dependabot[bot]
d348a9f67d
build(deps): bump github/codeql-action/upload-sarif
...
Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ) from 4.37.5 to 4.37.6.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](d1ba80a13d...5595ccaf91 )
---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.37.6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-08-13 15:26:59 +02:00
Guillaume Lours
f7585f5998
ci: grant actions:write to PR review workflow
...
docker-agent-action v2.0.3 raised the review job's required permission
from actions:read to actions:write (cache delete for review-lock
release, feedback artifact management). GitHub refuses to start a
reusable workflow requesting more permissions than the caller grants,
so every PR Review run since the v2.0.3 bump ended in startup_failure
and docker-agent stopped launching automatically.
Signed-off-by: Guillaume Lours <glours@users.noreply.github.com>
2026-08-13 14:52:12 +02:00
Nicolas De Loof
c936d76faa
ci: run e2e matrix with and without the containerd image store
...
Several image-identity bugs only manifest on one image store backend:
the graphdriver and containerd stores report different digest kinds and
resolve them differently (#14005 , #14007 , #14014 all reproduce only
under the containerd store, which no CI job covered). Cross the stable
e2e jobs with a store axis (graphdriver/containerd) so both backends
are exercised in plugin and standalone modes; oldstable jobs stay on
the default graphdriver.
Signed-off-by: Nicolas De Loof <nicolas.deloof@gmail.com>
2026-08-13 12:03:29 +02:00
Guillaume Lours
d98c41ba07
ci(e2e): run e2e against the containerd image store
...
The e2e suite only ran on graphdriver daemons, where the different kinds
of image digests coincide — the blind spot that let #13636 , #13998 and
#14005 through. Add one matrix entry enabling the containerd image store,
plus TestUpIdempotentContainerdStore: two consecutive `up` runs with no
change must not recreate any container. The test is red on this
configuration (the com.docker.compose.image label is written from the
index digest on the pulling run, then compared against the per-platform
manifest digest on the next run) and skipped until the next commit
resolves the pull-path digest.
Signed-off-by: Guillaume Lours <glours@users.noreply.github.com>
2026-08-13 12:03:29 +02:00
Nicolas De Loof
a53594adb2
ci: block merge while a PR contains AI_AGENT_DISCLOSURE.md
...
The disclosure file added by AI agents states the change may not have
been independently reviewed or tested by its human submitter. It is
meant as a checkpoint, not something to merge: fail a PR check while
the file is present, telling the contributor to review the code their
agent produced and remove the file to confirm that manual review.
Signed-off-by: Nicolas De Loof <nicolas.deloof@gmail.com>
2026-08-13 09:26:35 +02:00
dependabot[bot]
be30fb4dd1
build(deps): bump docker/github-builder/.github/workflows/bake.yml
...
Bumps the docker-actions group with 1 update: [docker/github-builder/.github/workflows/bake.yml](https://github.com/docker/github-builder ).
Updates `docker/github-builder/.github/workflows/bake.yml` from 1.15.0 to 1.16.0
- [Release notes](https://github.com/docker/github-builder/releases )
- [Commits](27ade872c1...a492c6d04f )
---
updated-dependencies:
- dependency-name: docker/github-builder/.github/workflows/bake.yml
dependency-version: 1.16.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: docker-actions
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-08-12 15:37:23 +02:00
dependabot[bot]
6a59c98de1
build(deps): bump github/codeql-action/upload-sarif
...
Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ) from 4.37.4 to 4.37.5.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](f205ea1c33...d1ba80a13d )
---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.37.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-08-11 08:02:48 +02:00
dependabot[bot]
fc209c8f44
build(deps): bump github/codeql-action/upload-sarif
...
Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ) from 4.37.3 to 4.37.4.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](e4fba868fa...f205ea1c33 )
---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.37.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-08-10 08:32:14 +02:00
dependabot[bot]
7e20f3bb26
build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4
...
Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action ) from 2.4.3 to 2.4.4.
- [Release notes](https://github.com/ossf/scorecard-action/releases )
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md )
- [Commits](4eaacf0543...2d1146689b )
---
updated-dependencies:
- dependency-name: ossf/scorecard-action
dependency-version: 2.4.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-08-03 14:22:14 +02:00
dependabot[bot]
e9a26b62b5
build(deps): bump docker/docker-agent-action/.github/workflows/review-pr.yml
...
Bumps the docker-actions group with 1 update: [docker/docker-agent-action/.github/workflows/review-pr.yml](https://github.com/docker/docker-agent-action ).
Updates `docker/docker-agent-action/.github/workflows/review-pr.yml` from 2.0.2 to 2.0.3
- [Release notes](https://github.com/docker/docker-agent-action/releases )
- [Commits](774b6e0e60...baf90543d8 )
---
updated-dependencies:
- dependency-name: docker/docker-agent-action/.github/workflows/review-pr.yml
dependency-version: 2.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: docker-actions
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-08-03 12:03:00 +02:00
dependabot[bot]
b7c346a72e
build(deps): bump actions/stale from 10.4.0 to 11.0.0
...
Bumps [actions/stale](https://github.com/actions/stale ) from 10.4.0 to 11.0.0.
- [Release notes](https://github.com/actions/stale/releases )
- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md )
- [Commits](1e223db275...4391f3da66 )
---
updated-dependencies:
- dependency-name: actions/stale
dependency-version: 11.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-08-03 12:02:29 +02:00
Guillaume Lours
ea82c55224
ci: publish images to Docker Hub using OIDC
...
Replace the long-lived DOCKERPUBLICBOT PAT with short-lived tokens
minted through the Docker Hub OIDC connection, using the
registry-identities input of the github-builder bake workflow.
The connection rulesets cover both triggers of this workflow
(refs/heads/main and refs/tags/v*) for compose-bin and
compose-desktop-module.
Signed-off-by: Guillaume Lours <glours@users.noreply.github.com>
2026-08-03 11:08:09 +02:00
dependabot[bot]
9846e27450
build(deps): bump docker/github-builder/.github/workflows/bake.yml
...
ci / validate (lint) (push) Waiting to run
ci / validate (validate-docs) (push) Waiting to run
ci / validate (validate-go-mod) (push) Waiting to run
ci / validate (validate-headers) (push) Waiting to run
ci / binary (push) Waiting to run
ci / binary-finalize (push) Blocked by required conditions
ci / bin-image-test (push) Waiting to run
ci / test (push) Waiting to run
ci / e2e (plugin, oldstable) (push) Waiting to run
ci / e2e (standalone, oldstable) (push) Waiting to run
ci / e2e (plugin, stable) (push) Waiting to run
ci / e2e (standalone, stable) (push) Waiting to run
ci / coverage (push) Blocked by required conditions
ci / release (push) Blocked by required conditions
merge / bin-image-prepare (push) Waiting to run
merge / bin-image (push) Blocked by required conditions
merge / module-image (push) Waiting to run
Scorecards supply-chain security / Scorecards analysis (push) Waiting to run
zizmor / zizmor (push) Waiting to run
Bumps the docker-actions group with 1 update: [docker/github-builder/.github/workflows/bake.yml](https://github.com/docker/github-builder ).
Updates `docker/github-builder/.github/workflows/bake.yml` from 1.14.0 to 1.15.0
- [Release notes](https://github.com/docker/github-builder/releases )
- [Commits](3415a188ca...27ade872c1 )
---
updated-dependencies:
- dependency-name: docker/github-builder/.github/workflows/bake.yml
dependency-version: 1.15.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: docker-actions
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-31 11:48:48 +02:00
dependabot[bot]
f2a6f94379
build(deps): bump actions/checkout from 7.0.0 to 7.0.1
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 7.0.0 to 7.0.1.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](9c091bb21b...3d3c42e5aa )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-30 11:41:08 +02:00
dependabot[bot]
1c7930e91a
build(deps): bump github/codeql-action/upload-sarif
...
ci / validate (lint) (push) Waiting to run
ci / validate (validate-docs) (push) Waiting to run
ci / validate (validate-go-mod) (push) Waiting to run
ci / validate (validate-headers) (push) Waiting to run
ci / binary (push) Waiting to run
ci / binary-finalize (push) Blocked by required conditions
ci / bin-image-test (push) Waiting to run
ci / test (push) Waiting to run
ci / e2e (plugin, oldstable) (push) Waiting to run
ci / e2e (standalone, oldstable) (push) Waiting to run
ci / e2e (plugin, stable) (push) Waiting to run
ci / e2e (standalone, stable) (push) Waiting to run
ci / coverage (push) Blocked by required conditions
ci / release (push) Blocked by required conditions
merge / bin-image-prepare (push) Waiting to run
merge / bin-image (push) Blocked by required conditions
merge / module-image (push) Waiting to run
Scorecards supply-chain security / Scorecards analysis (push) Waiting to run
zizmor / zizmor (push) Waiting to run
Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ) from 4.37.0 to 4.37.3.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](99df26d4f1...e4fba868fa )
---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.37.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-29 11:21:20 +02:00
dependabot[bot]
69568827a5
build(deps): bump actions/setup-go from 6.5.0 to 7.0.0
...
Bumps [actions/setup-go](https://github.com/actions/setup-go ) from 6.5.0 to 7.0.0.
- [Release notes](https://github.com/actions/setup-go/releases )
- [Commits](924ae3a1cd...b7ad1dad31 )
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-22 11:55:26 +02:00
dependabot[bot]
358efafdf5
build(deps): bump softprops/action-gh-release from 3.0.1 to 3.0.2
...
ci / validate (lint) (push) Waiting to run
ci / validate (validate-docs) (push) Waiting to run
ci / validate (validate-go-mod) (push) Waiting to run
ci / validate (validate-headers) (push) Waiting to run
ci / binary (push) Waiting to run
ci / binary-finalize (push) Blocked by required conditions
ci / bin-image-test (push) Waiting to run
ci / test (push) Waiting to run
ci / e2e (plugin, oldstable) (push) Waiting to run
ci / e2e (standalone, oldstable) (push) Waiting to run
ci / e2e (plugin, stable) (push) Waiting to run
ci / e2e (standalone, stable) (push) Waiting to run
ci / coverage (push) Blocked by required conditions
ci / release (push) Blocked by required conditions
merge / bin-image-prepare (push) Waiting to run
merge / bin-image (push) Blocked by required conditions
merge / module-image (push) Waiting to run
Scorecards supply-chain security / Scorecards analysis (push) Waiting to run
zizmor / zizmor (push) Waiting to run
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release ) from 3.0.1 to 3.0.2.
- [Release notes](https://github.com/softprops/action-gh-release/releases )
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md )
- [Commits](718ea10b13...3d0d9888cb )
---
updated-dependencies:
- dependency-name: softprops/action-gh-release
dependency-version: 3.0.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-21 11:27:44 +02:00
dependabot[bot]
ec0189c03f
build(deps): bump docker/github-builder/.github/workflows/bake.yml
...
Bumps the docker-actions group with 1 update: [docker/github-builder/.github/workflows/bake.yml](https://github.com/docker/github-builder ).
Updates `docker/github-builder/.github/workflows/bake.yml` from 1.13.0 to 1.14.0
- [Release notes](https://github.com/docker/github-builder/releases )
- [Commits](c4a1b216d9...3415a188ca )
---
updated-dependencies:
- dependency-name: docker/github-builder/.github/workflows/bake.yml
dependency-version: 1.14.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: docker-actions
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-20 11:46:39 +02:00
dependabot[bot]
5bf5a21687
build(deps): bump actions/stale from 10.3.0 to 10.4.0
...
ci / validate (lint) (push) Waiting to run
ci / validate (validate-docs) (push) Waiting to run
ci / validate (validate-go-mod) (push) Waiting to run
ci / validate (validate-headers) (push) Waiting to run
ci / binary (push) Waiting to run
ci / binary-finalize (push) Blocked by required conditions
ci / bin-image-test (push) Waiting to run
ci / test (push) Waiting to run
ci / e2e (plugin, oldstable) (push) Waiting to run
ci / e2e (standalone, oldstable) (push) Waiting to run
ci / e2e (plugin, stable) (push) Waiting to run
ci / e2e (standalone, stable) (push) Waiting to run
ci / coverage (push) Blocked by required conditions
ci / release (push) Blocked by required conditions
merge / bin-image-prepare (push) Waiting to run
merge / bin-image (push) Blocked by required conditions
merge / module-image (push) Waiting to run
Scorecards supply-chain security / Scorecards analysis (push) Waiting to run
zizmor / zizmor (push) Waiting to run
Bumps [actions/stale](https://github.com/actions/stale ) from 10.3.0 to 10.4.0.
- [Release notes](https://github.com/actions/stale/releases )
- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md )
- [Commits](eb5cf3af3a...1e223db275 )
---
updated-dependencies:
- dependency-name: actions/stale
dependency-version: 10.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-16 18:05:12 +02:00
dependabot[bot]
fd0faf788b
build(deps): bump the docker-actions group across 1 directory with 4 updates
...
Bumps the docker-actions group with 4 updates in the / directory: [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ), [docker/github-builder/.github/workflows/bake.yml](https://github.com/docker/github-builder ), [docker/bake-action](https://github.com/docker/bake-action ) and [docker/docker-agent-action/.github/workflows/review-pr.yml](https://github.com/docker/docker-agent-action ).
Updates `docker/setup-buildx-action` from 4.1.0 to 4.2.0
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](d7f5e7f509...bb05f3f551 )
Updates `docker/github-builder/.github/workflows/bake.yml` from 1.12.0 to 1.13.0
- [Release notes](https://github.com/docker/github-builder/releases )
- [Commits](5f637c833a...c4a1b216d9 )
Updates `docker/bake-action` from 7.2.0 to 7.3.0
- [Release notes](https://github.com/docker/bake-action/releases )
- [Commits](6614cfa25e...d3418bd7d0 )
Updates `docker/docker-agent-action/.github/workflows/review-pr.yml` from 2.0.1 to 2.0.2
- [Release notes](https://github.com/docker/docker-agent-action/releases )
- [Commits](e96a4bb40c...774b6e0e60 )
---
updated-dependencies:
- dependency-name: docker/bake-action
dependency-version: 7.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: docker-actions
- dependency-name: docker/docker-agent-action/.github/workflows/review-pr.yml
dependency-version: 2.0.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: docker-actions
- dependency-name: docker/github-builder/.github/workflows/bake.yml
dependency-version: 1.13.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: docker-actions
- dependency-name: docker/setup-buildx-action
dependency-version: 4.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: docker-actions
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-16 16:31:53 +02:00
dependabot[bot]
682a1f65fc
build(deps): bump github/codeql-action/upload-sarif
...
Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ) from 4.36.2 to 4.37.0.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](8aad20d150...99df26d4f1 )
---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-16 16:16:18 +02:00
dependabot[bot]
f32009d4a2
build(deps): bump actions/checkout from 6.0.2 to 7.0.0
...
ci / validate (lint) (push) Has been cancelled
ci / validate (validate-docs) (push) Has been cancelled
ci / validate (validate-go-mod) (push) Has been cancelled
ci / validate (validate-headers) (push) Has been cancelled
ci / binary (push) Has been cancelled
ci / bin-image-test (push) Has been cancelled
ci / test (push) Has been cancelled
ci / e2e (plugin, oldstable) (push) Has been cancelled
ci / e2e (standalone, oldstable) (push) Has been cancelled
ci / e2e (plugin, stable) (push) Has been cancelled
ci / e2e (standalone, stable) (push) Has been cancelled
docs-upstream / docs-yaml (push) Has been cancelled
merge / bin-image-prepare (push) Has been cancelled
merge / module-image (push) Has been cancelled
Scorecards supply-chain security / Scorecards analysis (push) Has been cancelled
zizmor / zizmor (push) Has been cancelled
ci / binary-finalize (push) Has been cancelled
ci / coverage (push) Has been cancelled
ci / release (push) Has been cancelled
docs-upstream / validate (push) Has been cancelled
merge / bin-image (push) Has been cancelled
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6.0.2 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](de0fac2e45...9c091bb21b )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-07 11:49:14 +02:00
dependabot[bot]
f4bc599fdb
build(deps): bump github/codeql-action/upload-sarif
...
Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ) from 3.36.3 to 4.36.2.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](411c4c9a36...8aad20d150 )
---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.36.2
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-07 11:45:50 +02:00
dependabot[bot]
2ed5bf2b61
build(deps): bump codecov/codecov-action from 5.5.3 to 7.0.0
...
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action ) from 5.5.3 to 7.0.0.
- [Release notes](https://github.com/codecov/codecov-action/releases )
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md )
- [Commits](1af58845a9...fb8b3582c8 )
---
updated-dependencies:
- dependency-name: codecov/codecov-action
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-07 11:45:10 +02:00
dependabot[bot]
d32d8c3c76
build(deps): bump mxschmitt/action-tmate from 3.23 to 3.24
...
Bumps [mxschmitt/action-tmate](https://github.com/mxschmitt/action-tmate ) from 3.23 to 3.24.
- [Release notes](https://github.com/mxschmitt/action-tmate/releases )
- [Changelog](https://github.com/mxschmitt/action-tmate/blob/master/RELEASE.md )
- [Commits](c0afd6f790...35b54afac2 )
---
updated-dependencies:
- dependency-name: mxschmitt/action-tmate
dependency-version: '3.24'
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-07 11:38:15 +02:00
dependabot[bot]
774d04dcef
build(deps): bump test-summary/action from 2.4 to 2.6
...
Bumps [test-summary/action](https://github.com/test-summary/action ) from 2.4 to 2.6.
- [Release notes](https://github.com/test-summary/action/releases )
- [Commits](31493c76ec...37b508cfee )
---
updated-dependencies:
- dependency-name: test-summary/action
dependency-version: '2.6'
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-07 11:37:45 +02:00
dependabot[bot]
2c87234df8
build(deps): bump actions/setup-go from 6.3.0 to 6.5.0
...
Bumps [actions/setup-go](https://github.com/actions/setup-go ) from 6.3.0 to 6.5.0.
- [Release notes](https://github.com/actions/setup-go/releases )
- [Commits](4b73464bb3...924ae3a1cd )
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-version: 6.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-07 11:36:51 +02:00
dependabot[bot]
d00abb6f94
build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1
...
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact ) from 7.0.0 to 7.0.1.
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/v7...043fb46d1a93c77aae656e7c1c64a875d1fc6a0a )
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-version: 7.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-07 11:36:16 +02:00
dependabot[bot]
6b2e8d20c3
build(deps): bump the docker-actions group with 3 updates
...
Bumps the docker-actions group with 3 updates: [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ), [docker/github-builder/.github/workflows/bake.yml](https://github.com/docker/github-builder ) and [docker/bake-action](https://github.com/docker/bake-action ).
Updates `docker/setup-buildx-action` from 4.0.0 to 4.1.0
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](4d04d5d948...d7f5e7f509 )
Updates `docker/github-builder/.github/workflows/bake.yml` from 1.4.0 to 1.12.0
- [Release notes](https://github.com/docker/github-builder/releases )
- [Commits](70313223e2...5f637c833a )
Updates `docker/bake-action` from 7.0.0 to 7.2.0
- [Release notes](https://github.com/docker/bake-action/releases )
- [Commits](82490499d2...6614cfa25e )
---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
dependency-version: 4.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: docker-actions
- dependency-name: docker/github-builder/.github/workflows/bake.yml
dependency-version: 1.12.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: docker-actions
- dependency-name: docker/bake-action
dependency-version: 7.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: docker-actions
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-07 11:34:25 +02:00
dependabot[bot]
43dc875f65
build(deps): bump actions/stale from 10.2.0 to 10.3.0
...
Bumps [actions/stale](https://github.com/actions/stale ) from 10.2.0 to 10.3.0.
