github-actions: bump docker/login-action from 4 to 4.5.2 - #647
Open
dependabot[bot] wants to merge 1 commit into
Open
github-actions: bump docker/login-action from 4 to 4.5.2#647dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Contributor
|
@dependabot rebase |
Bumps [docker/login-action](https://github.com/docker/login-action) from 4 to 4.5.2. - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@v4...v4.5.2) --- updated-dependencies: - dependency-name: docker/login-action dependency-version: 4.5.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/github_actions/docker/login-action-4.5.1
branch
from
August 4, 2026 14:07
a949bd9 to
7418dff
Compare
bgentry
reviewed
Aug 4, 2026
bgentry
left a comment
Contributor
There was a problem hiding this comment.
🤖 Codex review: Blocked because the proposed version is an operational and security downgrade.
Upgrade
docker/login-action: floating v4 → v4.5.2- Reviewed head:
7418dff7db22999d8bf81809eb8a93d5dadced68 - Proposed target:
v4.5.2→371161bbe7024a29a25c5e19bfcbc0804fe9ad2c
Security review
- The repository's existing
@v4now resolves to newer v4.6.0 commitdbcb813823bdd20940b903addbd779551569679f, published before this PR. Merging would therefore downgrade all three call sites. - The v4.5.2 source and bundle were compared and provenance checked. It predates v4.6 path hardening and still bundles vulnerable
js-yaml@5.2.1,undici@6.27.0, andbrace-expansion@1.1.16code. - River does not enable the most directly affected
registry-auth, blob/cookie/retry, or Docker Hub OIDC paths, but the downgrade loses fixes with no compensating benefit for these workflows.
Compatibility verification
- Current-head normal JS, Go, release, and riverui image checks passed. The Pro workflow fails at AWS role assumption before reaching live-registry login, so that credential path is not validated.
Residual risk / blocker
- Leave
@v4unchanged or replace this PR with at least v4.6.0. Prefer a later release that also refreshes Undici and brace-expansion. Do not approve or merge v4.5.2.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps docker/login-action from 4 to 4.5.2.
Release notes
Sourced from docker/login-action's releases.
... (truncated)
Commits
a5e9150Merge pull request #1048 from docker/dockerhub-oidc-supporta482ba4build(deps): bump the codeql-actions group with 2 updates9e3d36echore: update generated content14d6a79docker hub oidc support03c8510Merge pull request #1044 from docker/dependabot/npm_and_yarn/docker/actions-t...ad8a81fMerge pull request #1046 from docker/dependabot/npm_and_yarn/brace-expansion-...6d219a4[dependabot skip] chore: update generated contentb320069build(deps): bump@docker/actions-toolkitfrom 0.92.0 to 0.93.008d3680[dependabot skip] chore: update generated content381f5a4Merge pull request #1042 from docker/dependabot/github_actions/codeql-actions...