Skip to content

github-actions: bump docker/login-action from 4 to 4.5.2 - #647

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/docker/login-action-4.5.1
Open

github-actions: bump docker/login-action from 4 to 4.5.2#647
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/docker/login-action-4.5.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 1, 2026

Copy link
Copy Markdown
Contributor

Bumps docker/login-action from 4 to 4.5.2.

Release notes

Sourced from docker/login-action's releases.

v4.5.2

Full Changelog: docker/login-action@v4.5.1...v4.5.2

v4.5.1

Full Changelog: docker/login-action@v4.5.0...v4.5.1

v4.5.0

Full Changelog: docker/login-action@v4.4.0...v4.5.0

v4.4.0

Full Changelog: docker/login-action@v4.3.0...v4.4.0

v4.3.0

Full Changelog: docker/login-action@v4.2.0...v4.3.0

v4.2.0

... (truncated)

Commits
  • a5e9150 Merge pull request #1048 from docker/dockerhub-oidc-support
  • a482ba4 build(deps): bump the codeql-actions group with 2 updates
  • 9e3d36e chore: update generated content
  • 14d6a79 docker hub oidc support
  • 03c8510 Merge pull request #1044 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • ad8a81f Merge pull request #1046 from docker/dependabot/npm_and_yarn/brace-expansion-...
  • 6d219a4 [dependabot skip] chore: update generated content
  • b320069 build(deps): bump @​docker/actions-toolkit from 0.92.0 to 0.93.0
  • 08d3680 [dependabot skip] chore: update generated content
  • 381f5a4 Merge pull request #1042 from docker/dependabot/github_actions/codeql-actions...
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github-actions labels Aug 1, 2026
@bgentry

bgentry commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps [docker/login-action](https://github.com/docker/login-action) from 4 to 4.5.2.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@v4...v4.5.2)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 4.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title github-actions: bump docker/login-action from 4 to 4.5.1 github-actions: bump docker/login-action from 4 to 4.5.2 Aug 4, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/docker/login-action-4.5.1 branch from a949bd9 to 7418dff Compare August 4, 2026 14:07

@bgentry bgentry left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Codex review: Blocked because the proposed version is an operational and security downgrade.

Upgrade

  • docker/login-action: floating v4 → v4.5.2
  • Reviewed head: 7418dff7db22999d8bf81809eb8a93d5dadced68
  • Proposed target: v4.5.2371161bbe7024a29a25c5e19bfcbc0804fe9ad2c

Security review

  • The repository's existing @v4 now resolves to newer v4.6.0 commit dbcb813823bdd20940b903addbd779551569679f, published before this PR. Merging would therefore downgrade all three call sites.
  • The v4.5.2 source and bundle were compared and provenance checked. It predates v4.6 path hardening and still bundles vulnerable js-yaml@5.2.1, undici@6.27.0, and brace-expansion@1.1.16 code.
  • River does not enable the most directly affected registry-auth, blob/cookie/retry, or Docker Hub OIDC paths, but the downgrade loses fixes with no compensating benefit for these workflows.

Compatibility verification

  • Current-head normal JS, Go, release, and riverui image checks passed. The Pro workflow fails at AWS role assumption before reaching live-registry login, so that credential path is not validated.

Residual risk / blocker

  • Leave @v4 unchanged or replace this PR with at least v4.6.0. Prefer a later release that also refreshes Undici and brace-expansion. Do not approve or merge v4.5.2.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github-actions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant