Skip to content

build(deps): Bump docker/build-push-action from 7.2.0 to 7.3.0 - #1379

Merged
lklimek merged 1 commit into
v1.6-devfrom
dependabot/github_actions/docker/build-push-action-7.3.0
Jul 28, 2026
Merged

lklimek merged 1 commit into
v1.6-devfrom
dependabot/github_actions/docker/build-push-action-7.3.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 7, 2026

Copy link
Copy Markdown
Contributor

Bumps docker/build-push-action from 7.2.0 to 7.3.0.

Release notes

Sourced from docker/build-push-action's releases.

v7.3.0

Full Changelog: docker/build-push-action@v7.2.0...v7.3.0

Commits
  • 53b7df9 Merge pull request #1572 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 154298c [dependabot skip] chore: update generated content
  • cb1238b chore(deps): Bump @​docker/actions-toolkit from 0.91.0 to 0.92.0
  • 24f845d Merge pull request #1566 from docker/dependabot/npm_and_yarn/js-yaml-4.2.0
  • 9c69730 [dependabot skip] chore: update generated content
  • bc3a3a5 Merge pull request #1574 from docker/dependabot/github_actions/aws-actions/co...
  • a82c504 chore(deps): Bump js-yaml from 4.1.1 to 4.3.0
  • 0285a75 Merge pull request #1573 from docker/dependabot/github_actions/actions/cache-...
  • c6ad2a3 Merge pull request #1575 from docker/dependabot/github_actions/actions/checko...
  • d37484f Merge pull request #1564 from docker/dependabot/npm_and_yarn/undici-6.27.0
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code labels Jul 7, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code labels Jul 7, 2026
@lklimek

lklimek commented Jul 28, 2026

Copy link
Copy Markdown
Collaborator

Dependency security review — docker/build-push-action 7.2.0 → 7.3.0

Verdict: SAFE — recommend merge. Net security posture improves.

3 call sites: .github/workflows/docker.yml (lines 89, 105) and .github/workflows/e2e.yml (line 56). ~74 upstream commits (f9f3042 → 53b7df9).

What actually changed

The hand-written source diff is 2 lines:

  • src/context.ts — the secrets input is now parsed with {ignoreComma: true, trimWhitespace: false}, preserving trailing whitespace in secret values (correctness fix for e.g. SSH keys). We pass no secrets input anywhere, so no impact.
  • package.json — esbuild --keep-names, @docker/actions-toolkit 0.90.0→0.92.0, yarn 4.9.2→4.15.0.

Everything else is generated dist/, the lockfile, and upstream's own CI.

Known vulnerabilities

docker/build-push-action itself: no OSV/GHSA advisories. Bundled npm deps, verified against dist/licenses.txt rather than just the release notes:

Dep 7.2.0 → 7.3.0 Advisory status
tmp 0.2.5 → 0.2.7 Fixes GHSA-ph9p-34f9-6g65 / CVE-2026-44705 (HIGH, path traversal via prefix/postfix)
undici 6.24.1/6.25.0 → 6.27.0 Fixes GHSA-vxpw-j846-p89q / CVE-2026-12151 (HIGH, WebSocket fragment-count DoS) + 3 lower-severity. Now clean.
@sigstore/core 3.1.0/3.2.0 → 4.0.1 Fixes GHSA-jfc7-64v2-mr8c / CVE-2026-48758 (MOD, DSSE payloadType type-binding). Now clean.
js-yaml 4.1.1 → 5.2.0 Sheds CVE-2026-59869 + CVE-2026-53550; 5.2.0 carries GHSA-pm4m-ph32-ghv5 (HIGH, fixed 5.2.2) and GHSA-724g-mxrg-4qvm / CVE-2026-59870 (MOD, fixed 5.2.1)
@sigstore/bundle 4→5, @sigstore/tuf 4→5, @sigstore/verify 3.1→4.1, tuf-js 4.1→6.0, csv-parse 6→7 major bumps no advisories

Correction to the Dependabot release notes: they list js-yaml 4.1.1→4.3.0, but that is the dev-only path (eslint/cosmiconfig). The runtime bundle actually jumps to js-yaml 5.2.0, pulled in by @docker/actions-toolkit 0.92.0.

Those js-yaml advisories are not reachable. @docker/actions-toolkit imports js-yaml as import {dump as yamldump} (src/github/summary.ts, the only import site in the package); both advisories require load()/loadAll() on untrusted input. Both were also published (2026-07-20, 2026-07-24) after v7.3.0 shipped (2026-07-01), so this is not upstream negligence — expect 7.3.1 to pick up 5.2.2.

Bundle integrity checks (all clean)

  • dist/index.cjs diff is only 512 lines; the --keep-names rebundle did not balloon it.
  • Every URL/domain in added lines (sigstore, Azure, GitHub, oci.dag.dev, localhost stubs) already existed in v7.2.0 — no new network destinations.
  • eval( / new Function( / child_process / atob( counts are symmetric between removed and added lines — no new dynamic-execution or decode capability.
  • The dependency tree shrank: cacache, minipass*, socks-proxy-agent, socks, ssri, glob, https-proxy-agent, ip-address all dropped. The sigstore refactor also dropped the in-process @sigstore/sign DSSE builder and hardcoded Fulcio/Rekor/TSA URLs.
  • Upstream hardening in this range: .yarnrc.yml gains enableScripts: false + npmMinimalAgeGate: 2d, new .github/zizmor.yml, least-privilege permissions: on their e2e workflow, OIDC replacing static AWS creds.

Our usage

Concern Status
secrets / secret-envs / secret-files inputs Not used → the whitespace change is a no-op
Credential exposure on PRs docker.yml triggers only on release: published / workflow_dispatch, so DOCKERHUB_TOKEN is never exposed to PR runs. e2e.yml uses pull_request (not pull_request_target) with push: false. Good.
Tag pinning @v7.3.0 is an exact version tag and GitHub reports the release as immutable: true — the tag cannot be repointed. This substantially defuses the usual "pin by SHA" argument here.
tmp path traversal Context.tmpName() options are hardcoded by the toolkit; we never supply prefix/postfix. Not exploitable.

Notes / follow-ups (not blocking, not introduced by this PR)

  1. CI confidence caveat: the e2e-test jobs finished in ~24s because technote-space/get-diff-action short-circuits when no .go/Dockerfile changed — so the build-push-action@v7.3.0 step did not actually execute in this PR's CI. Green checks here do not prove the new version works; it will be exercised on the next Go-touching PR.
  2. .github/workflows/docker.yml:34 — docker/setup-qemu-action@master is pinned to a moving branch, in the job holding DOCKERHUB_TOKEN. Weakest link in that workflow; pin it.
  3. .github/workflows/docker.yml:69 — docker/metadata-action@v6 is a floating major tag with no immutable release behind it.
  4. .github/actions/bls/action.yml:16 — actions/setup-go@v2 is very stale.
  5. Neither docker.yml nor e2e.yml declares a permissions: block, so both inherit repo-default GITHUB_TOKEN scope. permissions: contents: read would be the fix — upstream just did exactly this to their own workflows. zizmor (which upstream adopted) is a good linter for all of the above.

Merging.

🤖 Co-authored by Claudius the Magnificent AI Agent

Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 7.2.0 to 7.3.0.
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@v7.2.0...v7.3.0)

---
updated-dependencies:
- dependency-name: docker/build-push-action
  dependency-version: 7.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@lklimek
lklimek force-pushed the dependabot/github_actions/docker/build-push-action-7.3.0 branch from 274f374 to 7c3169c Compare July 28, 2026 15:55
@lklimek

lklimek commented Jul 28, 2026

Copy link
Copy Markdown
Collaborator

Merge status: blocked by an unrelated, pre-existing CI failure

The security review above stands (SAFE), but this PR cannot be merged right now.

gh pr merge is refused by the base-branch policy because the branch was behind v1.6-dev. I rebased it (gh pr update-branch --rebase), which triggered a fresh CI run — and on that run govulncheck fails:

Vulnerability #1: GO-2026-6061
  Module: google.golang.org/grpc
    Found in: google.golang.org/grpc@v1.82.0
    Fixed in: google.golang.org/grpc@v1.82.1
Your code is affected by 1 vulnerability from 1 module.

This is not caused by this PR — it is a repo-wide, pre-existing failure. govulncheck is already red on v1.6-dev itself (runs 30374690769 and 30373884417), and go.mod on the base branch pins google.golang.org/grpc v1.82.0. The bump here touches only .github/workflows/*.yml and cannot affect a Go vulnerability scan; the earlier green run on this PR simply predates the disclosure of GO-2026-6061.

The unblocker is #1392 (Bump google.golang.org/grpc from 1.82.0 to 1.82.1), which lands exactly the fixed version. Once that merges to v1.6-dev and this branch is updated, this PR should go green and can be merged.

I am deliberately not using --admin to bypass the failing required check — a red vulnerability scan is a legitimate gate, even when the finding is inherited from the base branch.

🤖 Co-authored by Claudius the Magnificent AI Agent

@lklimek
lklimek merged commit 6ac8675 into v1.6-dev Jul 28, 2026
18 of 19 checks passed
@lklimek
lklimek deleted the dependabot/github_actions/docker/build-push-action-7.3.0 branch July 28, 2026 16:13
@lklimek

lklimek commented Jul 28, 2026

Copy link
Copy Markdown
Collaborator

Correction — merged

Follow-up to my previous comment: govulncheck turns out not to be a required status check on v1.6-dev, so it was not the blocker. The actual block was simply that the post-rebase CI run had not finished yet — once the required checks completed the PR went to UNSTABLE (mergeable, with only the non-required govulncheck red) and it merged normally, with no --admin bypass.

The GO-2026-6061 finding still stands as a real, separate issue on v1.6-dev — #1392 (google.golang.org/grpc 1.82.0 → 1.82.1) is the fix and is worth prioritising, since govulncheck will stay red on every PR until it lands.

🤖 Co-authored by Claudius the Magnificent AI Agent

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant