directory - #884

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/docker-actions-9a35141b6c
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/docker-actions-9a35141b6c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the docker-actions group with 1 update in the / directory: docker/setup-qemu-action.

Updates docker/setup-qemu-action from 4.2.0 to 4.3.0

Release notes

Sourced from docker/setup-qemu-action's releases.

v4.3.0

Full Changelog: docker/setup-qemu-action@v4.2.0...v4.3.0

Commits
  • 1f40c72 Merge pull request #336 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • 932216e [dependabot skip] chore: update generated content
  • a39e895 build(deps): bump @​docker/actions-toolkit from 0.92.0 to 0.96.0
  • a98ae9f Merge pull request #333 from docker/dependabot/npm_and_yarn/undici-6.28.0
  • 8ebc9d1 [dependabot skip] chore: update generated content
  • c41e3fc build(deps): bump undici from 6.27.0 to 6.28.0
  • 5fc60df Merge pull request #332 from docker/dependabot/npm_and_yarn/brace-expansion-1...
  • a26e892 Merge pull request #328 from docker/dependabot/github_actions/actions/checkou...
  • aa6d042 Merge pull request #324 from docker/dependabot/github_actions/actions/setup-n...
  • d381ce5 Merge pull request #317 from docker/dependabot/npm_and_yarn/sigstore-4.1.1
  • Additional commits viewable in compare view

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 14, 2026
@github-actions

github-actions Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Benchmark delta (vs main)

Soft regression feedback only — this comment never blocks the PR.
Latency budget: ⚠️ when head > base × 1.3. Accuracy budget: ⚠️ when head < base - 1pp.

Routing summary (single backend × catalog sizes)

size recall@k (head Δ vs base) MRR (head Δ vs base) p99 (ms)
50 ✅ 0.5649 (+0.0000) ✅ 0.4978 (+0.0000) ⚠️ 0.941 (base 0.650)
83 ✅ 0.3825 (+0.0000) ✅ 0.3242 (+0.0000) ✅ 1.327 (base 1.205)
1000 ✅ 0.1475 (+0.0000) ✅ 0.1456 (+0.0000) ✅ 35.926 (base 47.855)

Per-backend × per-size matrix

backend size recall@k (Δ) MRR (Δ) p99 (ms)
bm25 100 ✅ 0.3825 (+0.0000) ✅ 0.3399 (+0.0000) ✅ 6.448 (base 8.399)
bm25 500 ✅ 0.2250 (+0.0000) ✅ 0.2165 (+0.0000) ✅ 31.889 (base 41.865)
bm25 1000 ✅ 0.1575 (+0.0000) ✅ 0.1525 (+0.0000) ✅ 87.363 (base 112.387)
embedding_hashing 100 ✅ 0.5175 (+0.0000) ✅ 0.4360 (+0.0000) ✅ 8.116 (base 7.218)
embedding_hashing 500 ✅ 0.2700 (+0.0000) ✅ 0.2674 (+0.0000) ✅ 41.373 (base 43.171)
embedding_hashing 1000 ✅ 0.2000 (+0.0000) ✅ 0.1931 (+0.0000) ✅ 97.951 (base 102.979)
embedding_st 100 skipped (skipped: missing sentence-transformers) — —
embedding_st 500 skipped (skipped: missing sentence-transformers) — —
embedding_st 1000 skipped (skipped: missing sentence-transformers) — —
fuzzy 100 skipped (skipped: missing rapidfuzz) — —
fuzzy 500 skipped (skipped: missing rapidfuzz) — —
fuzzy 1000 skipped (skipped: missing rapidfuzz) — —
tfidf 100 ✅ 0.3825 (+0.0000) ✅ 0.3220 (+0.0000) ✅ 1.008 (base 1.193)
tfidf 500 ✅ 0.2325 (+0.0000) ✅ 0.2314 (+0.0000) ✅ 9.070 (base 10.803)
tfidf 1000 ✅ 0.1475 (+0.0000) ✅ 0.1456 (+0.0000) ✅ 35.868 (base 42.986)

Context pipeline (per scenario)

scenario tokens dropped dedup
large_catalog 1480 (base 1480, Δ+0) 0 (base 0, Δ+0) 0 (base 0, Δ+0)
long_conversation 2500 (base 2500, Δ+0) 0 (base 0, Δ+0) 0 (base 0, Δ+0)
mixed_payload 488 (base 488, Δ+0) 0 (base 0, Δ+0) 0 (base 0, Δ+0)
short_conversation 487 (base 487, Δ+0) 0 (base 0, Δ+0) 0 (base 0, Δ+0)
stress_conversation 6590 (base 6590, Δ+0) 11 (base 11, Δ+0) 4 (base 4, Δ+0)
tiny_payload 256 (base 256, Δ+0) 0 (base 0, Δ+0) 0 (base 0, Δ+0)

Numbers come from make benchmark / make benchmark-matrix.
Latency is hardware-dependent — treat the markers as a rough guide.
See benchmarks/scorecard.md for the full picture.

dgenio commented Sep 17, 2026

Copy link
Copy Markdown
Owner

Review — docker/setup-qemu-action 4.2.0 → 4.3.0

Verdict: safe to merge. One line, one workflow, no major crossing.

