Skip to content

chore(deps): bump docker/login-action from 4.5.1 to 4.6.0 - #94

Merged
bbaarriiss merged 1 commit into
mainfrom
dependabot/github_actions/docker/login-action-4.6.0
Sep 1, 2026
Merged

chore(deps): bump docker/login-action from 4.5.1 to 4.6.0#94
bbaarriiss merged 1 commit into
mainfrom
dependabot/github_actions/docker/login-action-4.6.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown

Bumps docker/login-action from 4.5.1 to 4.6.0.

Release notes

Sourced from docker/login-action's releases.

v4.6.0

Full Changelog: docker/login-action@v4.5.2...v4.6.0

v4.5.2

Full Changelog: docker/login-action@v4.5.1...v4.5.2

Commits
  • dbcb813 Merge pull request #1051 from docker/dependabot/npm_and_yarn/aws-sdk-dependen...
  • 5bcb015 [dependabot skip] chore: update generated content
  • b30b2f2 build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...
  • 9087f1e Merge pull request #1057 from docker/dependabot/npm_and_yarn/js-yaml-5.2.2
  • 0009830 [dependabot skip] chore: update generated content
  • 2325523 build(deps): bump js-yaml from 5.2.1 to 5.2.2
  • 4ec1d4a Merge pull request #1056 from docker/dependabot/npm_and_yarn/postcss-8.5.22
  • 5fc99ba Merge pull request #1053 from docker/dependabot/github_actions/aws-actions/co...
  • e512bd5 Merge pull request #1052 from docker/dependabot/github_actions/codeql-actions...
  • a146c91 Merge pull request #1059 from crazy-max/harden-buildx-scope-paths
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [docker/login-action](https://github.com/docker/login-action) from 4.5.1 to 4.6.0.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@v4.5.1...v4.6.0)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 4.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 1, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 1, 2026 01:53
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 1, 2026

- name: Login to Quay.io
uses: docker/login-action@v4.5.1
uses: docker/login-action@v4.6.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep identified an issue in your code:

The docker/login-action@v4.6.0 tag can be silently repointed, causing the workflow to run attacker-controlled code with Quay credentials and potentially tamper with published images.

More details about this

docker/login-action@v4.6.0 uses a version tag rather than an immutable commit. The deploy-staging job runs this step on pushes to main and passes ${{ secrets.QUAY_USERNAME }} and ${{ secrets.QUAY_ROBOT_TOKEN }} to the action. If the docker/login-action owner—or an account that compromises the repository—moves the v4.6.0 tag, a later workflow run can execute attacker-controlled action code instead of the intended login implementation.

A plausible attack would be:

  1. The attacker repoints v4.6.0 to a malicious commit.
  2. A developer pushes to main, triggering deploy-staging.
  3. The malicious docker/login-action runs with the Quay credentials supplied through username and password, then sends QUAY_ROBOT_TOKEN to an attacker-controlled endpoint or uses it to alter images in quay.io/wire/poll-app.
  4. The workflow continues to Build and push, allowing the attacker to tamper with the image published by docker/build-push-action or use the stolen credentials outside this workflow.

Because the reference can change without any workflow-file change, a previously reviewed workflow can begin executing different code on a future main push.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
uses: docker/login-action@v4.6.0
uses: docker/login-action@<VERIFIED_VALUE_REQUIRED>
View step-by-step instructions
  1. Replace the mutable version tag with the full 40-character commit SHA for the trusted docker/login-action release corresponding to v4.6.0: uses: docker/login-action@<40-character-commit-sha>.
  2. Verify that the SHA belongs to the intended release in the official docker/login-action repository before using it. Do not use @v4, @v4.6.0, or a shortened SHA.
  3. Keep the existing registry, username, and password inputs unchanged. A full commit SHA prevents the action code from changing if the tag is later moved.
💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.

You can view more details about this finding in the Semgrep AppSec Platform.

@bbaarriiss
bbaarriiss merged commit 5e6fdc0 into main Sep 1, 2026
7 checks passed
@bbaarriiss
bbaarriiss deleted the dependabot/github_actions/docker/login-action-4.6.0 branch September 1, 2026 06:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant