build(deps): Bump docker/login-action from 4.2.0 to 4.4.0 - #1050
build(deps): Bump docker/login-action from 4.2.0 to 4.4.0#1050dependabot[bot] wants to merge 1 commit into
Conversation
🤖 Cursor Dependency AnalysisSupply-Chain Malware ReviewI'll review the upstream Minor, intentional upstream update ( Evidence
Scanner disagreement: status is Compatibility AnalysisI'll analyze local usage of 1) Local usageSingle consumer site: Inputs used:
Not used: 2) API / behavior intersection
3) Risks / unknowns
4) VerdictSafe minor bump for this repo’s usage pattern. Merge. Malware Scan Summary
Top findings
|
Bumps [docker/login-action](https://github.com/docker/login-action) from 4.2.0 to 4.4.0. - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@v4.2.0...v4.4.0) --- updated-dependencies: - dependency-name: docker/login-action dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
a6569c5 to
f8e4c23
Compare
|
Superseded by #1078. |
Bumps docker/login-action from 4.2.0 to 4.4.0.
Release notes
Sourced from docker/login-action's releases.
Commits
af1e73fMerge pull request #1034 from docker/dependabot/npm_and_yarn/aws-sdk-dependen...da722bd[dependabot skip] chore: update generated content2916ad6build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...ca0a662Merge pull request #1035 from crazy-max/fix-registry-auth-empty-maskc455755chore: update generated content4835190skip empty registry-auth secret mask992421cMerge pull request #1033 from docker/dependabot/github_actions/docker/bake-ac...b249b43Merge pull request #1032 from docker/dependabot/github_actions/docker/bake-ac...1b67977build(deps): bump docker/bake-action from 7.2.0 to 7.3.09d49d6abuild(deps): bump docker/bake-action/subaction/matrixNote
Low Risk
Routine CI dependency bump with no application or secret-handling logic changes in this repo.
Overview
Bumps
docker/login-actionfrom v4.2.0 to v4.4.0 in the review deploy workflow’s package job, on the step that logs into ghcr.io before the image build/push. No inputs or surrounding steps change—only the action pin.Reviewed by Cursor Bugbot for commit f8e4c23. Bugbot is set up for automated code reviews on this repo. Configure here.