What the diff actually is

Judged from get_files, not the title:

.github/workflows/docker-publish.yml  (+1/-1)
- uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4
+ uses: docker/setup-qemu-action@1f40c72289eff860ee54a304f1438e3cff362e0a # v4

SHA-pinned on both sides with the version comment retained — the supply-chain hygiene this repo uses is preserved, and the # v4 comment stays accurate (4.2.0 → 4.3.0 is within the major, so no comment drift).

The check dependabot does not do: is the bump complete?

A partial pin bump leaves two versions of the same action live in one repository. Grepped main for the outgoing SHA across all of .github/:

$ git grep -n 96fe6ef7f33517b61c61be40b68a1882f3264fb8 origin/main -- .github/
origin/main  uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4

One site, and it is the one this PR changes. confirmed — nothing is left behind.

Scope

arm64 emulation setup for the multi-arch docker build. If 4.3.0 regressed QEMU registration the failure surfaces in docker-publish.yml, which is release-path rather than PR-path — worth knowing, though the action is a thin wrapper around binfmt registration and the release workflow would fail loudly rather than silently.

Status

16/16 checks green (including Floor deps (lowest-direct, 3.10), Windows (3.12) and the benchmark gate).

Not verified

I did not confirm 1f40c722… is the genuine tag commit for docker/setup-qemu-action@v4.3.0 — that repository is outside this session's GitHub scope, so I cannot read its tags. unverified, and stated rather than glossed: the SHA's provenance rests on Dependabot here, not on my own check.

Dependabot PR, so REVIEW only — not merging it.


Generated by Claude Code

dgenio commented Sep 20, 2026

Copy link
Copy Markdown
Owner

Review — approve, but nothing in CI has run this change

Verdict: safe to merge. One SHA-pinned minor bump, comment still accurate. The caveat is stronger than on #885: none of this PR's green checks exercised the line it changes.

The bump, verified against upstream tags

Action From To
docker/setup-qemu-action 96fe6ef = v4.2.0 1f40c72 = v4.3.0

Confirmed with git ls-remote --tags rather than reading the # v4 comment. Minor bump inside v4, so the comment stays truthful. One file, one line.

What the green board does not cover

docker-publish.yml triggers on:

on:
  release:
    types: [published]
  workflow_dispatch: {}

No pull_request, no push. So every check on this PR ran other workflows, and the modified step — Set up QEMU (arm64 emulation) — has not executed once with the new sha. It first runs when a release is published, which is the worst moment to discover an arm64 emulation setup problem, because the failure lands in a release build rather than in a PR.

The risk is genuinely low: patch/minor bumps of docker/setup-qemu-action are routine, and the neighbouring setup-buildx-action pin is untouched so there is no version-skew between the two. But "CI is green" is not the reason to believe it here — the reason is the upstream tag and the size of the change.

workflow_dispatch: {} is present, so this is cheap to actually verify: dispatch docker-publish.yml on this branch once and confirm the QEMU step still sets up arm64. That converts the only real unknown into an observation. Worth doing before the next release rather than after.

Related

#885 has the same shape on docs.yml and ossf-scorecard.yml — reviewed there. Between the two PRs, five of six changed uses: lines sit in workflows that never run on a pull request. That is a property of how these workflows are triggered, not a defect in either PR, but it does mean Dependabot's action bumps in this repo are largely unvalidated until after merge.

No blocking findings. Not merging — Dependabot PRs get reviewed here, not merged.


Generated by Claude Code

Bumps the docker-actions group with 1 update in the / directory: [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action).


Updates `docker/setup-qemu-action` from 4.2.0 to 4.3.0
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](docker/setup-qemu-action@96fe6ef...1f40c72)

---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: docker-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(ci): bump docker/setup-qemu-action from 4.2.0 to 4.3.0 in the docker-actions group chore(ci): bump docker/setup-qemu-action from 4.2.0 to 4.3.0 in the docker-actions group across 1 directory Sep 21, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/docker-actions-9a35141b6c branch from 507d023 to 2829e49 Compare September 21, 2026 06:15

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant