Compare commits

...

57 Commits

Author SHA1 Message Date
dependabot[bot]
c787a3580d build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 updates
Bumps the aws-sdk-dependencies group with 2 updates in the / directory: [@aws-sdk/client-ecr](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ecr) and [@aws-sdk/client-ecr-public](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ecr-public).


Updates `@aws-sdk/client-ecr` from 3.1095.0 to 3.1103.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ecr/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1103.0/clients/client-ecr)

Updates `@aws-sdk/client-ecr-public` from 3.1095.0 to 3.1103.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ecr-public/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1103.0/clients/client-ecr-public)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-ecr"
  dependency-version: 3.1096.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk-dependencies
- dependency-name: "@aws-sdk/client-ecr-public"
  dependency-version: 3.1096.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-07 05:54:22 +00:00
CrazyMax
eed2509203 Merge pull request #1068 from crazy-max/dockerhub-oidc-increase-expire-in
raise Docker Hub OIDC max expiry to 6 hours
2026-08-06 12:07:08 +02:00
CrazyMax
07573e7c18 chore: update generated content
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-08-06 11:54:13 +02:00
CrazyMax
99ffd0f38a raise Docker Hub OIDC max expiry to 6 hours
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-08-06 11:53:57 +02:00
CrazyMax
dbcb813823 Merge pull request #1051 from docker/dependabot/npm_and_yarn/aws-sdk-dependencies-46cc3261cb
build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 updates
2026-07-29 13:33:29 +02:00
github-actions[bot]
5bcb015ee6 [dependabot skip] chore: update generated content 2026-07-29 10:44:53 +00:00
dependabot[bot]
b30b2f2d31 build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 updates
Bumps the aws-sdk-dependencies group with 2 updates in the / directory: [@aws-sdk/client-ecr](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ecr) and [@aws-sdk/client-ecr-public](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ecr-public).


Updates `@aws-sdk/client-ecr` from 3.1091.0 to 3.1095.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ecr/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1095.0/clients/client-ecr)

Updates `@aws-sdk/client-ecr-public` from 3.1091.0 to 3.1095.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ecr-public/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1095.0/clients/client-ecr-public)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-ecr"
  dependency-version: 3.1092.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk-dependencies
- dependency-name: "@aws-sdk/client-ecr-public"
  dependency-version: 3.1092.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-29 10:43:57 +00:00
CrazyMax
9087f1e6d6 Merge pull request #1057 from docker/dependabot/npm_and_yarn/js-yaml-5.2.2
build(deps): bump js-yaml from 5.2.1 to 5.2.2
2026-07-29 12:40:51 +02:00
github-actions[bot]
0009830ea1 [dependabot skip] chore: update generated content 2026-07-29 10:32:28 +00:00
dependabot[bot]
23255232d3 build(deps): bump js-yaml from 5.2.1 to 5.2.2
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 5.2.1 to 5.2.2.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/5.2.1...5.2.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 5.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-29 10:31:34 +00:00
CrazyMax
4ec1d4a769 Merge pull request #1056 from docker/dependabot/npm_and_yarn/postcss-8.5.22
build(deps): bump postcss from 8.5.10 to 8.5.22
2026-07-29 12:28:53 +02:00
CrazyMax
5fc99ba47b Merge pull request #1053 from docker/dependabot/github_actions/aws-actions/configure-aws-credentials-6.2.3
build(deps): bump aws-actions/configure-aws-credentials from 6.2.2 to 6.2.3
2026-07-29 12:28:12 +02:00
CrazyMax
e512bd59d1 Merge pull request #1052 from docker/dependabot/github_actions/codeql-actions-73adf09e94
build(deps): bump the codeql-actions group across 1 directory with 2 updates
2026-07-29 12:26:59 +02:00
CrazyMax
a146c91b8f Merge pull request #1059 from crazy-max/harden-buildx-scope-paths
harden buildx scoped config path handling
2026-07-29 10:50:27 +02:00
CrazyMax
8ffd80ffa5 chore: update generated content
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-29 09:57:41 +02:00
CrazyMax
8305724bcf harden buildx scoped config path handling
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-29 09:57:00 +02:00
dependabot[bot]
91264757e1 build(deps): bump the codeql-actions group across 1 directory with 2 updates
Bumps the codeql-actions group with 2 updates in the / directory: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.37.2 to 4.37.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](e0647621c2...e4fba868fa)

Updates `github/codeql-action/analyze` from 4.37.2 to 4.37.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](e0647621c2...e4fba868fa)

---
updated-dependencies:
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-28 05:54:42 +00:00
CrazyMax
371161bbe7 Merge pull request #1058 from crazy-max/fix-dockerhub-oidc-error-handling
surface Docker Hub OIDC error responses
2026-07-27 18:30:08 +02:00
CrazyMax
5dc73df38e chore: update generated content
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-27 17:15:04 +02:00
CrazyMax
2aa1edee0b surface Docker Hub OIDC error responses
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-27 17:14:54 +02:00
dependabot[bot]
b472f5b276 build(deps): bump postcss from 8.5.10 to 8.5.22
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.10 to 8.5.22.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/postcss/postcss/compare/8.5.10...8.5.22)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.22
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-24 12:24:30 +00:00
CrazyMax
abd2ef45e7 Merge pull request #1055 from crazy-max/test-registry-auth-oidc
test: cover Docker Hub OIDC with registry-auth
2026-07-24 14:22:47 +02:00
CrazyMax
d49d3a9839 Merge pull request #1054 from crazy-max/oidc-missing-dhi
support dhi.io as Docker Hub OIDC registry
2026-07-24 14:22:20 +02:00
CrazyMax
b58b17c30b test: cover Docker Hub OIDC with registry-auth
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-24 10:37:01 +02:00
CrazyMax
be646c21ce chore: update generated content
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-24 10:33:14 +02:00
CrazyMax
d77c059cb9 support dhi.io as Docker Hub OIDC registry
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-24 10:26:38 +02:00
dependabot[bot]
9d876d6c33 build(deps): bump aws-actions/configure-aws-credentials
Bumps [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) from 6.2.2 to 6.2.3.
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](517a711dbc...e6de054238)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-24 05:54:30 +00:00
CrazyMax
06fb636fac Merge pull request #1037 from docker/dependabot/npm_and_yarn/aws-sdk-dependencies-001763bcc2
build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 updates
2026-07-23 13:48:53 +02:00
github-actions[bot]
a8bc953911 [dependabot skip] chore: update generated content 2026-07-23 11:45:23 +00:00
dependabot[bot]
f54b9019bf build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 updates
Bumps the aws-sdk-dependencies group with 2 updates in the / directory: [@aws-sdk/client-ecr](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ecr) and [@aws-sdk/client-ecr-public](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ecr-public).


Updates `@aws-sdk/client-ecr` from 3.1077.0 to 3.1091.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ecr/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1091.0/clients/client-ecr)

Updates `@aws-sdk/client-ecr-public` from 3.1077.0 to 3.1091.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ecr-public/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1091.0/clients/client-ecr-public)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-ecr"
  dependency-version: 3.1079.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk-dependencies
- dependency-name: "@aws-sdk/client-ecr-public"
  dependency-version: 3.1079.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-23 11:44:24 +00:00
CrazyMax
77f18f6713 Merge pull request #1049 from docker/dependabot/github_actions/codeql-actions-6a53124c02
build(deps): bump the codeql-actions group with 2 updates
2026-07-23 13:41:05 +02:00
CrazyMax
ec0bf287fb Merge pull request #1050 from docker/dependabot/npm_and_yarn/docker/actions-toolkit-0.94.0
build(deps): bump @docker/actions-toolkit from 0.93.0 to 0.94.0
2026-07-23 13:40:40 +02:00
github-actions[bot]
e37171e542 [dependabot skip] chore: update generated content 2026-07-23 11:36:42 +00:00
dependabot[bot]
1d3a7174ca build(deps): bump @docker/actions-toolkit from 0.93.0 to 0.94.0
Bumps [@docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.93.0 to 0.94.0.
- [Release notes](https://github.com/docker/actions-toolkit/releases)
- [Commits](https://github.com/docker/actions-toolkit/compare/v0.93.0...v0.94.0)

---
updated-dependencies:
- dependency-name: "@docker/actions-toolkit"
  dependency-version: 0.94.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-23 11:35:46 +00:00
CrazyMax
a5e9150fe2 Merge pull request #1048 from docker/dockerhub-oidc-support
Docker Hub OIDC login support
2026-07-23 13:24:10 +02:00
dependabot[bot]
a482ba4366 build(deps): bump the codeql-actions group with 2 updates
Bumps the codeql-actions group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.36.3 to 4.37.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](54f647b7e1...e0647621c2)

Updates `github/codeql-action/analyze` from 4.36.3 to 4.37.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](54f647b7e1...e0647621c2)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codeql-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codeql-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-23 05:54:58 +00:00
CrazyMax
9e3d36ea10 chore: update generated content
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-22 13:01:47 +02:00
CrazyMax
14d6a7934e docker hub oidc support
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-22 13:01:46 +02:00
CrazyMax
03c851098f Merge pull request #1044 from docker/dependabot/npm_and_yarn/docker/actions-toolkit-0.93.0
build(deps): bump @docker/actions-toolkit from 0.92.0 to 0.93.0
2026-07-22 08:53:04 +02:00
CrazyMax
ad8a81f098 Merge pull request #1046 from docker/dependabot/npm_and_yarn/brace-expansion-1.1.16
build(deps): bump brace-expansion from 1.1.13 to 1.1.16
2026-07-22 08:51:57 +02:00
github-actions[bot]
6d219a4928 [dependabot skip] chore: update generated content 2026-07-22 06:51:44 +00:00
dependabot[bot]
b3200694f4 build(deps): bump @docker/actions-toolkit from 0.92.0 to 0.93.0
Bumps [@docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.92.0 to 0.93.0.
- [Release notes](https://github.com/docker/actions-toolkit/releases)
- [Commits](https://github.com/docker/actions-toolkit/compare/v0.92.0...v0.93.0)

---
updated-dependencies:
- dependency-name: "@docker/actions-toolkit"
  dependency-version: 0.93.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-22 06:50:49 +00:00
github-actions[bot]
08d3680aa8 [dependabot skip] chore: update generated content 2026-07-22 06:50:38 +00:00
CrazyMax
381f5a4f5e Merge pull request #1042 from docker/dependabot/github_actions/codeql-actions-af2beed448
build(deps): bump the codeql-actions group with 2 updates
2026-07-22 08:49:44 +02:00
dependabot[bot]
4bc69ce4fd build(deps): bump brace-expansion from 1.1.13 to 1.1.16
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.13 to 1.1.16.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.13...v1.1.16)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.16
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-22 06:49:44 +00:00
CrazyMax
ddf94996dc Merge pull request #1043 from docker/dependabot/github_actions/actions/setup-node-7.0.0
build(deps): bump actions/setup-node from 6.4.0 to 7.0.0
2026-07-22 08:49:18 +02:00
CrazyMax
d870eb57d3 Merge pull request #1045 from docker/dependabot/github_actions/actions/checkout-7.0.1
build(deps): bump actions/checkout from 7.0.0 to 7.0.1
2026-07-22 08:48:31 +02:00
CrazyMax
4d7b1348c8 Merge pull request #1038 from docker/dependabot/npm_and_yarn/js-yaml-5.2.1
build(deps): bump js-yaml from 5.2.0 to 5.2.1
2026-07-22 08:47:43 +02:00
dependabot[bot]
608836776e build(deps): bump actions/checkout from 7.0.0 to 7.0.1
Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](9c091bb21b...3d3c42e5aa)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-21 05:52:59 +00:00
dependabot[bot]
3bab31f360 build(deps): bump actions/setup-node from 6.4.0 to 7.0.0
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.4.0 to 7.0.0.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](48b55a011b...8207627860)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-15 05:52:18 +00:00
dependabot[bot]
dc654b7be1 build(deps): bump the codeql-actions group with 2 updates
Bumps the codeql-actions group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.36.2 to 4.36.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](8aad20d150...54f647b7e1)

Updates `github/codeql-action/analyze` from 4.36.2 to 4.36.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](8aad20d150...54f647b7e1)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.36.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.36.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 12:01:00 +00:00
CrazyMax
c66a8fcb24 Merge pull request #1041 from crazy-max/group-codeql-dependabot-updates
chore: group codeql dependabot updates
2026-07-09 13:57:49 +02:00
CrazyMax
6d7f9d458a chore: group codeql dependabot updates
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-09 12:43:17 +02:00
CrazyMax
13169716da Merge pull request #1040 from docker/dependabot/github_actions/aws-actions/configure-aws-credentials-6.2.2
build(deps): bump aws-actions/configure-aws-credentials from 6.2.1 to 6.2.2
2026-07-09 10:17:14 +02:00
dependabot[bot]
c1aa9e5f45 build(deps): bump aws-actions/configure-aws-credentials
Bumps [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) from 6.2.1 to 6.2.2.
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](254c19bd24...517a711dbc)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 05:53:39 +00:00
github-actions[bot]
026f3975fd [dependabot skip] chore: update generated content 2026-07-06 05:55:36 +00:00
dependabot[bot]
3dbb99fd00 build(deps): bump js-yaml from 5.2.0 to 5.2.1
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 5.2.0 to 5.2.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/5.2.0...5.2.1)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 5.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-06 05:54:34 +00:00
19 changed files with 1021 additions and 424 deletions

View File

@@ -10,6 +10,9 @@ updates:
crazy-max-dot-github: crazy-max-dot-github:
patterns: patterns:
- "crazy-max/.github/*" - "crazy-max/.github/*"
codeql-actions:
patterns:
- "github/codeql-action/*"
labels: labels:
- "dependencies" - "dependencies"
- "bot" - "bot"

View File

@@ -25,7 +25,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Stop docker name: Stop docker
run: | run: |
@@ -49,7 +49,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to GitHub Container Registry name: Login to GitHub Container Registry
uses: ./ uses: ./
@@ -67,7 +67,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to GitHub Container Registry name: Login to GitHub Container Registry
uses: ./ uses: ./
@@ -97,7 +97,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to GitHub Container Registry name: Login to GitHub Container Registry
uses: ./ uses: ./
@@ -122,7 +122,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to ACR name: Login to ACR
uses: ./ uses: ./
@@ -142,7 +142,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to Docker Hub name: Login to Docker Hub
uses: ./ uses: ./
@@ -150,6 +150,50 @@ jobs:
username: ${{ vars.DOCKERPUBLICBOT_USERNAME }} username: ${{ vars.DOCKERPUBLICBOT_USERNAME }}
password: ${{ secrets.DOCKERPUBLICBOT_READ_PAT }} password: ${{ secrets.DOCKERPUBLICBOT_READ_PAT }}
dockerhub-oidc:
permissions:
contents: read
id-token: write
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os:
- ubuntu-latest
- windows-latest
steps:
-
name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
-
name: Login to Docker Hub with OIDC
uses: ./
env:
DOCKERHUB_OIDC_CONNECTIONID: ${{ vars.DOCKERHUB_OIDC_CONNECTIONID }}
with:
username: ${{ vars.DOCKERHUB_OIDC_USERNAME }}
registry-auth-oidc:
permissions:
contents: read
id-token: write
runs-on: ubuntu-latest
steps:
-
name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
-
name: Login to registries
uses: ./
env:
DOCKERHUB_OIDC_CONNECTIONID: ${{ vars.DOCKERHUB_OIDC_CONNECTIONID }}
with:
registry-auth: |
- username: ${{ vars.DOCKERHUB_OIDC_USERNAME }}
- registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
ecr: ecr:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
strategy: strategy:
@@ -161,7 +205,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to ECR name: Login to ECR
uses: ./ uses: ./
@@ -181,10 +225,10 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Configure AWS Credentials name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@254c19bd240aabef8777f48595e9d2d7b972184b # v6.2.1 uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
with: with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
@@ -209,10 +253,10 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Configure AWS Credentials name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@254c19bd240aabef8777f48595e9d2d7b972184b # v6.2.1 uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
with: with:
role-to-assume: arn:aws:iam::175142243308:role/official_gha_cicd_login_action role-to-assume: arn:aws:iam::175142243308:role/official_gha_cicd_login_action
aws-region: us-east-1 aws-region: us-east-1
@@ -233,7 +277,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to Public ECR name: Login to Public ECR
continue-on-error: ${{ matrix.os == 'windows-latest' }} continue-on-error: ${{ matrix.os == 'windows-latest' }}
@@ -256,10 +300,10 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Configure AWS Credentials name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@254c19bd240aabef8777f48595e9d2d7b972184b # v6.2.1 uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
with: with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
@@ -285,10 +329,10 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Configure AWS Credentials name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@254c19bd240aabef8777f48595e9d2d7b972184b # v6.2.1 uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
with: with:
role-to-assume: arn:aws:iam::175142243308:role/official_gha_cicd_login_action role-to-assume: arn:aws:iam::175142243308:role/official_gha_cicd_login_action
aws-region: us-east-1 aws-region: us-east-1
@@ -310,7 +354,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to GitHub Container Registry name: Login to GitHub Container Registry
uses: ./ uses: ./
@@ -330,7 +374,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to GitLab name: Login to GitLab
uses: ./ uses: ./
@@ -350,7 +394,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to Google Artifact Registry name: Login to Google Artifact Registry
uses: ./ uses: ./
@@ -370,7 +414,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to Google Container Registry name: Login to Google Container Registry
uses: ./ uses: ./
@@ -384,7 +428,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to registries name: Login to registries
uses: ./ uses: ./
@@ -407,7 +451,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to registries name: Login to registries
uses: ./ uses: ./
@@ -428,7 +472,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to registries name: Login to registries
id: login id: login
@@ -460,7 +504,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to Docker Hub name: Login to Docker Hub
uses: ./ uses: ./
@@ -490,7 +534,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to Docker Hub name: Login to Docker Hub
uses: ./ uses: ./
@@ -520,7 +564,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to GitHub Container Registry name: Login to GitHub Container Registry
uses: ./ uses: ./
@@ -551,7 +595,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to GitHub Container Registry name: Login to GitHub Container Registry
uses: ./ uses: ./

View File

@@ -22,7 +22,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Enable corepack name: Enable corepack
run: | run: |
@@ -30,17 +30,17 @@ jobs:
yarn --version yarn --version
- -
name: Set up Node name: Set up Node
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with: with:
node-version: ${{ env.NODE_VERSION }} node-version: ${{ env.NODE_VERSION }}
- -
name: Initialize CodeQL name: Initialize CodeQL
uses: github/codeql-action/init@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 uses: github/codeql-action/init@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4.37.3
with: with:
languages: javascript-typescript languages: javascript-typescript
build-mode: none build-mode: none
- -
name: Perform CodeQL Analysis name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 uses: github/codeql-action/analyze@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4.37.3
with: with:
category: "/language:javascript-typescript" category: "/language:javascript-typescript"

View File

@@ -22,7 +22,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Publish name: Publish
uses: actions/publish-immutable-action@4bc8754ffc40f27910afb20287dbbbb675a4e978 # v0.0.4 uses: actions/publish-immutable-action@4bc8754ffc40f27910afb20287dbbbb675a4e978 # v0.0.4

View File

@@ -20,7 +20,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Test name: Test
uses: docker/bake-action@d3418bd7d0e9324001bca92fa8ba175ea7e6dc9b # v7.3.0 uses: docker/bake-action@d3418bd7d0e9324001bca92fa8ba175ea7e6dc9b # v7.3.0

View File

@@ -30,7 +30,7 @@ jobs:
permission-contents: write permission-contents: write
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with: with:
ref: ${{ github.event.pull_request.head.ref }} ref: ${{ github.event.pull_request.head.ref }}
fetch-depth: 0 fetch-depth: 0

View File

@@ -22,7 +22,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Generate matrix name: Generate matrix
id: generate id: generate

View File

@@ -28,6 +28,7 @@ ___
* [Set scopes for the authentication token](#set-scopes-for-the-authentication-token) * [Set scopes for the authentication token](#set-scopes-for-the-authentication-token)
* [Customizing](#customizing) * [Customizing](#customizing)
* [inputs](#inputs) * [inputs](#inputs)
* [environment variables](#environment-variables)
* [Contributing](#contributing) * [Contributing](#contributing)
## Usage ## Usage
@@ -57,6 +58,36 @@ jobs:
password: ${{ secrets.DOCKERHUB_TOKEN }} password: ${{ secrets.DOCKERHUB_TOKEN }}
``` ```
You can also [authenticate to Docker Hub with OpenID Connect](https://docs.docker.com/enterprise/security/oidc-connections/)
when your Docker Hub organization has an OIDC connection configured. The
workflow must grant the `id-token: write` permission, pass the Docker Hub
organization name as `username`, omit `password`, and set the OIDC connection
ID in `DOCKERHUB_OIDC_CONNECTIONID` environment variable.
```yaml
name: ci
on:
push:
branches: main
permissions:
contents: read
id-token: write
jobs:
login:
runs-on: ubuntu-latest
steps:
-
name: Login to Docker Hub
uses: docker/login-action@v4
env:
DOCKERHUB_OIDC_CONNECTIONID: ${{ vars.DOCKERHUB_OIDC_CONNECTIONID }}
with:
username: ${{ vars.DOCKERHUB_ORGANIZATION }}
```
### GitHub Container Registry ### GitHub Container Registry
To authenticate to the [GitHub Container Registry](https://docs.github.com/en/packages/working-with-a-github-packages-registry/working-with-the-container-registry), To authenticate to the [GitHub Container Registry](https://docs.github.com/en/packages/working-with-a-github-packages-registry/working-with-the-container-registry),
@@ -617,6 +648,38 @@ jobs:
password: ${{ secrets.GITHUB_TOKEN }} password: ${{ secrets.GITHUB_TOKEN }}
``` ```
Docker Hub OIDC can also be used with `registry-auth`. Grant `id-token: write`,
set `DOCKERHUB_OIDC_CONNECTIONID`, pass the Docker Hub organization name as
`username`, and omit `password` for the Docker Hub object:
```yaml
name: ci
on:
push:
branches: main
permissions:
contents: read
id-token: write
jobs:
login:
runs-on: ubuntu-latest
steps:
-
name: Login to registries
uses: docker/login-action@v4
env:
DOCKERHUB_OIDC_CONNECTIONID: ${{ vars.DOCKERHUB_OIDC_CONNECTIONID }}
with:
registry-auth: |
- username: ${{ vars.DOCKERHUB_ORGANIZATION }}
- registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
```
### Set scopes for the authentication token ### Set scopes for the authentication token
The `scope` input allows limiting registry credentials to a specific repository The `scope` input allows limiting registry credentials to a specific repository
@@ -690,6 +753,15 @@ The following inputs can be used as `step.with` keys:
> [!NOTE] > [!NOTE]
> The `registry-auth` input cannot be used with other inputs except `logout`. > The `registry-auth` input cannot be used with other inputs except `logout`.
### environment variables
The following environment variables can be set as `step.env` keys:
| Name | Type | Default | Description |
|-------------------------------|--------|---------|----------------------------------------------------------------------------------------------------|
| `DOCKERHUB_OIDC_CONNECTIONID` | String | | Docker Hub OIDC connection ID. Required for Docker Hub OIDC login |
| `DOCKERHUB_OIDC_EXPIREIN` | Number | `300` | Docker Hub OIDC token lifetime in seconds. Must be between `300` (5 minutes) and `21600` (6 hours) |
## Contributing ## Contributing
Want to contribute? Awesome! You can find information about contributing to Want to contribute? Awesome! You can find information about contributing to

View File

@@ -35,6 +35,87 @@ test('getAuthList uses the default Docker Hub registry when computing scoped con
}); });
}); });
test('getAuthList supports @ scopes appended to the registry config dir', async () => {
process.env['INPUT_USERNAME'] = 'dbowie';
process.env['INPUT_PASSWORD'] = 'groundcontrol';
process.env['INPUT_SCOPE'] = '@push';
process.env['INPUT_LOGOUT'] = 'false';
const [auth] = getAuthList(getInputs());
expect(auth).toMatchObject({
configDir: path.join(Buildx.configDir, 'config', 'registry-1.docker.io') + '@push'
});
});
test('getAuthList supports repository scopes with appended actions', async () => {
process.env['INPUT_USERNAME'] = 'dbowie';
process.env['INPUT_PASSWORD'] = 'groundcontrol';
process.env['INPUT_SCOPE'] = 'docker/buildx-bin@push';
process.env['INPUT_LOGOUT'] = 'false';
const [auth] = getAuthList(getInputs());
expect(auth).toMatchObject({
configDir: path.join(Buildx.configDir, 'config', 'registry-1.docker.io', 'docker', 'buildx-bin@push')
});
});
test('getAuthList supports comma-separated scope actions', async () => {
process.env['INPUT_USERNAME'] = 'dbowie';
process.env['INPUT_PASSWORD'] = 'groundcontrol';
process.env['INPUT_SCOPE'] = 'docker/buildx-bin@pull,push';
process.env['INPUT_LOGOUT'] = 'false';
const [auth] = getAuthList(getInputs());
expect(auth).toMatchObject({
configDir: path.join(Buildx.configDir, 'config', 'registry-1.docker.io', 'docker', 'buildx-bin@pull,push')
});
});
// prettier-ignore
test.each([
'../../../../work/leaked',
'..',
'foo/../../../../etc',
'@../../../leaked',
'foo/bar@../../../leaked',
'@push@pull',
'foo/bar@push@pull',
'@push,',
'@,push',
'@pull,,push',
'@Push',
path.join(path.parse(Buildx.configDir).root, 'work', 'leaked')
])('getAuthList rejects unsafe or unsupported scope path: %s', async scope => {
expect(() => {
getAuthList({
registry: '',
username: 'dbowie',
password: 'groundcontrol',
scope,
ecr: '',
logout: false,
registryAuth: ''
});
}).toThrow(/Invalid scope/);
});
// prettier-ignore
test.each([
'../../../../work/leaked',
'..',
'foo/../../../../etc',
path.join(path.parse(Buildx.configDir).root, 'work', 'leaked')
])('getAuthList rejects unsafe registry path: %s', async registry => {
expect(() => {
getAuthList({
registry,
username: 'dbowie',
password: 'groundcontrol',
scope: '@push',
ecr: '',
logout: false,
registryAuth: ''
});
}).toThrow(/Invalid registry/);
});
test('getAuthList skips secret masking when registry-auth password is absent', async () => { test('getAuthList skips secret masking when registry-auth password is absent', async () => {
const stdoutWriteSpy = vi.spyOn(process.stdout, 'write').mockImplementation(() => true); const stdoutWriteSpy = vi.spyOn(process.stdout, 'write').mockImplementation(() => true);
const [auth] = getAuthList({ const [auth] = getAuthList({
@@ -54,6 +135,25 @@ test('getAuthList skips secret masking when registry-auth password is absent', a
}); });
}); });
test('getAuthList supports password-less Docker Hub registry-auth for OIDC', async () => {
const [auth] = getAuthList({
registry: '',
username: '',
password: '',
scope: '',
ecr: '',
logout: true,
registryAuth: '- username: docker-org\n'
});
expect(auth).toMatchObject({
registry: 'docker.io',
username: 'docker-org',
password: undefined,
ecr: 'auto'
});
});
test('getAuthList masks registry-auth password when present', async () => { test('getAuthList masks registry-auth password when present', async () => {
const stdoutWriteSpy = vi.spyOn(process.stdout, 'write').mockImplementation(() => true); const stdoutWriteSpy = vi.spyOn(process.stdout, 'write').mockImplementation(() => true);
getAuthList({ getAuthList({

View File

@@ -1,8 +1,14 @@
import {expect, test, vi} from 'vitest'; import {afterEach, expect, test, vi} from 'vitest';
import {Docker} from '@docker/actions-toolkit/lib/docker/docker.js'; import {Docker} from '@docker/actions-toolkit/lib/docker/docker.js';
import {loginStandard, logout} from '../src/docker.js'; import {login, loginStandard, logout} from '../src/docker.js';
import * as dockerhub from '../src/dockerhub.js';
afterEach(() => {
vi.restoreAllMocks();
delete process.env.DOCKERHUB_OIDC_CONNECTIONID;
});
test('loginStandard calls exec', async () => { test('loginStandard calls exec', async () => {
const execSpy = vi.spyOn(Docker, 'getExecOutput').mockImplementation(async () => { const execSpy = vi.spyOn(Docker, 'getExecOutput').mockImplementation(async () => {
@@ -32,6 +38,37 @@ test('loginStandard calls exec', async () => {
}); });
}); });
test('login exchanges Docker Hub OIDC token for password-less auth', async () => {
process.env.DOCKERHUB_OIDC_CONNECTIONID = '123e4567-e89b-42d3-a456-426614174000';
const execSpy = vi.spyOn(Docker, 'getExecOutput').mockImplementation(async () => {
return {
exitCode: 0,
stdout: '',
stderr: ''
};
});
const oidcSpy = vi.spyOn(dockerhub, 'getOIDCToken').mockResolvedValue({
username: 'docker-org',
token: 'hub-token'
});
await login({
registry: 'docker.io',
username: 'docker-org',
password: '',
scope: '',
ecr: 'auto',
configDir: ''
});
expect(oidcSpy).toHaveBeenCalledWith('docker.io', 'docker-org');
expect(execSpy).toHaveBeenCalledWith(['login', '--password-stdin', '--username', 'docker-org', 'docker.io'], {
input: Buffer.from('hub-token'),
silent: true,
ignoreReturnCode: true
});
});
test('logout calls exec', async () => { test('logout calls exec', async () => {
const execSpy = vi.spyOn(Docker, 'getExecOutput').mockImplementation(async () => { const execSpy = vi.spyOn(Docker, 'getExecOutput').mockImplementation(async () => {
return { return {

139
__tests__/dockerhub.test.ts Normal file
View File

@@ -0,0 +1,139 @@
import * as core from '@actions/core';
import * as httpm from '@actions/http-client';
import {beforeEach, describe, expect, test, vi} from 'vitest';
import * as dockerhub from '../src/dockerhub.js';
vi.mock('@actions/core', () => ({
getIDToken: vi.fn(),
info: vi.fn(),
setSecret: vi.fn()
}));
const validConnectionID = '123e4567-e89b-42d3-a456-426614174000';
const httpResponse = (statusCode: number, body: string, headers: Record<string, string> = {}): httpm.HttpClientResponse => {
return {
message: {
statusCode,
headers
},
readBody: vi.fn(async () => body)
} as unknown as httpm.HttpClientResponse;
};
describe('isDockerHubOIDC', () => {
beforeEach(() => {
delete process.env.DOCKERHUB_OIDC_CONNECTIONID;
});
test.each(['', 'docker.io', 'registry-1.docker.io', 'registry-1-stage.docker.io'])('detects Docker Hub registry %p with empty password', registry => {
process.env.DOCKERHUB_OIDC_CONNECTIONID = validConnectionID;
expect(dockerhub.isDockerHubOIDC(registry, '')).toBe(true);
});
test('requires connection ID env var', () => {
expect(dockerhub.isDockerHubOIDC('docker.io', '')).toBe(false);
});
test('requires empty password', () => {
process.env.DOCKERHUB_OIDC_CONNECTIONID = validConnectionID;
expect(dockerhub.isDockerHubOIDC('docker.io', 'groundcontrol')).toBe(false);
});
test('ignores non-Docker Hub registries', () => {
process.env.DOCKERHUB_OIDC_CONNECTIONID = validConnectionID;
expect(dockerhub.isDockerHubOIDC('ghcr.io', '')).toBe(false);
});
});
describe('getOIDCToken', () => {
const getIDTokenMock = vi.mocked(core.getIDToken);
const setSecretMock = vi.mocked(core.setSecret);
let postSpy: ReturnType<typeof vi.spyOn>;
beforeEach(() => {
process.env.DOCKERHUB_OIDC_CONNECTIONID = validConnectionID;
delete process.env.DOCKERHUB_OIDC_EXPIREIN;
getIDTokenMock.mockResolvedValue('github-id-token');
postSpy = vi.spyOn(httpm.HttpClient.prototype, 'post').mockResolvedValue(httpResponse(200, JSON.stringify({access_token: 'hub-token'})));
});
test('exchanges GitHub OIDC token for Docker Hub token', async () => {
const credentials = await dockerhub.getOIDCToken('docker.io', 'dbowie');
expect(credentials).toEqual({
username: 'dbowie',
token: 'hub-token'
});
expect(getIDTokenMock).toHaveBeenCalledWith('https://identity.docker.com');
expect(postSpy).toHaveBeenCalledTimes(1);
expect(postSpy.mock.calls[0][0]).toBe('https://identity.docker.com/oauth/token');
const http = postSpy.mock.contexts[0] as httpm.HttpClient;
expect(http.userAgent).toBe('github.com/docker/login-action');
expect(http.requestOptions?.headers).toEqual({
'Content-Type': 'application/x-www-form-urlencoded'
});
const body = new URLSearchParams(postSpy.mock.calls[0][1]);
expect(body.get('grant_type')).toBe('urn:ietf:params:oauth:grant-type:token-exchange');
expect(body.get('subject_token_type')).toBe('urn:ietf:params:oauth:token-type:id_token');
expect(body.get('subject_token')).toBe('github-id-token');
expect(body.get('connection_id')).toBe(validConnectionID);
expect(body.get('expires_in')).toBe('300');
expect(setSecretMock).toHaveBeenCalledWith('hub-token');
});
test('uses custom token expiration', async () => {
process.env.DOCKERHUB_OIDC_EXPIREIN = '21600';
await dockerhub.getOIDCToken('docker.io', 'dbowie');
const body = new URLSearchParams(postSpy.mock.calls[0][1]);
expect(body.get('expires_in')).toBe('21600');
});
test('uses stage identity host for stage registry', async () => {
await dockerhub.getOIDCToken('registry-1-stage.docker.io', 'dbowie');
expect(getIDTokenMock).toHaveBeenCalledWith('https://identity-stage.docker.com');
expect(postSpy.mock.calls[0][0]).toBe('https://identity-stage.docker.com/oauth/token');
});
test('requires connection ID env var', async () => {
delete process.env.DOCKERHUB_OIDC_CONNECTIONID;
await expect(dockerhub.getOIDCToken('docker.io', 'dbowie')).rejects.toThrow('DOCKERHUB_OIDC_CONNECTIONID is required for Docker Hub OIDC login');
expect(getIDTokenMock).not.toHaveBeenCalled();
expect(postSpy).not.toHaveBeenCalled();
});
test('validates connection ID', async () => {
process.env.DOCKERHUB_OIDC_CONNECTIONID = 'not-a-uuid';
await expect(dockerhub.getOIDCToken('docker.io', 'dbowie')).rejects.toThrow('Invalid DOCKERHUB_OIDC_CONNECTIONID. Must be a valid UUID.');
expect(getIDTokenMock).not.toHaveBeenCalled();
expect(postSpy).not.toHaveBeenCalled();
});
test.each(['not-a-number', '299', '21601'])('validates token expiration %p', async expiresIn => {
process.env.DOCKERHUB_OIDC_EXPIREIN = expiresIn;
await expect(dockerhub.getOIDCToken('docker.io', 'dbowie')).rejects.toThrow(`Invalid DOCKERHUB_OIDC_EXPIREIN: ${expiresIn}. Must be between 300 and 21600`);
expect(getIDTokenMock).not.toHaveBeenCalled();
expect(postSpy).not.toHaveBeenCalled();
});
test('retries rate limited token requests with Retry-After', async () => {
postSpy.mockResolvedValueOnce(httpResponse(429, '', {'retry-after': '0'})).mockResolvedValueOnce(httpResponse(200, JSON.stringify({access_token: 'hub-token'})));
await dockerhub.getOIDCToken('docker.io', 'dbowie');
expect(postSpy).toHaveBeenCalledTimes(2);
expect(core.info).toHaveBeenCalledWith('Docker Hub OIDC token request rate limited, retrying in 0ms (attempt 1/5)');
});
test('throws Docker Hub OIDC error responses', async () => {
postSpy.mockResolvedValue(httpResponse(400, JSON.stringify({error: 'invalid_request', error_description: 'bad connection', error_uri: 'https://docs.docker.com'})));
await expect(dockerhub.getOIDCToken('docker.io', 'dbowie')).rejects.toThrow('Docker Hub API: bad status code 400: {"error":"invalid_request","error_description":"bad connection","error_uri":"https://docs.docker.com"}');
});
test('throws rate limited Docker Hub OIDC error response after retries', async () => {
postSpy.mockResolvedValue(httpResponse(429, JSON.stringify({error: 'rate_limited', error_description: 'slow down'}), {'retry-after': '0'}));
await expect(dockerhub.getOIDCToken('docker.io', 'dbowie')).rejects.toThrow('Docker Hub API: bad status code 429: {"error":"rate_limited","error_description":"slow down"}');
expect(postSpy).toHaveBeenCalledTimes(6);
});
});

241
dist/index.cjs generated vendored

File diff suppressed because one or more lines are too long

8
dist/index.cjs.map generated vendored

File diff suppressed because one or more lines are too long

79
dist/licenses.txt generated vendored
View File

@@ -3,7 +3,7 @@ https://www.npmjs.com/package/generate-license-file
The following npm package may be included in this product: The following npm package may be included in this product:
- @aws/lambda-invoke-store@0.2.3 - @aws/lambda-invoke-store@0.3.0
This package contains the following license: This package contains the following license:
@@ -399,7 +399,7 @@ Apache License
The following npm package may be included in this product: The following npm package may be included in this product:
- @docker/actions-toolkit@0.92.0 - @docker/actions-toolkit@0.94.0
This package contains the following license: This package contains the following license:
@@ -1913,8 +1913,8 @@ Apache License
The following npm packages may be included in this product: The following npm packages may be included in this product:
- @aws-sdk/client-ecr-public@3.1077.0 - @aws-sdk/client-ecr-public@3.1095.0
- @aws-sdk/client-ecr@3.1077.0 - @aws-sdk/client-ecr@3.1095.0
These packages each contain the following license: These packages each contain the following license:
@@ -2124,9 +2124,9 @@ Apache License
The following npm packages may be included in this product: The following npm packages may be included in this product:
- @aws-sdk/signature-v4-multi-region@3.996.37 - @aws-sdk/signature-v4-multi-region@3.996.42
- @smithy/core@3.28.0 - @smithy/core@3.30.0
- @smithy/types@4.15.0 - @smithy/types@4.16.1
These packages each contain the following license: These packages each contain the following license:
@@ -2396,11 +2396,12 @@ SOFTWARE.
----------- -----------
The following npm package may be included in this product: The following npm packages may be included in this product:
- js-yaml@5.2.0 - js-yaml@5.2.1
- js-yaml@5.2.2
This package contains the following license: These packages each contain the following license:
(The MIT License) (The MIT License)
@@ -3175,7 +3176,7 @@ software or this license, under any kind of legal claim.***
The following npm package may be included in this product: The following npm package may be included in this product:
- @aws-sdk/core@3.974.25 - @aws-sdk/core@3.977.1
This package contains the following license: This package contains the following license:
@@ -3385,16 +3386,16 @@ Apache License
The following npm packages may be included in this product: The following npm packages may be included in this product:
- @aws-sdk/credential-provider-env@3.972.51 - @aws-sdk/credential-provider-env@3.972.61
- @aws-sdk/credential-provider-ini@3.972.58 - @aws-sdk/credential-provider-ini@3.973.6
- @aws-sdk/credential-provider-node@3.972.60 - @aws-sdk/credential-provider-node@3.972.72
- @aws-sdk/token-providers@3.1077.0 - @aws-sdk/token-providers@3.1095.0
- @aws-sdk/types@3.973.14 - @aws-sdk/types@3.974.2
- @aws-sdk/xml-builder@3.972.32 - @aws-sdk/xml-builder@3.972.37
- @smithy/credential-provider-imds@4.4.4 - @smithy/credential-provider-imds@4.4.14
- @smithy/fetch-http-handler@5.6.1 - @smithy/fetch-http-handler@5.6.11
- @smithy/node-http-handler@4.9.1 - @smithy/node-http-handler@4.9.11
- @smithy/signature-v4@5.6.0 - @smithy/signature-v4@5.6.10
These packages each contain the following license: These packages each contain the following license:
@@ -3604,9 +3605,9 @@ Apache License
The following npm packages may be included in this product: The following npm packages may be included in this product:
- @aws-sdk/credential-provider-process@3.972.51 - @aws-sdk/credential-provider-process@3.972.61
- @aws-sdk/credential-provider-sso@3.972.57 - @aws-sdk/credential-provider-sso@3.973.5
- @aws-sdk/credential-provider-web-identity@3.972.57 - @aws-sdk/credential-provider-web-identity@3.972.67
These packages each contain the following license: These packages each contain the following license:
@@ -3880,9 +3881,9 @@ END OF TERMS AND CONDITIONS
The following npm packages may be included in this product: The following npm packages may be included in this product:
- @aws-sdk/credential-provider-http@3.972.53 - @aws-sdk/credential-provider-http@3.972.63
- @aws-sdk/credential-provider-login@3.972.57 - @aws-sdk/credential-provider-login@3.972.68
- @aws-sdk/nested-clients@3.997.25 - @aws-sdk/nested-clients@3.997.35
- @sigstore/verify@4.1.0 - @sigstore/verify@4.1.0
These packages each contain the following license: These packages each contain the following license:
@@ -4590,7 +4591,7 @@ USE OR OTHER DEALINGS IN THE SOFTWARE.
The following npm packages may be included in this product: The following npm packages may be included in this product:
- brace-expansion@1.1.13 - brace-expansion@1.1.16
- brace-expansion@2.0.3 - brace-expansion@2.0.3
These packages each contain the following license: These packages each contain the following license:
@@ -5562,7 +5563,7 @@ THE SOFTWARE.
The following npm package may be included in this product: The following npm package may be included in this product:
- csv-parse@7.0.0 - csv-parse@7.0.1
This package contains the following license: This package contains the following license:
@@ -5590,6 +5591,24 @@ SOFTWARE.
----------- -----------
The following npm package may be included in this product:
- uuid@14.0.1
This package contains the following license:
The MIT License (MIT)
Copyright (c) 2010-2020 Robert Kieffer and other contributors
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
-----------
The following npm package may be included in this product: The following npm package may be included in this product:
- tunnel@0.0.6 - tunnel@0.0.6
@@ -6207,7 +6226,7 @@ THE SOFTWARE.
The following npm packages may be included in this product: The following npm packages may be included in this product:
- @actions/artifact@6.2.1 - @actions/artifact@6.2.1
- @actions/cache@6.1.0 - @actions/cache@6.2.0
- @actions/core@3.0.0 - @actions/core@3.0.0
- @actions/core@3.0.1 - @actions/core@3.0.1
- @actions/exec@3.0.0 - @actions/exec@3.0.0

View File

@@ -24,12 +24,14 @@
"packageManager": "yarn@4.15.0", "packageManager": "yarn@4.15.0",
"dependencies": { "dependencies": {
"@actions/core": "^3.0.1", "@actions/core": "^3.0.1",
"@aws-sdk/client-ecr": "^3.1077.0", "@actions/http-client": "^4.0.1",
"@aws-sdk/client-ecr-public": "^3.1077.0", "@aws-sdk/client-ecr": "^3.1103.0",
"@docker/actions-toolkit": "^0.92.0", "@aws-sdk/client-ecr-public": "^3.1103.0",
"@docker/actions-toolkit": "^0.94.0",
"http-proxy-agent": "^9.1.0", "http-proxy-agent": "^9.1.0",
"https-proxy-agent": "^9.1.0", "https-proxy-agent": "^9.1.0",
"js-yaml": "^5.2.0" "js-yaml": "^5.2.2",
"uuid": "^14.0.1"
}, },
"devDependencies": { "devDependencies": {
"@eslint/js": "^9.39.3", "@eslint/js": "^9.39.3",

View File

@@ -77,13 +77,33 @@ export function scopeToConfigDir(registry: string, scope?: string): string {
if (scopeDisabled() || !scope || scope === '') { if (scopeDisabled() || !scope || scope === '') {
return ''; return '';
} }
let configDir = path.join(Buildx.configDir, 'config', registry === 'docker.io' ? 'registry-1.docker.io' : registry); const configRoot = path.resolve(Buildx.configDir, 'config');
if (scope.startsWith('@')) { const registryDir = path.resolve(configRoot, registry === 'docker.io' ? 'registry-1.docker.io' : registry);
configDir += scope; if (!isChildPath(configRoot, registryDir)) {
} else { throw new Error(`Invalid registry '${registry}': resolved config path escapes the Buildx config directory`);
configDir = path.join(configDir, scope);
} }
return configDir; const scopeParts = scope.split('@');
if (scopeParts.length > 2) {
throw new Error(`Invalid scope '${scope}': scope can contain at most one @ separator`);
}
const [scopePath, scopeActions] = scopeParts;
if (scopeActions !== undefined && !/^[a-z]+(,[a-z]+)*$/.test(scopeActions)) {
throw new Error(`Invalid scope '${scope}': scope actions must be lowercase names separated by commas`);
}
const scopeSuffix = scopeActions === undefined ? '' : `@${scopeActions}`;
if (scopePath === '') {
return `${registryDir}${scopeSuffix}`;
}
const configDir = path.resolve(registryDir, scopePath);
if (!isChildPath(registryDir, configDir)) {
throw new Error(`Invalid scope '${scope}': resolved config path escapes the Buildx config directory`);
}
return `${configDir}${scopeSuffix}`;
}
function isChildPath(parent: string, child: string): boolean {
const relativePath = path.relative(parent, child);
return relativePath !== '' && relativePath !== '..' && !relativePath.startsWith(`..${path.sep}`) && !path.isAbsolute(relativePath);
} }
function scopeDisabled(): boolean { function scopeDisabled(): boolean {

View File

@@ -4,12 +4,20 @@ import {Docker} from '@docker/actions-toolkit/lib/docker/docker.js';
import * as aws from './aws.js'; import * as aws from './aws.js';
import * as context from './context.js'; import * as context from './context.js';
import * as dockerhub from './dockerhub.js';
export async function login(auth: context.Auth): Promise<void> { export async function login(auth: context.Auth): Promise<void> {
if (/true/i.test(auth.ecr) || (auth.ecr == 'auto' && aws.isECR(auth.registry))) { if (/true/i.test(auth.ecr) || (auth.ecr == 'auto' && aws.isECR(auth.registry))) {
await loginECR(auth.registry, auth.username, auth.password, auth.scope); await loginECR(auth.registry, auth.username, auth.password, auth.scope);
} else { } else {
await loginStandard(auth.registry, auth.username, auth.password, auth.scope); let username = auth.username;
let password = auth.password;
if (dockerhub.isDockerHubOIDC(auth.registry, password)) {
const credentials = await dockerhub.getOIDCToken(auth.registry, username);
username = credentials.username;
password = credentials.token;
}
await loginStandard(auth.registry, username, password, auth.scope);
} }
} }

126
src/dockerhub.ts Normal file
View File

@@ -0,0 +1,126 @@
import * as core from '@actions/core';
import * as httpm from '@actions/http-client';
import {HttpCodes} from '@actions/http-client';
import {validate as uuidValidate} from 'uuid';
export interface LoginCredentials {
username: string;
token: string;
}
interface OIDCTokenResponse {
access_token: string;
}
const registries = new Set(['', 'docker.io', 'registry-1.docker.io', 'registry-1-stage.docker.io', 'dhi.io']);
const defaultExpiresIn = 300;
const minExpiresIn = 300;
const maxExpiresIn = 21600;
const maxRetries = 5;
export const isDockerHubOIDC = (registry: string, password: string): boolean => {
return process.env.DOCKERHUB_OIDC_CONNECTIONID !== undefined && !password && registries.has(registry);
};
export const getOIDCToken = async (registry: string, username: string): Promise<LoginCredentials> => {
const connectionID = process.env.DOCKERHUB_OIDC_CONNECTIONID?.trim();
if (!connectionID) {
throw new Error('DOCKERHUB_OIDC_CONNECTIONID is required for Docker Hub OIDC login');
}
if (!uuidValidate(connectionID)) {
throw new Error('Invalid DOCKERHUB_OIDC_CONNECTIONID. Must be a valid UUID.');
}
const expiresIn = getExpiresIn();
const identityHost = registry === 'registry-1-stage.docker.io' ? 'identity-stage.docker.com' : 'identity.docker.com';
const audience = `https://${identityHost}`;
const idToken = await core.getIDToken(audience);
const http: httpm.HttpClient = new httpm.HttpClient('github.com/docker/login-action', [], {
headers: {
'Content-Type': 'application/x-www-form-urlencoded'
}
});
const data = new URLSearchParams();
data.set('grant_type', 'urn:ietf:params:oauth:grant-type:token-exchange');
data.set('subject_token_type', 'urn:ietf:params:oauth:token-type:id_token');
data.set('subject_token', idToken);
data.set('connection_id', connectionID);
data.set('expires_in', expiresIn.toString());
const resp = await postWithRetry(http, `https://${identityHost}/oauth/token`, data.toString());
const tokenResp = <OIDCTokenResponse>JSON.parse(await handleResponse(resp));
core.setSecret(tokenResp.access_token);
return {
username,
token: tokenResp.access_token
};
};
const getExpiresIn = (): number => {
const expiresInInput = process.env.DOCKERHUB_OIDC_EXPIREIN?.trim() || defaultExpiresIn.toString();
const expiresIn = Number(expiresInInput);
if (isNaN(expiresIn) || expiresIn < minExpiresIn || expiresIn > maxExpiresIn) {
throw new Error(`Invalid DOCKERHUB_OIDC_EXPIREIN: ${expiresInInput}. Must be between ${minExpiresIn} and ${maxExpiresIn}`);
}
return expiresIn;
};
const postWithRetry = async (http: httpm.HttpClient, url: string, data: string): Promise<httpm.HttpClientResponse> => {
let resp = await http.post(url, data);
for (let attempt = 0; (resp.message.statusCode || HttpCodes.InternalServerError) === HttpCodes.TooManyRequests && attempt < maxRetries; attempt++) {
const delay = parseRetryAfter(resp.message.headers['retry-after']);
if (delay === null) {
break;
}
await resp.readBody();
core.info(`Docker Hub OIDC token request rate limited, retrying in ${delay}ms (attempt ${attempt + 1}/${maxRetries})`);
await new Promise(resolve => setTimeout(resolve, delay));
resp = await http.post(url, data);
}
return resp;
};
const parseRetryAfter = (value: string | string[] | undefined): number | null => {
if (value === undefined) {
return null;
}
if (Array.isArray(value)) {
value = value[0];
}
const seconds = Number(value);
if (isNaN(seconds)) {
return null;
}
return Math.max(0, seconds * 1000);
};
const handleResponse = async (resp: httpm.HttpClientResponse): Promise<string> => {
const body = await resp.readBody();
const statusCode = resp.message.statusCode || HttpCodes.InternalServerError;
if (statusCode < HttpCodes.OK || statusCode >= HttpCodes.MultipleChoices) {
throw parseError(statusCode, body);
}
return body;
};
const parseError = (statusCode: number, body: string): Error => {
if (body) {
let errResp: unknown;
try {
errResp = JSON.parse(body);
} catch {
errResp = undefined;
}
if (errResp !== undefined) {
throw new Error(`Docker Hub API: bad status code ${statusCode}: ${JSON.stringify(errResp)}`);
}
}
if (statusCode === 401) {
throw new Error(`Docker Hub API: operation not permitted`);
}
throw new Error(`Docker Hub API: bad status code ${statusCode}`);
};

470
yarn.lock
View File

@@ -34,9 +34,9 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"@actions/cache@npm:^6.1.0": "@actions/cache@npm:^6.2.0":
version: 6.1.0 version: 6.2.0
resolution: "@actions/cache@npm:6.1.0" resolution: "@actions/cache@npm:6.2.0"
dependencies: dependencies:
"@actions/core": "npm:^3.0.1" "@actions/core": "npm:^3.0.1"
"@actions/exec": "npm:^3.0.0" "@actions/exec": "npm:^3.0.0"
@@ -47,7 +47,7 @@ __metadata:
"@azure/storage-blob": "npm:^12.31.0" "@azure/storage-blob": "npm:^12.31.0"
"@protobuf-ts/runtime-rpc": "npm:^2.11.1" "@protobuf-ts/runtime-rpc": "npm:^2.11.1"
semver: "npm:^7.7.4" semver: "npm:^7.7.4"
checksum: 10/0cd89f335c1e89f514d56060110bfddc6ab1112ec0091533364c32aec2621896112cde71cfc4089b86d00f3b5478996088e4c4e0aba0aec32aae0afeb4921b3d checksum: 10/b2b3d219d3458b6b7e8f47ff6a83a0566f0b3cd5b257e307636d2147f892e595ce8cecbc0675590a57d0eb4d4d73564d08d28753baa50934ad59a65cbee2d8fa
languageName: node languageName: node
linkType: hard linkType: hard
@@ -170,244 +170,244 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/client-ecr-public@npm:^3.1077.0": "@aws-sdk/client-ecr-public@npm:^3.1103.0":
version: 3.1077.0 version: 3.1103.0
resolution: "@aws-sdk/client-ecr-public@npm:3.1077.0" resolution: "@aws-sdk/client-ecr-public@npm:3.1103.0"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.977.6"
"@aws-sdk/credential-provider-node": "npm:^3.972.60" "@aws-sdk/credential-provider-node": "npm:^3.972.78"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.2"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.31.1"
"@smithy/fetch-http-handler": "npm:^5.6.1" "@smithy/fetch-http-handler": "npm:^5.6.13"
"@smithy/node-http-handler": "npm:^4.9.1" "@smithy/node-http-handler": "npm:^4.9.13"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/916cf62d4db13bfcecc8023b26e9cdcc69e1df9c7daa7cbbe8b205998ccb9443251cae24fe3a06f5f20d2fbffee4e400e0714c2963dc75536a3482fd60544f53 checksum: 10/06ee2e2fc40cd0bb245d3e852fadd399f19ef098dd2aa35fd08674d3b4a1f67d0b5c5868178afbd0692aa5dcdc2c3b6d66aae2c696d4eb58bc92378a35f66cb5
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/client-ecr@npm:^3.1077.0": "@aws-sdk/client-ecr@npm:^3.1103.0":
version: 3.1077.0 version: 3.1103.0
resolution: "@aws-sdk/client-ecr@npm:3.1077.0" resolution: "@aws-sdk/client-ecr@npm:3.1103.0"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.977.6"
"@aws-sdk/credential-provider-node": "npm:^3.972.60" "@aws-sdk/credential-provider-node": "npm:^3.972.78"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.2"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.31.1"
"@smithy/fetch-http-handler": "npm:^5.6.1" "@smithy/fetch-http-handler": "npm:^5.6.13"
"@smithy/node-http-handler": "npm:^4.9.1" "@smithy/node-http-handler": "npm:^4.9.13"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/5c70110f9a3cac414701b97710ae40147e1e982ab6239ccd6a839f8726f490b548874fc4e4d968ccc548bdc187cd2864b54c2d3d5ed3bfe32285e555c6a413a8 checksum: 10/9f47b939dfacead51d4607a5a87a36ca6718fa4810594bb5e5247c8ea9257b87d648d3602c44d84f8f023137ab9c5199a06682d4a01b421fdaaf76530196951b
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/core@npm:^3.974.25": "@aws-sdk/core@npm:^3.977.6":
version: 3.974.25 version: 3.977.6
resolution: "@aws-sdk/core@npm:3.974.25" resolution: "@aws-sdk/core@npm:3.977.6"
dependencies: dependencies:
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.2"
"@aws-sdk/xml-builder": "npm:^3.972.32" "@aws-sdk/xml-builder": "npm:^3.972.37"
"@aws/lambda-invoke-store": "npm:^0.2.2" "@aws/lambda-invoke-store": "npm:^0.3.0"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.31.1"
"@smithy/signature-v4": "npm:^5.6.0" "@smithy/signature-v4": "npm:^5.6.12"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
bowser: "npm:^2.11.0" bowser: "npm:^2.11.0"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/25ca1498913983d8f7c2f25485d3c825e9b23a48b15eeac3e695b70fd6393f815f644b4ca11bc8145eff2dec5cbee06360ae7bcf76b5fd9dbb214fd80abe81be checksum: 10/e5c0c4d485156975a63854ede3b880fac7bae31d29d0bfb46120238a2530aed56de782811185fa987fa60a8cf17391ec7c4044d962209034f9259c80b8c07136
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/credential-provider-env@npm:^3.972.51": "@aws-sdk/credential-provider-env@npm:^3.972.67":
version: 3.972.51 version: 3.972.67
resolution: "@aws-sdk/credential-provider-env@npm:3.972.51" resolution: "@aws-sdk/credential-provider-env@npm:3.972.67"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.977.6"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.2"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.31.1"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/3e745169838f44f26828a6c860e32d662d9b52be6d7b63dd2407028b53567fdd24b8a2e92bfb27da73c2f71e07a051a17722bfe0c7dd5a665a0d3f302812a148 checksum: 10/1754d024dcf2dab5afc3b30fc4668ed53780785b1b7a1bb47b12faea0d5a73d8f751443f3f42795cc1a79404e5017f2430b0d10622f270bc07c659363a161429
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/credential-provider-http@npm:^3.972.53": "@aws-sdk/credential-provider-http@npm:^3.972.69":
version: 3.972.53 version: 3.972.69
resolution: "@aws-sdk/credential-provider-http@npm:3.972.53" resolution: "@aws-sdk/credential-provider-http@npm:3.972.69"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.977.6"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.2"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.31.1"
"@smithy/fetch-http-handler": "npm:^5.6.1" "@smithy/fetch-http-handler": "npm:^5.6.13"
"@smithy/node-http-handler": "npm:^4.9.1" "@smithy/node-http-handler": "npm:^4.9.13"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/94247a81a8d0235c3eb14a2e8ac41b70314efa585ca62d0c16c0293f96a2d2f1d0b0ed947d6e15e46d0fdc565725d6d2a37d5e847523995d11f21fe254eb0094 checksum: 10/3258d4878af27062fcee035352975f274e7f0af7558f0e0d2dc0773dde5fbac2ec4c3176bdab9bed70aeca72c5e4e0930943a19d50ce44e6ecc4bea34ab222cb
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/credential-provider-ini@npm:^3.972.58": "@aws-sdk/credential-provider-ini@npm:^3.973.12":
version: 3.972.58 version: 3.973.12
resolution: "@aws-sdk/credential-provider-ini@npm:3.972.58" resolution: "@aws-sdk/credential-provider-ini@npm:3.973.12"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.977.6"
"@aws-sdk/credential-provider-env": "npm:^3.972.51" "@aws-sdk/credential-provider-env": "npm:^3.972.67"
"@aws-sdk/credential-provider-http": "npm:^3.972.53" "@aws-sdk/credential-provider-http": "npm:^3.972.69"
"@aws-sdk/credential-provider-login": "npm:^3.972.57" "@aws-sdk/credential-provider-login": "npm:^3.972.74"
"@aws-sdk/credential-provider-process": "npm:^3.972.51" "@aws-sdk/credential-provider-process": "npm:^3.972.67"
"@aws-sdk/credential-provider-sso": "npm:^3.972.57" "@aws-sdk/credential-provider-sso": "npm:^3.973.11"
"@aws-sdk/credential-provider-web-identity": "npm:^3.972.57" "@aws-sdk/credential-provider-web-identity": "npm:^3.972.73"
"@aws-sdk/nested-clients": "npm:^3.997.25" "@aws-sdk/nested-clients": "npm:^3.997.41"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.2"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.31.1"
"@smithy/credential-provider-imds": "npm:^4.4.4" "@smithy/credential-provider-imds": "npm:^4.4.16"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/d9d0024c120fbe0de0a6436fe7d5fd8056549cfd630f385b389d131417cf06ba6848c56a45b0afad5fdeec6b850d2c1dc91fc165d47a671d904e9e1facd7001b checksum: 10/71689382274efb5e80e2ef31b2d741a10e24c6b2fb1017532939e58e121a9bca6c80a3d83571140eb0e7a7b0e9958b2038aed6d3951fbd61337e45e1521849bd
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/credential-provider-login@npm:^3.972.57": "@aws-sdk/credential-provider-login@npm:^3.972.74":
version: 3.972.57 version: 3.972.74
resolution: "@aws-sdk/credential-provider-login@npm:3.972.57" resolution: "@aws-sdk/credential-provider-login@npm:3.972.74"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.977.6"
"@aws-sdk/nested-clients": "npm:^3.997.25" "@aws-sdk/nested-clients": "npm:^3.997.41"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.2"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.31.1"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/22b24eedad0620c15ed78f6e02a6add822357c778acd452adf76a492a41a6750654aa01bd6a7877ee4cf96968988b305dbaf9a15278989f7960dddb53a11ddd0 checksum: 10/91ab722e9cb46ad498081485ac95626ea9966b18c085fde3d606a7ea19b50e8963777b7ed616d5c4b7c84f24185c90aa347d563b775970a67abd915c2522b127
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/credential-provider-node@npm:^3.972.60": "@aws-sdk/credential-provider-node@npm:^3.972.78":
version: 3.972.60 version: 3.972.78
resolution: "@aws-sdk/credential-provider-node@npm:3.972.60" resolution: "@aws-sdk/credential-provider-node@npm:3.972.78"
dependencies: dependencies:
"@aws-sdk/credential-provider-env": "npm:^3.972.51" "@aws-sdk/credential-provider-env": "npm:^3.972.67"
"@aws-sdk/credential-provider-http": "npm:^3.972.53" "@aws-sdk/credential-provider-http": "npm:^3.972.69"
"@aws-sdk/credential-provider-ini": "npm:^3.972.58" "@aws-sdk/credential-provider-ini": "npm:^3.973.12"
"@aws-sdk/credential-provider-process": "npm:^3.972.51" "@aws-sdk/credential-provider-process": "npm:^3.972.67"
"@aws-sdk/credential-provider-sso": "npm:^3.972.57" "@aws-sdk/credential-provider-sso": "npm:^3.973.11"
"@aws-sdk/credential-provider-web-identity": "npm:^3.972.57" "@aws-sdk/credential-provider-web-identity": "npm:^3.972.73"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.2"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.31.1"
"@smithy/credential-provider-imds": "npm:^4.4.4" "@smithy/credential-provider-imds": "npm:^4.4.16"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/5249e3bf1ded99f207ef8b4c80c4c19ab934115304790916def3f29877061c850e3089f71fd65cca3688327763175837a86f5afa100ef926c9749782ca0b7a44 checksum: 10/402aa3b68bf10b15c9dcf14c7a03a576c757077c3c9d4d593d7deacb648274262e320a3c6626adb772c3a874e1c4bffd59ad66066c639d44dbd01d4e796adfd2
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/credential-provider-process@npm:^3.972.51": "@aws-sdk/credential-provider-process@npm:^3.972.67":
version: 3.972.51 version: 3.972.67
resolution: "@aws-sdk/credential-provider-process@npm:3.972.51" resolution: "@aws-sdk/credential-provider-process@npm:3.972.67"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.977.6"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.2"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.31.1"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/bdbd1dbd6aadbc8737b03ff776fc3b9c8d7c773214f35113ac7cb796f56bbb9ae141cf282b15a5a17b77c5f06133a28fdbd363053772f5aad9021bd08d777e8d checksum: 10/696c7acb3ce40376700da6e59e3365486c6a9083472679aa7d8b5a578818ac6eced954bf8aa5dadd9928c702ea5068af9096b2ae50d9c2ef0d2c30ccab827de4
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/credential-provider-sso@npm:^3.972.57": "@aws-sdk/credential-provider-sso@npm:^3.973.11":
version: 3.972.57 version: 3.973.11
resolution: "@aws-sdk/credential-provider-sso@npm:3.972.57" resolution: "@aws-sdk/credential-provider-sso@npm:3.973.11"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.977.6"
"@aws-sdk/nested-clients": "npm:^3.997.25" "@aws-sdk/nested-clients": "npm:^3.997.41"
"@aws-sdk/token-providers": "npm:3.1077.0" "@aws-sdk/token-providers": "npm:3.1103.0"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.2"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.31.1"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/53fa4e00bcedd8673ac271503dfe452d3c4076ac780bb381012b0f71732511dcb63e83211b544db1f0bedc667925629af5dc5b3b5fa0e8c11372a4211cbf135d checksum: 10/aeabd076d977890c705b7a8c0f56c9ff811fb673f35c9ebcfaf4b7d7fb1b6dbf406470f89c37d91ae6da179130a8e911989a0519f42b8f26b4473b029d59adfc
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/credential-provider-web-identity@npm:^3.972.57": "@aws-sdk/credential-provider-web-identity@npm:^3.972.73":
version: 3.972.57 version: 3.972.73
resolution: "@aws-sdk/credential-provider-web-identity@npm:3.972.57" resolution: "@aws-sdk/credential-provider-web-identity@npm:3.972.73"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.977.6"
"@aws-sdk/nested-clients": "npm:^3.997.25" "@aws-sdk/nested-clients": "npm:^3.997.41"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.2"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.31.1"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/e3db324879b623695584fe4e591a360d930c82dc276fea4d344e537df29c1c821c52886562af51008573d0357e132fe6676a99ac49b545368f8e82ebd94a58f4 checksum: 10/cd1ee1d17c5749dbb889f0c97ba99ade788d916dd605d4277be2932a71387039d47f5630d061d09b2d5b9904244e5bd7b0bfc423a3fc261f8bc85b781058d675
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/nested-clients@npm:^3.997.25": "@aws-sdk/nested-clients@npm:^3.997.41":
version: 3.997.25 version: 3.997.41
resolution: "@aws-sdk/nested-clients@npm:3.997.25" resolution: "@aws-sdk/nested-clients@npm:3.997.41"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.977.6"
"@aws-sdk/signature-v4-multi-region": "npm:^3.996.37" "@aws-sdk/signature-v4-multi-region": "npm:^3.996.43"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.2"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.31.1"
"@smithy/fetch-http-handler": "npm:^5.6.1" "@smithy/fetch-http-handler": "npm:^5.6.13"
"@smithy/node-http-handler": "npm:^4.9.1" "@smithy/node-http-handler": "npm:^4.9.13"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/6e9507477672572d90e7802526f133b9956adb6306f401b51c1f76b55b60e93297943d9927e531cecba63303a157757bfadbf14524e164688a515e351f57d9de checksum: 10/9bb39bbd68da8bc5448a4667cf486a78aaf49a9aebca29324129396e8d48500919736588bf9aa4d86ae560ed6284225a33bfc301aa4a5df63f5635bca40e7969
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/signature-v4-multi-region@npm:^3.996.37": "@aws-sdk/signature-v4-multi-region@npm:^3.996.43":
version: 3.996.37 version: 3.996.43
resolution: "@aws-sdk/signature-v4-multi-region@npm:3.996.37" resolution: "@aws-sdk/signature-v4-multi-region@npm:3.996.43"
dependencies: dependencies:
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.2"
"@smithy/signature-v4": "npm:^5.6.0" "@smithy/signature-v4": "npm:^5.6.12"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/16608054281ae2b29c409ef772572f27d51c05269efc5965bfb2a72405675fb2449087d635f62e9e6438a73cf2edad15c1161287ddb2672ad8f08e8bc598df0a checksum: 10/07a95a47866ae69af40aa36c69a6105e97723aa6aef85daec19e28a7f1a19fb56f999e33c563e8fab8d65098b2f48a6fb309266bea2d60a7e756fd72409b5097
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/token-providers@npm:3.1077.0": "@aws-sdk/token-providers@npm:3.1103.0":
version: 3.1077.0 version: 3.1103.0
resolution: "@aws-sdk/token-providers@npm:3.1077.0" resolution: "@aws-sdk/token-providers@npm:3.1103.0"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.977.6"
"@aws-sdk/nested-clients": "npm:^3.997.25" "@aws-sdk/nested-clients": "npm:^3.997.41"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.2"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.31.1"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/7b026fd9a234c52424dba53c86208143dc87b009efee933cee5522ac815e77ac567cc25fba013df34b3616268697f36737ad47c4a9e274da57519d4c5cf024f4 checksum: 10/211447e0c2298f5cc7e129971ef4b5c8e1e275439106fde4a31c36a59baa50e40dd0f9f40f0a4df49497069fd91804123855f00e8885a3a234336261f7ad4e98
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/types@npm:^3.973.14": "@aws-sdk/types@npm:^3.974.2":
version: 3.973.14 version: 3.974.2
resolution: "@aws-sdk/types@npm:3.973.14" resolution: "@aws-sdk/types@npm:3.974.2"
dependencies: dependencies:
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/2c960877e3d5bb83b81a2974bc8aab86baa83053179e8fb1a77fde223138a64f5e14bc95d20146292af7eed499dd2b38aefd47ae68b5f746828abea8532e96a8 checksum: 10/12a2a3c13507211881d91d9186c0d20b138a569ab8e1937744393d2bcb14dc01257a97de42dd7ef002500a49f0237ce1faeb11e5a9c607d4ad16fd63357cefee
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/xml-builder@npm:^3.972.32": "@aws-sdk/xml-builder@npm:^3.972.37":
version: 3.972.32 version: 3.972.37
resolution: "@aws-sdk/xml-builder@npm:3.972.32" resolution: "@aws-sdk/xml-builder@npm:3.972.37"
dependencies: dependencies:
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/d42371e477fb55823d406fac361bd2288af56284c52265dfeaa60191f90fc4f9105760df23e803fd5e1ea7bb14cd2567bb101e551d06417dad8bbd16568cf452 checksum: 10/20f221d158a12cb39b117e65cde8ecb19f629d5292def76adee8680dad176cf6c9f0e83a3534c65bcd40ffaf5fa8a2afd62de262c4c00b355d1c8c057c261acb
languageName: node languageName: node
linkType: hard linkType: hard
"@aws/lambda-invoke-store@npm:^0.2.2": "@aws/lambda-invoke-store@npm:^0.3.0":
version: 0.2.3 version: 0.3.0
resolution: "@aws/lambda-invoke-store@npm:0.2.3" resolution: "@aws/lambda-invoke-store@npm:0.3.0"
checksum: 10/d0efa8ca73b2d8dc0bf634525eefa1b72cda85f5d47366264849343a6f2860cfa5c52b7f766a16b78da8406bbd3ee975da3abb1dbe38183f8af95413eafeb256 checksum: 10/4a6c7af16477dd330d4dcd2269f89370be68295b54ae1e90ef8c2175efa4df6735f9a3f914ab7efa21ba7db5477031fe8488853adcd268eeb6cb8e34ad06b206
languageName: node languageName: node
linkType: hard linkType: hard
@@ -677,12 +677,12 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"@docker/actions-toolkit@npm:^0.92.0": "@docker/actions-toolkit@npm:^0.94.0":
version: 0.92.0 version: 0.94.0
resolution: "@docker/actions-toolkit@npm:0.92.0" resolution: "@docker/actions-toolkit@npm:0.94.0"
dependencies: dependencies:
"@actions/artifact": "npm:^6.2.1" "@actions/artifact": "npm:^6.2.1"
"@actions/cache": "npm:^6.1.0" "@actions/cache": "npm:^6.2.0"
"@actions/core": "npm:^3.0.1" "@actions/core": "npm:^3.0.1"
"@actions/exec": "npm:^3.0.0" "@actions/exec": "npm:^3.0.0"
"@actions/github": "npm:^9.1.1" "@actions/github": "npm:^9.1.1"
@@ -693,16 +693,16 @@ __metadata:
"@sigstore/tuf": "npm:^5.0.0" "@sigstore/tuf": "npm:^5.0.0"
"@sigstore/verify": "npm:^4.1.0" "@sigstore/verify": "npm:^4.1.0"
async-retry: "npm:^1.3.3" async-retry: "npm:^1.3.3"
csv-parse: "npm:^7.0.0" csv-parse: "npm:^7.0.1"
gunzip-maybe: "npm:^1.4.2" gunzip-maybe: "npm:^1.4.2"
handlebars: "npm:^4.7.9" handlebars: "npm:^4.7.9"
he: "npm:^1.2.0" he: "npm:^1.2.0"
js-yaml: "npm:^5.2.0" js-yaml: "npm:^5.2.1"
jwt-decode: "npm:^4.0.0" jwt-decode: "npm:^4.0.0"
semver: "npm:^7.8.5" semver: "npm:^7.8.5"
tar-stream: "npm:^3.2.0" tar-stream: "npm:^3.2.0"
tmp: "npm:^0.2.7" tmp: "npm:^0.2.7"
checksum: 10/599cea84b897069c53744a2f05371c6d9ad60da18448b4431273529b92fd2d77ddc718ee205cf0bf1da53083d412da90b1067f1e64a5fdac73fe71d486726064 checksum: 10/96f7b3e488dd50db0b77575e1a2bd7e92506b1a2695d5c31a57d361e4dc07871ef1a14a7ab87bf6fe27af2f817d34351c2e289446b126675a20d9776fe5ab8ce
languageName: node languageName: node
linkType: hard linkType: hard
@@ -1956,66 +1956,66 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"@smithy/core@npm:^3.28.0": "@smithy/core@npm:^3.31.1":
version: 3.28.0 version: 3.31.1
resolution: "@smithy/core@npm:3.28.0" resolution: "@smithy/core@npm:3.31.1"
dependencies: dependencies:
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/b8fe9db961112b8dd36b48c9d692d0cbe83be3a5962b51874f52079a22595674a9bc30c01bb3868da74e0c9ab328cac1f71405982432434be3e5d9d57777b5d7 checksum: 10/4a66d0f1f6b6aac8cbe424d0c9c6ca12e02b8b64c21065de396b60c203f163e245000e4607f02d1a8391028a669a78b666843dc5769af4c8f0101afd6858aba0
languageName: node languageName: node
linkType: hard linkType: hard
"@smithy/credential-provider-imds@npm:^4.4.4": "@smithy/credential-provider-imds@npm:^4.4.16":
version: 4.4.4 version: 4.4.16
resolution: "@smithy/credential-provider-imds@npm:4.4.4" resolution: "@smithy/credential-provider-imds@npm:4.4.16"
dependencies: dependencies:
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.31.1"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/47950acf6e89480592466fec4e7e5d6eed8ff9b939d76ef83a584b39067c593ce06df2616f354fda084b284af1406ac9a82d759a38623066b28ad7efe05a736b checksum: 10/5a9d54b151ec9296db79f52e68c8fd1feddd4d75332f13dad0dc5efe2aabe3994092193ea532c2cb3e5133f099a650accbd2ff836b4aba916b96d0d796766a0c
languageName: node languageName: node
linkType: hard linkType: hard
"@smithy/fetch-http-handler@npm:^5.6.1": "@smithy/fetch-http-handler@npm:^5.6.13":
version: 5.6.1 version: 5.6.13
resolution: "@smithy/fetch-http-handler@npm:5.6.1" resolution: "@smithy/fetch-http-handler@npm:5.6.13"
dependencies: dependencies:
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.31.1"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/e7a841ef750fcfd936e274cd1bd011d0749328d7597e9d5ba8ed286be883fde25e6629315428502aec343c072c826ed512dd26a08ee33609884812cbbc1e2d84 checksum: 10/272d367031096802c8ea7c8e7479e7522589018628064e01b5d101316091687eaa48b4029543e0a11486db6ec4ffbcd9a9ac26923f0a655150e33fe9e085e3ca
languageName: node languageName: node
linkType: hard linkType: hard
"@smithy/node-http-handler@npm:^4.9.1": "@smithy/node-http-handler@npm:^4.9.13":
version: 4.9.1 version: 4.9.13
resolution: "@smithy/node-http-handler@npm:4.9.1" resolution: "@smithy/node-http-handler@npm:4.9.13"
dependencies: dependencies:
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.31.1"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/d12b489b301b71767036a33c3c6736f4f37ea5ae8f147b054acbebaf3a5b02df05cba38b764813fa0cd24cde3c3faa22842bda31e0840bb4d79dd737f801d82e checksum: 10/d52fac160d879b957c8092c70e9991c23a3775bb448a8c6d5836873afab1f5ea43dd72c63150da748879b29443f0af7f83fb777763975a81939e8806e18ba71a
languageName: node languageName: node
linkType: hard linkType: hard
"@smithy/signature-v4@npm:^5.6.0": "@smithy/signature-v4@npm:^5.6.12":
version: 5.6.0 version: 5.6.12
resolution: "@smithy/signature-v4@npm:5.6.0" resolution: "@smithy/signature-v4@npm:5.6.12"
dependencies: dependencies:
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.31.1"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.16.1"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/e4036321b89bc522d2c1edad6e70151c155dc0e4780a0d828cfdf941d5f8a871fda50912e7b9ed87172916761e84e50030b05f020523873232877b3f814f0b8c checksum: 10/0a14dac2c93118eb5fabdb34c8e3dd042fb645be959a6546e67c6b3d181a3df8f13ef210a8c2b9811371b8b0fc846d9e15e9bb3076bcb1c019e830f924fba60a
languageName: node languageName: node
linkType: hard linkType: hard
"@smithy/types@npm:^4.15.0": "@smithy/types@npm:^4.16.1":
version: 4.15.0 version: 4.16.1
resolution: "@smithy/types@npm:4.15.0" resolution: "@smithy/types@npm:4.16.1"
dependencies: dependencies:
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/e41a84ec3eb9feb45040ccd541b1cacf0fc2375297802886459cb9311ff361080978c08ef98e9ad69f41d80ad212279d682a8fe30a993381b2f1dd376c1006c3 checksum: 10/23651203f2e8800b2b2311ef163ddec166d91e15b30fa1c877be352aeef8ae7cc7b0189f99e07b0dcd52160b10adfb3fa4ca32c38a2d7195fc5428b8986d5201
languageName: node languageName: node
linkType: hard linkType: hard
@@ -2762,12 +2762,12 @@ __metadata:
linkType: hard linkType: hard
"brace-expansion@npm:^1.1.7": "brace-expansion@npm:^1.1.7":
version: 1.1.13 version: 1.1.16
resolution: "brace-expansion@npm:1.1.13" resolution: "brace-expansion@npm:1.1.16"
dependencies: dependencies:
balanced-match: "npm:^1.0.0" balanced-match: "npm:^1.0.0"
concat-map: "npm:0.0.1" concat-map: "npm:0.0.1"
checksum: 10/b5f4329fdbe9d2e25fa250c8f866ebd054ba946179426e99b86dcccddabdb1d481f0e40ee5430032e62a7d0a6c2837605ace6783d015aa1d65d85ca72154d936 checksum: 10/94498bead66c51536df5b7bf1b0a0e581a5b7f86888be10481d06920c4bd9d976e003b13a3d19fddc733f21a09d162ff72f90e18b2c9d062b15121e973d0e13b
languageName: node languageName: node
linkType: hard linkType: hard
@@ -3103,10 +3103,10 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"csv-parse@npm:^7.0.0": "csv-parse@npm:^7.0.1":
version: 7.0.0 version: 7.0.1
resolution: "csv-parse@npm:7.0.0" resolution: "csv-parse@npm:7.0.1"
checksum: 10/53c96e6b4ff80047713bb4d2967d06495890d4b628284a80271860be089fdb5a74cd97c76fd535a00ad26b11cc6e4fc5a243658e5377c0a6334ddd104620d169 checksum: 10/5c914f01181dbb381068b98e17b49361d853faa95db3e8e82bc96b6a0de5313ecc8325a77db35ff66644d7747099965ba3167ec21bd9ce4500edf21b5bdd49bf
languageName: node languageName: node
linkType: hard linkType: hard
@@ -3155,9 +3155,10 @@ __metadata:
resolution: "docker-login@workspace:." resolution: "docker-login@workspace:."
dependencies: dependencies:
"@actions/core": "npm:^3.0.1" "@actions/core": "npm:^3.0.1"
"@aws-sdk/client-ecr": "npm:^3.1077.0" "@actions/http-client": "npm:^4.0.1"
"@aws-sdk/client-ecr-public": "npm:^3.1077.0" "@aws-sdk/client-ecr": "npm:^3.1103.0"
"@docker/actions-toolkit": "npm:^0.92.0" "@aws-sdk/client-ecr-public": "npm:^3.1103.0"
"@docker/actions-toolkit": "npm:^0.94.0"
"@eslint/js": "npm:^9.39.3" "@eslint/js": "npm:^9.39.3"
"@types/js-yaml": "npm:^4.0.9" "@types/js-yaml": "npm:^4.0.9"
"@types/node": "npm:^24.11.0" "@types/node": "npm:^24.11.0"
@@ -3173,9 +3174,10 @@ __metadata:
globals: "npm:^17.3.0" globals: "npm:^17.3.0"
http-proxy-agent: "npm:^9.1.0" http-proxy-agent: "npm:^9.1.0"
https-proxy-agent: "npm:^9.1.0" https-proxy-agent: "npm:^9.1.0"
js-yaml: "npm:^5.2.0" js-yaml: "npm:^5.2.2"
prettier: "npm:^3.8.1" prettier: "npm:^3.8.1"
typescript: "npm:^5.9.3" typescript: "npm:^5.9.3"
uuid: "npm:^14.0.1"
vitest: "npm:^4.0.18" vitest: "npm:^4.0.18"
languageName: unknown languageName: unknown
linkType: soft linkType: soft
@@ -4344,14 +4346,25 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"js-yaml@npm:^5.2.0": "js-yaml@npm:^5.2.1":
version: 5.2.0 version: 5.2.1
resolution: "js-yaml@npm:5.2.0" resolution: "js-yaml@npm:5.2.1"
dependencies: dependencies:
argparse: "npm:^2.0.1" argparse: "npm:^2.0.1"
bin: bin:
js-yaml: bin/js-yaml.mjs js-yaml: bin/js-yaml.mjs
checksum: 10/8a5e55c5d0fcafae4ac02114a99dc070048b8e5a82a056089ce1f69f8a00fd8eb05b622e76ad50aac1f9d409010636c9616c6b2ed4e58dae138379a60d301220 checksum: 10/e1eca2d21c15572585bb236d9fde31d6789eb50b9c63e8753fa7e0777bc480f7521cad517bd7a0c66f27dfc27ddcd7100beeefa51c1a50e10e98f2e009633c3d
languageName: node
linkType: hard
"js-yaml@npm:^5.2.2":
version: 5.2.2
resolution: "js-yaml@npm:5.2.2"
dependencies:
argparse: "npm:^2.0.1"
bin:
js-yaml: bin/js-yaml.mjs
checksum: 10/2b4c2933af12c97e1c4894a4f27fe9b06dab70a64a96bb50624b4429bef6bf11008bde20d868bce52a36784473314efc30078ba6025b58cf7537961e23b1ae9c
languageName: node languageName: node
linkType: hard linkType: hard
@@ -4851,12 +4864,12 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"nanoid@npm:^3.3.11": "nanoid@npm:^3.3.16":
version: 3.3.11 version: 3.3.16
resolution: "nanoid@npm:3.3.11" resolution: "nanoid@npm:3.3.16"
bin: bin:
nanoid: bin/nanoid.cjs nanoid: bin/nanoid.cjs
checksum: 10/73b5afe5975a307aaa3c95dfe3334c52cdf9ae71518176895229b8d65ab0d1c0417dd081426134eb7571c055720428ea5d57c645138161e7d10df80815527c48 checksum: 10/8004af92b5541af1dbd23b69845b5026f777d5b7ef07163cea1837aae86e052ced8b383cecbf8a4f1b5e77ae207df96dc45e16b9e0fa3c4b761d085f1e42851b
languageName: node languageName: node
linkType: hard linkType: hard
@@ -5279,13 +5292,13 @@ __metadata:
linkType: hard linkType: hard
"postcss@npm:^8.5.6": "postcss@npm:^8.5.6":
version: 8.5.10 version: 8.5.22
resolution: "postcss@npm:8.5.10" resolution: "postcss@npm:8.5.22"
dependencies: dependencies:
nanoid: "npm:^3.3.11" nanoid: "npm:^3.3.16"
picocolors: "npm:^1.1.1" picocolors: "npm:^1.1.1"
source-map-js: "npm:^1.2.1" source-map-js: "npm:^1.2.1"
checksum: 10/7eac6169e535b63c8412e94d4f6047fc23efa3e9dde804b541940043c831b25f1cd867d83cd2c4371ad2450c8abcb42c208aa25668c1f0f3650d7f72faf711a8 checksum: 10/7944444f267f2d94c7caeed66f3da56d5b947bd4a7e57a166a5161af25c6006dd73f40e2a1a6822f3d7fccc2fa005778c03058368eb7efca1b5038aec55abd14
languageName: node languageName: node
linkType: hard linkType: hard
@@ -6300,6 +6313,15 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"uuid@npm:^14.0.1":
version: 14.0.1
resolution: "uuid@npm:14.0.1"
bin:
uuid: dist-node/bin/uuid
checksum: 10/0f978fd5b0269d7acb615342aeb131f0b8d85eeb8ec34f2915d906baa3befcc14a079a430d0f8116aec6fd20c850cbfab65d1b3d1643fa81ed373c0cf9574f18
languageName: node
linkType: hard
"validate-npm-package-name@npm:^7.0.0": "validate-npm-package-name@npm:^7.0.0":
version: 7.0.2 version: 7.0.2
resolution: "validate-npm-package-name@npm:7.0.2" resolution: "validate-npm-package-name@npm:7.0.2"