This is an automated email from the ASF dual-hosted git repository.
jerryshao pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/gravitino.git
The following commit(s) were added to refs/heads/main by this push:
new d315d86452 [MINOR] fix(ci): bump docker/login-action to an allowlisted
SHA (#13496)
d315d86452 is described below
commit d315d864527b9598477e90eb032b00070a4cbb36
Author: Bharath Krishna <[email protected]>
AuthorDate: Wed Sep 23 22:53:38 2026 -0700
[MINOR] fix(ci): bump docker/login-action to an allowlisted SHA (#13496)
### What changes were proposed in this pull request?
Bump `docker/login-action` from `650006c6` (v4.2.0) to `dbcb8138`
(v4.6.0) in `.github/workflows/docker-image.yml`.
### Why are the changes needed?
ASF Infra's daily "Remove Expired Refs" job
([apache/infrastructure-actions@3f48e927](https://github.com/apache/infrastructure-actions/commit/3f48e927),
2026-09-24 02:27 UTC) expired `docker/login-action@650006c6` from the
actions allowlist. Every dispatch of `docker-image.yml` now fails at
startup with:
> The action docker/login-action@650006c6... is not allowed in
apache/gravitino
This blocks all Gravitino image builds on `main` and `branch-1.3`, and
it blocked the image publish for 1.3.1-rc2.
v4.6.0 is chosen because it is the current release and the only
allowlisted revision of this action with no `expires_at` date. Every
older entry is already scheduled to expire (v4.3.0 on 2026-09-27, v4.5.2
on 2026-10-22), so pinning any of them would reintroduce this failure
within weeks.
`setup-qemu-action` and `setup-buildx-action` are still allowlisted at
their current pins and are left unchanged.
### Does this PR introduce any user-facing change?
No. CI only.
### How was this patch tested?
- Confirmed `dbcb813823bdd20940b903addbd779551569679f` is present in
`apache/infrastructure-actions/approved_patterns.yml`, and that the
previous SHA is not.
- Confirmed the SHA resolves to `docker/login-action` v4.6.0.
- Compared `action.yml` at the old and new SHAs: inputs are identical
(`registry`, `username`, `password`, `ecr`, `scope`, `logout`,
`registry-auth`), so the workflow's `username`/`password` usage is
unaffected.
Follow-up worth considering separately: enabling Dependabot for the
`github-actions` ecosystem, which ASF's [GitHub Actions
policy](https://infra.apache.org/github-actions-policy.html) recommends
and which would refresh pins before they expire.
---
.github/workflows/docker-image.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/.github/workflows/docker-image.yml
b/.github/workflows/docker-image.yml
index 9b879557d2..da910f309a 100644
--- a/.github/workflows/docker-image.yml
+++ b/.github/workflows/docker-image.yml
@@ -130,7 +130,7 @@ jobs:
uses:
docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0
- name: Login to Docker Hub
- uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee #
v4.2.0
+ uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f #
v4.6.0
with:
username: ${{ github.event.inputs.username }}
password: ${{ secrets.DOCKER_REPOSITORY_PASSWORD }}