- [Release notes](https://github.com/actions/stale/releases )
- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md )
- [Commits](b5d41d4e1d...eb5cf3af3a )
---
updated-dependencies:
- dependency-name: actions/stale
dependency-version: 10.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-07 11:10:54 +02:00
Guillaume Lours
69ba683e15
ci: address review feedback on release job
...
ci / validate (lint) (push) Waiting to run
ci / validate (validate-docs) (push) Waiting to run
ci / validate (validate-go-mod) (push) Waiting to run
ci / validate (validate-headers) (push) Waiting to run
ci / binary (push) Waiting to run
ci / binary-finalize (push) Blocked by required conditions
ci / bin-image-test (push) Waiting to run
ci / test (push) Waiting to run
ci / e2e (plugin, oldstable) (push) Waiting to run
ci / e2e (standalone, oldstable) (push) Waiting to run
ci / e2e (plugin, stable) (push) Waiting to run
ci / e2e (standalone, stable) (push) Waiting to run
ci / coverage (push) Blocked by required conditions
ci / release (push) Blocked by required conditions
merge / bin-image-prepare (push) Waiting to run
merge / bin-image (push) Blocked by required conditions
merge / module-image (push) Waiting to run
Scorecards supply-chain security / Scorecards analysis (push) Waiting to run
zizmor / zizmor (push) Waiting to run
- Replace ncipollo/release-action with softprops/action-gh-release
(v3.0.1, SHA-pinned), the action used across Docker repositories;
input mapping is one-to-one.
- Duplicate the artifact listing/type checks into binary-finalize:
one copy inspects the artifact as assembled, on every push/PR (lost
when the tag guard moved to job level); the release-job copy still
inspects what was downloaded and gets attached to the release.
- Set overwrite_files: false so a job re-run never replaces assets
already uploaded to an existing release: unlike ncipollo, softprops
updates an existing release instead of failing. A re-run may still
refresh the release name/notes.
Signed-off-by: Guillaume Lours <glours@users.noreply.github.com>
2026-07-07 10:56:13 +02:00
Guillaume Lours
336f21f846
ci: harden GitHub Actions workflows
...
The pinned codeql-action/upload-sarif v2 (v2.28.1) falls in the
vulnerable range of CVE-2025-24362 and the v2 line has no patched
release, so bump to v3.36.3. Scope the release job to tag refs so its
contents:write token is only minted when a release is actually
created. In merge.yml, drop a dead conditional (workflow only triggers
on push) and pass DOCKERDESKTOP_REPO to github-script via env rather
than inline interpolation, as recommended against script injection.
Signed-off-by: Guillaume Lours <glours@users.noreply.github.com>
2026-07-07 10:56:13 +02:00
CrazyMax
a666b63a3c
ci: fix docs-upstream workflow
...
ci / validate (lint) (push) Waiting to run
ci / validate (validate-docs) (push) Waiting to run
ci / validate (validate-go-mod) (push) Waiting to run
ci / validate (validate-headers) (push) Waiting to run
ci / binary (push) Waiting to run
ci / binary-finalize (push) Blocked by required conditions
ci / bin-image-test (push) Waiting to run
ci / test (push) Waiting to run
ci / e2e (plugin, oldstable) (push) Waiting to run
ci / e2e (standalone, oldstable) (push) Waiting to run
ci / e2e (plugin, stable) (push) Waiting to run
ci / e2e (standalone, stable) (push) Waiting to run
ci / coverage (push) Blocked by required conditions
ci / release (push) Blocked by required conditions
docs-upstream / docs-yaml (push) Waiting to run
docs-upstream / validate (push) Blocked by required conditions
merge / bin-image-prepare (push) Waiting to run
merge / bin-image (push) Blocked by required conditions
merge / module-image (push) Waiting to run
Scorecards supply-chain security / Scorecards analysis (push) Waiting to run
zizmor / zizmor (push) Waiting to run
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-06 17:29:12 +02:00
CrazyMax
be7b72e0ef
fix zizmor findings
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-06 17:11:24 +02:00
CrazyMax
1c9aa35c21
ci: zizmor workflow
...
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-06 17:11:24 +02:00
Sebastiaan van Stijn
26550b0d1f
ci: remove unused desktop-edge-test workflow
...
It's not currently used, and we can probably trigger this from the
desktop repository itself.
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-07-06 11:18:38 +02:00
Derek Misler
81e420139a
ci: add concurrency group to pr-review-trigger to prevent duplicate reviews
...
Signed-off-by: Derek Misler <derek.misler@docker.com>
2026-07-06 10:25:22 +02:00
Docker Agent
a3c1c0dc2e
chore: migrate to docker-agent-action v2.0.1
...
ci / validate (lint) (push) Waiting to run
ci / validate (validate-docs) (push) Waiting to run
ci / validate (validate-go-mod) (push) Waiting to run
ci / validate (validate-headers) (push) Waiting to run
ci / binary (push) Waiting to run
ci / binary-finalize (push) Blocked by required conditions
ci / bin-image-test (push) Waiting to run
ci / test (push) Waiting to run
ci / e2e (plugin, oldstable) (push) Waiting to run
ci / e2e (standalone, oldstable) (push) Waiting to run
ci / e2e (plugin, stable) (push) Waiting to run
ci / e2e (standalone, stable) (push) Waiting to run
ci / coverage (push) Blocked by required conditions
ci / release (push) Blocked by required conditions
merge / bin-image-prepare (push) Waiting to run
merge / bin-image (push) Blocked by required conditions
merge / module-image (push) Waiting to run
merge / desktop-edge-test (push) Blocked by required conditions
Scorecards supply-chain security / Scorecards analysis (push) Waiting to run
- Bump docker-agent-action to v2.0.1 (e96a4bb)
- Add review_requested to pr-review-trigger.yml pull_request types
Signed-off-by: Docker Agent <svc-github-docker-agent@docker.com>
2026-06-24 14:51:31 +02:00
Docker Agent
899e88475a
chore: migrate cagent-action to docker-agent-action (v2.0.0)
...
ci / validate (lint) (push) Waiting to run
ci / validate (validate-docs) (push) Waiting to run
ci / validate (validate-go-mod) (push) Waiting to run
ci / validate (validate-headers) (push) Waiting to run
ci / binary (push) Waiting to run
ci / binary-finalize (push) Blocked by required conditions
ci / bin-image-test (push) Waiting to run
ci / test (push) Waiting to run
ci / e2e (plugin, oldstable) (push) Waiting to run
ci / e2e (standalone, oldstable) (push) Waiting to run
ci / e2e (plugin, stable) (push) Waiting to run
ci / e2e (standalone, stable) (push) Waiting to run
ci / coverage (push) Blocked by required conditions
ci / release (push) Blocked by required conditions
merge / bin-image-prepare (push) Waiting to run
merge / bin-image (push) Blocked by required conditions
merge / module-image (push) Waiting to run
merge / desktop-edge-test (push) Blocked by required conditions
Scorecards supply-chain security / Scorecards analysis (push) Waiting to run
Signed-off-by: Derek Misler <derek.misler@docker.com>
2026-06-23 22:42:46 +02:00
Sebastiaan van Stijn
79d63a8b84
gha: update docs-upstream to pin workflows by sha
...
ci / validate (lint) (push) Waiting to run
ci / validate (validate-docs) (push) Waiting to run
ci / validate (validate-go-mod) (push) Waiting to run
ci / validate (validate-headers) (push) Waiting to run
ci / binary (push) Waiting to run
ci / binary-finalize (push) Blocked by required conditions
ci / bin-image-test (push) Waiting to run
ci / test (push) Waiting to run
ci / e2e (plugin, oldstable) (push) Waiting to run
ci / e2e (standalone, oldstable) (push) Waiting to run
ci / e2e (plugin, stable) (push) Waiting to run
ci / e2e (standalone, stable) (push) Waiting to run
ci / coverage (push) Blocked by required conditions
ci / release (push) Blocked by required conditions
docs-upstream / docs-yaml (push) Waiting to run
docs-upstream / validate (push) Blocked by required conditions
merge / bin-image-prepare (push) Waiting to run
merge / bin-image (push) Blocked by required conditions
merge / module-image (push) Waiting to run
merge / desktop-edge-test (push) Blocked by required conditions
Scorecards supply-chain security / Scorecards analysis (push) Waiting to run
This workflow was updated in 56e2dba366
but it looks to have pinned to a version before the workflows were
pinned; 464a44a6e7/.github/workflows/validate-upstream.yml
This patch updates the workflow to a version that uses pinned actions;
00aefd5eae/.github/workflows/validate-upstream.yml
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-06-09 17:57:47 +02:00
derekmisler
60584e72b2
chore: update cagent-action to v1.4.4
...
Signed-off-by: Derek Misler <derek.misler@docker.com>
2026-05-05 10:43:37 +02:00
Guillaume Lours
9fd9dc7ca9
ci: remove unused e2e job from merge workflow
...
The e2e job targets desktop runners (desktop-windows, desktop-macos,
desktop-m1) that are not configured anymore for this project.
Signed-off-by: Guillaume Lours <glours@users.noreply.github.com>
2026-04-16 09:23:06 +02:00
Guillaume Lours
977a4310f9
remove 'provenance' attribute'
...
Signed-off-by: Guillaume Lours <glours@users.noreply.github.com>
2026-04-15 15:46:06 +02:00
Guillaume Lours
d518da2419
build and push Docker Desktop module image on release
...
Add workflow to build and push docker/compose-desktop-module image
to Docker Hub on version tag push, used by Docker Desktop's update
system to deliver the Compose CLI plugin.
Signed-off-by: Guillaume Lours <glours@users.noreply.github.com>
2026-04-10 16:12:09 +02:00
Guillaume Lours
7aeb90c9a3
Skip PR review workflow for Dependabot PRs
...
Dependabot PRs don't have access to the secrets required by the
cagent-action reusable workflow (CAGENT_ORG_MEMBERSHIP_TOKEN), causing
the org membership check to fail with "github-token not supplied".
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Guillaume Lours <glours@users.noreply.github.com>
2026-03-31 10:58:45 +02:00
Guillaume Lours
0de456bc76
chore: bump GitHub Actions to latest versions
...
- actions/checkout v4 -> v6
- actions/upload-artifact v4/v6 -> v7
- actions/download-artifact v4/v7 -> v8
- docker/setup-buildx-action v3 -> v4
- docker/bake-action v6 -> v7
- actions/stale v9 -> v10
- actions/create-github-app-token v1 -> v3
- actions/github-script v7 -> v8
- ossf/scorecard-action v2.4.0 -> v2.4.3
- ncipollo/release-action v1.10.0 -> v1.21.0
- mxschmitt/action-tmate v3.11 -> v3.23
- codecov/codecov-action, test-summary/action, github/codeql-action: bump to latest patch
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Guillaume Lours <glours@users.noreply.github.com>
2026-03-25 10:19:36 +01:00
Guillaume Lours
56e2dba366
chore: pin GitHub Actions to commit SHA, remove pr-review workflow
...
- Pin all action references to full commit SHA instead of mutable
version tags. Tag retained as inline comment for readability.
- Remove pr-review.yml workflow.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Guillaume Lours <glours@users.noreply.github.com>
# Conflicts:
# .github/workflows/pr-review.yml
2026-03-25 10:19:36 +01:00
Derek Misler
46d75d0bea
Update .github/workflows/pr-review.yml
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Derek Misler <derekmisler@gmail.com>
2026-03-25 09:52:29 +01:00
Derek Misler
bd351d7f96
Update .github/workflows/pr-review.yml
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Derek Misler <derekmisler@gmail.com>
2026-03-25 09:52:29 +01:00
Derek Misler
ece1886824
update cagent-action to latest (with better permissions)
...
Signed-off-by: Derek Misler <derek.misler@docker.com>
2026-03-25 09:52:29 +01:00