This is an automated email from the ASF dual-hosted git repository.
jerryshao pushed a commit to branch branch-1.3
in repository https://gitbox.apache.org/repos/asf/gravitino.git
The following commit(s) were added to refs/heads/branch-1.3 by this push:
new 1090c788b5 [MINOR] fix(ci): bump docker/login-action to an allowlisted
SHA (branch-1.3) (#13497)
1090c788b5 is described below
commit 1090c788b57c60bcbf129998099a7ff449e324a0
Author: Bharath Krishna <[email protected]>
AuthorDate: Wed Sep 23 22:53:13 2026 -0700
[MINOR] fix(ci): bump docker/login-action to an allowlisted SHA
(branch-1.3) (#13497)
Direct backport of #13496 to `branch-1.3`, opened in parallel rather
than waiting for main's CI so 1.3.1-rc3 isn't serialised behind two full
CI cycles (per Jerry's suggestion).
### What changes were proposed in this pull request?
Bump `docker/login-action` from `650006c6` (v4.2.0) to `dbcb8138`
(v4.6.0) in `.github/workflows/docker-image.yml`. Identical one-line
change to #13496.
### Why are the changes needed?
ASF Infra's daily "Remove Expired Refs" job
([apache/infrastructure-actions@3f48e927](https://github.com/apache/infrastructure-actions/commit/3f48e927),
2026-09-24 02:27 UTC) expired `docker/login-action@650006c6` from the
actions allowlist. All dispatches of `docker-image.yml` now fail at
startup with:
> The action docker/login-action@650006c6... is not allowed in
apache/gravitino
This blocked the image publish for 1.3.1-rc2 and blocks any image build
from `branch-1.3`.
v4.6.0 is the only allowlisted revision of this action with no
`expires_at` date; the older entries are all already scheduled to expire
(v4.3.0 on 2026-09-27, v4.5.2 on 2026-10-22).
`setup-qemu-action` and `setup-buildx-action` remain allowlisted at
their current pins and are unchanged.
### Does this PR introduce any user-facing change?
No. CI only.
### How was this patch tested?
- Confirmed `dbcb813823bdd20940b903addbd779551569679f` is in
`apache/infrastructure-actions/approved_patterns.yml` and the previous
SHA is not.
- Confirmed the SHA resolves to `docker/login-action` v4.6.0.
- Compared `action.yml` at the old and new SHAs: inputs are identical
(`registry`, `username`, `password`, `ecr`, `scope`, `logout`,
`registry-auth`), so the workflow's `username`/`password` usage is
unaffected.
---
.github/workflows/docker-image.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/.github/workflows/docker-image.yml
b/.github/workflows/docker-image.yml
index 9b879557d2..da910f309a 100644
--- a/.github/workflows/docker-image.yml
+++ b/.github/workflows/docker-image.yml
@@ -130,7 +130,7 @@ jobs:
uses:
docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0
- name: Login to Docker Hub
- uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee #
v4.2.0
+ uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f #
v4.6.0
with:
username: ${{ github.event.inputs.username }}
password: ${{ secrets.DOCKER_REPOSITORY_PASSWORD }}