ci(deps): bump docker/setup-buildx-action from 3 to 4 - #374
Conversation
|
Warning Your comment is too long (maximum is 65536 characters), so the coverage report was not added. See the job log for how to reduce it. |
52dfd91 to
d4d9c41
Compare
|
👋 This PR needs a couple of things fixed before OpenHands can review it:
Push an update once this is addressed and this check re-runs automatically. This is an automated check - no AI was used to generate this comment. |
2c5078e to
75febfb
Compare
bd4db86 to
cde4b48
Compare
neubig
left a comment
There was a problem hiding this comment.
Approved: checks are green. This review was created by an AI agent (OpenHands) on behalf of the user.
cde4b48 to
671c8c6
Compare
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 3 to 4. - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@v3...v4) --- updated-dependencies: - dependency-name: docker/setup-buildx-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
671c8c6 to
27175d1
Compare
all-hands-bot
left a comment
There was a problem hiding this comment.
This review was posted by an AI agent (OpenHands).
Bumps docker/setup-buildx-action from v3 to v4 in the two workflows that use it: .github/workflows/ghcr-build.yml and .github/workflows/tag-image.yml. Both changes are tag-only bumps with no new inputs and no behavior changes to the surrounding steps.
Assessment:
- Scope: The change belongs in this repository.
AGENTS.md(Cross-Repository Boundaries / Repository Structure) confirms these workflows live and are owned here, and.github/dependabot.ymlexplicitly configures weeklygithub-actionsupdates for this repo. No product or architecture decision is needed. - Compatibility of the changed inputs: The only input passed to the action in either workflow is
driver-opts(ghcr-build.yml);tag-image.ymlpasses none. Comparing the action metadata forv4.0.0andv3.12.0,driver-optsstill exists in v4, so the existing usage remains valid. The inputs removed in v4 (config,config-inline,install) are not referenced by either workflow, so v4's "Remove deprecated inputs/outputs" change does not affect this repo. - Runtime requirement: v4 switches the action runtime to Node 24, which needs Actions Runner v2.327.1+. Both jobs use GitHub-hosted
ubuntu-24.04runners, which are always current, so this is satisfied. - CI evidence at this head: All checks on the exact head
27175d12a0ceb017f3c44d31c060e66fd87b3767are green (Docker/ "Build and Push Automation Image",ci,Run tests,pr). TheDockerrun is the one that actually exercises the bumped action end to end and it succeeded, so the bump is validated on the production-facing path rather than by inspection alone. - No security regression: No secret handling, permissions, or trigger conditions changed in the diff.
No material correctness, security, compatibility, or acceptance-criterion defect found on the current head.
✅ APPROVED
neubig
left a comment
There was a problem hiding this comment.
Current CI checks pass. Approved by an AI agent (OpenHands) on behalf of Graham Neubig.
Bumps docker/setup-buildx-action from 3 to 4.
Release notes
Sourced from docker/setup-buildx-action's releases.
... (truncated)
Commits
f87e599Merge pull request #624 from crazy-max/skip-pull-with-endpointe700274chore: update generated content3061c91skip BuildKit image pre-pulls for explicit endpoints594f3bfMerge pull request #609 from crazy-max/pull-buildkit-image-before-createbd6e702chore: update generated content6268c9dpull BuildKit image before builder creatione823525Merge pull request #621 from docker/dependabot/github_actions/codeql-actions-...533ed8ebuild(deps): bump the codeql-actions group with 2 updatesbedaf13Merge pull request #620 from crazy-max/shared-error-helpersd5079fbchore: update generated content