Skip to content

ci(deps): bump the actions group across 1 directory with 3 updates - #15

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-b5b707d031
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-b5b707d031

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 31, 2026 •

Copy link
Copy Markdown

Bumps the actions group with 3 updates in the / directory: docker/login-action, actions/setup-go and docker/build-push-action.

Updates docker/login-action from 4.1.0 to 4.6.0

Release notes

Sourced from docker/login-action's releases.

v4.6.0

Full Changelog: docker/login-action@v4.5.2...v4.6.0

v4.5.2

Full Changelog: docker/login-action@v4.5.1...v4.5.2

v4.5.1

Full Changelog: docker/login-action@v4.5.0...v4.5.1

v4.5.0

Full Changelog: docker/login-action@v4.4.0...v4.5.0

v4.4.0

Full Changelog: docker/login-action@v4.3.0...v4.4.0

v4.3.0

Full Changelog: docker/login-action@v4.2.0...v4.3.0

v4.2.0

... (truncated)

Commits
  • dbcb813 Merge pull request #1051 from docker/dependabot/npm_and_yarn/aws-sdk-dependen...
  • 5bcb015 [dependabot skip] chore: update generated content
  • b30b2f2 build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...
  • 9087f1e Merge pull request #1057 from docker/dependabot/npm_and_yarn/js-yaml-5.2.2
  • 0009830 [dependabot skip] chore: update generated content
  • 2325523 build(deps): bump js-yaml from 5.2.1 to 5.2.2
  • 4ec1d4a Merge pull request #1056 from docker/dependabot/npm_and_yarn/postcss-8.5.22
  • 5fc99ba Merge pull request #1053 from docker/dependabot/github_actions/aws-actions/co...
  • e512bd5 Merge pull request #1052 from docker/dependabot/github_actions/codeql-actions...
  • a146c91 Merge pull request #1059 from crazy-max/harden-buildx-scope-paths
  • Additional commits viewable in compare view

Updates actions/setup-go from 5.5.0 to 7.0.0

Release notes

Sourced from actions/setup-go's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/setup-go@v6...v7.0.0

v6.5.0

What's Changed

Dependency update

New Contributors

Full Changelog: actions/setup-go@v6...v6.5.0

v6.4.0

What's Changed

Enhancement

Dependency update

Documentation update

New Contributors

Full Changelog: actions/setup-go@v6...v6.4.0

v6.3.0

What's Changed

Full Changelog: actions/setup-go@v6...v6.3.0

v6.2.0

What's Changed

... (truncated)

Commits

Updates docker/build-push-action from 6.18.0 to 7.4.0

Release notes

Sourced from docker/build-push-action's releases.

v7.4.0

Full Changelog: docker/build-push-action@v7.3.0...v7.4.0

v7.3.0

Full Changelog: docker/build-push-action@v7.2.0...v7.3.0

v7.2.0

Full Changelog: docker/build-push-action@v7.1.0...v7.2.0

v7.1.0

... (truncated)

Commits
  • c3c9e26 Merge pull request #1621 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 459b674 [dependabot skip] chore: update generated content
  • 4dedcb2 chore(deps): Bump @​docker/actions-toolkit from 0.99.0 to 0.100.0
  • 379bf63 Merge pull request #1620 from crazy-max/buildx-error-message
  • 9877975 chore: update generated content
  • 7ed0556 use the shared Buildx error summary helper
  • 91670ba Merge pull request #1618 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 80dbc86 [dependabot skip] chore: update generated content
  • 50cac3a chore(deps): Bump @​docker/actions-toolkit from 0.98.0 to 0.99.0
  • 03b4d6c Merge pull request #1617 from crazy-max/fix-metadata-workflow-commands
  • Additional commits viewable in compare view

Summary by CodeRabbit

  • Chores
    • Updated the automation used for conformance checks, integration checks, and releases. No changes to their existing configuration or end-user functionality.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 31, 2026
@dependabot dependabot Bot changed the title ci(deps): bump the actions group with 3 updates ci(deps): bump the actions group across 1 directory with 3 updates Sep 14, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-b5b707d031 branch from 1a7531e to 984ddf6 Compare September 14, 2026 20:46
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-b5b707d031 branch from 984ddf6 to 98281ea Compare September 21, 2026 20:46
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-b5b707d031 branch from 98281ea to c16fc27 Compare September 28, 2026 20:46
@shaneutt

Copy link
Copy Markdown
Member

@dependabot recreate

Bumps the actions group with 3 updates in the / directory: [docker/login-action](https://github.com/docker/login-action), [actions/setup-go](https://github.com/actions/setup-go) and [docker/build-push-action](https://github.com/docker/build-push-action).


Updates `docker/login-action` from 4.1.0 to 4.6.0
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@4907a6d...dbcb813)

Updates `actions/setup-go` from 5.5.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](actions/setup-go@d35c59a...b7ad1da)

Updates `docker/build-push-action` from 6.18.0 to 7.4.0
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@2634353...c3c9e26)

---
updated-dependencies:
- dependency-name: actions/setup-go
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: docker/build-push-action
  dependency-version: 7.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: docker/login-action
  dependency-version: 4.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-b5b707d031 branch from c16fc27 to 2a8543d Compare September 29, 2026 17:25
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: praxis-proxy/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: c48a07a4-bf54-4664-a9c6-3d60e0118aa8

📥 Commits

Reviewing files that changed from the base of the PR and between fb8beaa and 2a8543d.

📒 Files selected for processing (3)
  • .github/workflows/conformance.yaml
  • .github/workflows/integration.yaml
  • .github/workflows/release.yaml
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

The conformance, integration, and release workflows update pinned versions of GitHub Actions. Existing action inputs and workflow step configurations remain unchanged.

Changes

Workflow action version updates

Layer / File(s) Summary
Update workflow action pins
.github/workflows/conformance.yaml, .github/workflows/integration.yaml, .github/workflows/release.yaml
The workflows update docker/login-action to v4.6.0, actions/setup-go to v7.0.0, and docker/build-push-action to v7.4.0. Other step configurations remain unchanged.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Suggested reviewers: shaneutt

Merge Risk: ⚪ Minimal · up to 2a854

The changes update workflow actions without changing their configurations. No specific workflow failure is identified; the PR appears mergeable subject to normal checks.

Architecture Summary

Architecture risk: 🔵 Low · up to 2a854

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/conformance.yaml: Updates the pinned docker/login-action version from v4.1.0 to v4.6.0.
  • observed — Modified behavior in .github/workflows/conformance.yaml: Updates the pinned actions/setup-go version from v5.5.0 to v7.0.0.
  • observed — Modified behavior in .github/workflows/integration.yaml: The GHCR login step’s docker/login-action pin changes from v4.1.0 to v4.6.0.
  • observed — Modified behavior in .github/workflows/release.yaml: The GHCR login step now uses docker/login-action v4.6.0 instead of v4.1.0; its registry and credential configuration is unchanged.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the three GitHub Actions dependency updates across the .github/workflows directory.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

@shaneutt

Copy link
Copy Markdown
Member

Will need to bump this manually later.

@shaneutt shaneutt closed this Sep 29, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/github_actions/actions-b5b707d031 branch September 29, 2026 18:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant