Skip to content

chore(deps): update docker/build-push-action action to v7.4.0 - #51

Merged
g-carre merged 1 commit into
mainfrom
renovate/docker-build-push-action-7.x
Sep 28, 2026
Merged

g-carre merged 1 commit into
mainfrom
renovate/docker-build-push-action-7.x

Conversation

@scality-renovate

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
docker/build-push-action action minor v7.3.0 → v7.4.0

Release Notes

docker/build-push-action (docker/build-push-action)

v7.4.0

Compare Source

Full Changelog: docker/build-push-action@v7.3.0...v7.4.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 9am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@github-actions

Copy link
Copy Markdown

Dependency Bump Evaluation

Version change: v7.3.0 → v7.4.0 (minor)
Semver bump type: minor

Changes:

  • Security fix: Prevents workflow command injection in metadata logs (#1617) — the docker-container driver writes the GitHub event payload into --metadata-file, and untrusted content (PR titles, branch names) could inject workflow commands when logged. Fixed by using printUntrusted to bracket output with ::stop-commands::.
  • Shared error helper for Buildx commands (#1620)
  • 10 internal dependency bumps (@docker/actions-toolkit 0.92.0→0.100.0, js-yaml, nanoid, postcss, undici, etc.)

Breaking changes: None

Security concerns: None — the update improves security by closing a moderate-to-high command injection vector in metadata logging.

Impact on codebase: Single usage in .github/workflows/build.yaml with standard inputs (context, build-args, push, tags, cache-from, cache-to). No inputs or behavior used by this repo are affected by the changes.

Recommendation: SAFE TO MERGE

Notes: This update is recommended promptly as it includes a security hardening fix. The action's API surface is unchanged — all changes are internal (error handling, log sanitization, transitive dependency bumps).

— Claude Code

@g-carre
g-carre merged commit 5b5f49f into main Sep 28, 2026
22 checks passed
@g-carre
g-carre deleted the renovate/docker-build-push-action-7.x branch September 28, 2026 07:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant