This is an automated email from the ASF dual-hosted git repository.

jerryshao pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/gravitino.git


The following commit(s) were added to refs/heads/main by this push:
     new d315d86452 [MINOR] fix(ci): bump docker/login-action to an allowlisted 
SHA (#13496)
d315d86452 is described below

commit d315d864527b9598477e90eb032b00070a4cbb36
Author: Bharath Krishna <[email protected]>
AuthorDate: Wed Sep 23 22:53:38 2026 -0700

    [MINOR] fix(ci): bump docker/login-action to an allowlisted SHA (#13496)
    
    ### What changes were proposed in this pull request?
    
    Bump `docker/login-action` from `650006c6` (v4.2.0) to `dbcb8138`
    (v4.6.0) in `.github/workflows/docker-image.yml`.
    
    ### Why are the changes needed?
    
    ASF Infra's daily "Remove Expired Refs" job
    
([apache/infrastructure-actions@3f48e927](https://github.com/apache/infrastructure-actions/commit/3f48e927),
    2026-09-24 02:27 UTC) expired `docker/login-action@650006c6` from the
    actions allowlist. Every dispatch of `docker-image.yml` now fails at
    startup with:
    
    > The action docker/login-action@650006c6... is not allowed in
    apache/gravitino
    
    This blocks all Gravitino image builds on `main` and `branch-1.3`, and
    it blocked the image publish for 1.3.1-rc2.
    
    v4.6.0 is chosen because it is the current release and the only
    allowlisted revision of this action with no `expires_at` date. Every
    older entry is already scheduled to expire (v4.3.0 on 2026-09-27, v4.5.2
    on 2026-10-22), so pinning any of them would reintroduce this failure
    within weeks.
    
    `setup-qemu-action` and `setup-buildx-action` are still allowlisted at
    their current pins and are left unchanged.
    
    ### Does this PR introduce any user-facing change?
    
    No. CI only.
    
    ### How was this patch tested?
    
    - Confirmed `dbcb813823bdd20940b903addbd779551569679f` is present in
    `apache/infrastructure-actions/approved_patterns.yml`, and that the
    previous SHA is not.
    - Confirmed the SHA resolves to `docker/login-action` v4.6.0.
    - Compared `action.yml` at the old and new SHAs: inputs are identical
    (`registry`, `username`, `password`, `ecr`, `scope`, `logout`,
    `registry-auth`), so the workflow's `username`/`password` usage is
    unaffected.
    
    Follow-up worth considering separately: enabling Dependabot for the
    `github-actions` ecosystem, which ASF's [GitHub Actions
    policy](https://infra.apache.org/github-actions-policy.html) recommends
    and which would refresh pins before they expire.
---
 .github/workflows/docker-image.yml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/.github/workflows/docker-image.yml 
b/.github/workflows/docker-image.yml
index 9b879557d2..da910f309a 100644
--- a/.github/workflows/docker-image.yml
+++ b/.github/workflows/docker-image.yml
@@ -130,7 +130,7 @@ jobs:
         uses: 
docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0
 
       - name: Login to Docker Hub
-        uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # 
v4.2.0
+        uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # 
v4.6.0
         with:
           username: ${{ github.event.inputs.username }}
           password: ${{ secrets.DOCKER_REPOSITORY_PASSWORD }}

Reply via email to