bharos opened a new pull request, #13497: URL: https://github.com/apache/gravitino/pull/13497
Direct backport of #13496 to `branch-1.3`, opened in parallel rather than waiting for main's CI so 1.3.1-rc3 isn't serialised behind two full CI cycles (per Jerry's suggestion). ### What changes were proposed in this pull request? Bump `docker/login-action` from `650006c6` (v4.2.0) to `dbcb8138` (v4.6.0) in `.github/workflows/docker-image.yml`. Identical one-line change to #13496. ### Why are the changes needed? ASF Infra's daily "Remove Expired Refs" job ([apache/infrastructure-actions@3f48e927](https://github.com/apache/infrastructure-actions/commit/3f48e927), 2026-09-24 02:27 UTC) expired `docker/login-action@650006c6` from the actions allowlist. All dispatches of `docker-image.yml` now fail at startup with: > The action docker/login-action@650006c6... is not allowed in apache/gravitino This blocked the image publish for 1.3.1-rc2 and blocks any image build from `branch-1.3`. v4.6.0 is the only allowlisted revision of this action with no `expires_at` date; the older entries are all already scheduled to expire (v4.3.0 on 2026-09-27, v4.5.2 on 2026-10-22). `setup-qemu-action` and `setup-buildx-action` remain allowlisted at their current pins and are unchanged. ### Does this PR introduce any user-facing change? No. CI only. ### How was this patch tested? - Confirmed `dbcb813823bdd20940b903addbd779551569679f` is in `apache/infrastructure-actions/approved_patterns.yml` and the previous SHA is not. - Confirmed the SHA resolves to `docker/login-action` v4.6.0. - Compared `action.yml` at the old and new SHAs: inputs are identical (`registry`, `username`, `password`, `ecr`, `scope`, `logout`, `registry-auth`), so the workflow's `username`/`password` usage is unaffected. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
