Skip to content

chore(deps): bump docker/login-action from 4.2.0 to 4.4.0#669

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/docker/login-action-4.3.0
Open

chore(deps): bump docker/login-action from 4.2.0 to 4.4.0#669
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/docker/login-action-4.3.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 3, 2026

Copy link
Copy Markdown
Contributor

Bumps docker/login-action from 4.2.0 to 4.4.0.

Release notes

Sourced from docker/login-action's releases.

v4.4.0

Full Changelog: docker/login-action@v4.3.0...v4.4.0

v4.3.0

Full Changelog: docker/login-action@v4.2.0...v4.3.0

Commits
  • af1e73f Merge pull request #1034 from docker/dependabot/npm_and_yarn/aws-sdk-dependen...
  • da722bd [dependabot skip] chore: update generated content
  • 2916ad6 build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...
  • ca0a662 Merge pull request #1035 from crazy-max/fix-registry-auth-empty-mask
  • c455755 chore: update generated content
  • 4835190 skip empty registry-auth secret mask
  • 992421c Merge pull request #1033 from docker/dependabot/github_actions/docker/bake-ac...
  • b249b43 Merge pull request #1032 from docker/dependabot/github_actions/docker/bake-ac...
  • 1b67977 build(deps): bump docker/bake-action from 7.2.0 to 7.3.0
  • 9d49d6a build(deps): bump docker/bake-action/subaction/matrix
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 3, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 3, 2026
@operon-ensemble-reviewer

Copy link
Copy Markdown

Ensemble Code Review

Verdict: approve

Summary: This is a clean Dependabot bump of the SHA-pinned docker/login-action from v4.2.0 to v4.3.0 in a single workflow file. The commit SHA and trailing tag comment are updated consistently, the action remains commit-pinned (the recommended security posture), and no usage, inputs, or logic changed. All three reviewers approved.

Findings (none — all reviewers approved)

The Verifier confirmed the old SHA (650006c6…) was replaced with the v4.3.0 SHA (c99871de…), the tag comment was updated to match, and no other references to the old SHA exist in the repo. No correctness, security, or contract concerns.


Generated by Operon Ensemble Code Review.

@dependabot dependabot Bot changed the title chore(deps): bump docker/login-action from 4.2.0 to 4.3.0 chore(deps): bump docker/login-action from 4.2.0 to 4.4.0 Jul 7, 2026
Bumps [docker/login-action](https://github.com/docker/login-action) from 4.2.0 to 4.4.0.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@650006c...af1e73f)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/docker/login-action-4.3.0 branch from 3c5c603 to a9ddff6 Compare July 7, 2026 19:37
@operon-ensemble-reviewer

Copy link
Copy Markdown

Ensemble Code Review

Verdict: approve

Summary: This is a clean Dependabot bump of the SHA-pinned docker/login-action from v4.2.0 to v4.4.0 in .github/workflows/demo-image.yml. The commit SHA (af1e73f9…) and trailing # v4.4.0 tag comment are updated consistently, the action remains commit-pinned (the recommended supply-chain posture), and no workflow inputs or logic changed. The branch-name/PR-title version skew (4.3.0 vs 4.4.0) is just Dependabot rebasing onto a newer release — the diff content is correct.

Findings (none — all reviewers approved)

The Verifier confirmed the old SHA (650006c6…) has no remaining references in the repo and the new pin resolves consistently with its # v4.4.0 tag comment. No correctness, security, or contract concerns from any reviewer.


Suggestions (1)
  • Before merging, confirm the pinned SHA af1e73f918a031802d376d3c8bbc3fe56130a9b0 corresponds to the official signed v4.4.0 release of docker/login-action — this preserves the security benefit of commit pinning. (Flagged by Pattern Matcher.)

Generated by Operon Ensemble Code Review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants