This is an automated email from the ASF dual-hosted git repository.

jerryshao pushed a commit to branch branch-1.3
in repository https://gitbox.apache.org/repos/asf/gravitino.git


The following commit(s) were added to refs/heads/branch-1.3 by this push:
     new 1090c788b5 [MINOR] fix(ci): bump docker/login-action to an allowlisted 
SHA (branch-1.3) (#13497)
1090c788b5 is described below

commit 1090c788b57c60bcbf129998099a7ff449e324a0
Author: Bharath Krishna <[email protected]>
AuthorDate: Wed Sep 23 22:53:13 2026 -0700

    [MINOR] fix(ci): bump docker/login-action to an allowlisted SHA 
(branch-1.3) (#13497)
    
    Direct backport of #13496 to `branch-1.3`, opened in parallel rather
    than waiting for main's CI so 1.3.1-rc3 isn't serialised behind two full
    CI cycles (per Jerry's suggestion).
    
    ### What changes were proposed in this pull request?
    
    Bump `docker/login-action` from `650006c6` (v4.2.0) to `dbcb8138`
    (v4.6.0) in `.github/workflows/docker-image.yml`. Identical one-line
    change to #13496.
    
    ### Why are the changes needed?
    
    ASF Infra's daily "Remove Expired Refs" job
    
([apache/infrastructure-actions@3f48e927](https://github.com/apache/infrastructure-actions/commit/3f48e927),
    2026-09-24 02:27 UTC) expired `docker/login-action@650006c6` from the
    actions allowlist. All dispatches of `docker-image.yml` now fail at
    startup with:
    
    > The action docker/login-action@650006c6... is not allowed in
    apache/gravitino
    
    This blocked the image publish for 1.3.1-rc2 and blocks any image build
    from `branch-1.3`.
    
    v4.6.0 is the only allowlisted revision of this action with no
    `expires_at` date; the older entries are all already scheduled to expire
    (v4.3.0 on 2026-09-27, v4.5.2 on 2026-10-22).
    
    `setup-qemu-action` and `setup-buildx-action` remain allowlisted at
    their current pins and are unchanged.
    
    ### Does this PR introduce any user-facing change?
    
    No. CI only.
    
    ### How was this patch tested?
    
    - Confirmed `dbcb813823bdd20940b903addbd779551569679f` is in
    `apache/infrastructure-actions/approved_patterns.yml` and the previous
    SHA is not.
    - Confirmed the SHA resolves to `docker/login-action` v4.6.0.
    - Compared `action.yml` at the old and new SHAs: inputs are identical
    (`registry`, `username`, `password`, `ecr`, `scope`, `logout`,
    `registry-auth`), so the workflow's `username`/`password` usage is
    unaffected.
---
 .github/workflows/docker-image.yml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/.github/workflows/docker-image.yml 
b/.github/workflows/docker-image.yml
index 9b879557d2..da910f309a 100644
--- a/.github/workflows/docker-image.yml
+++ b/.github/workflows/docker-image.yml
@@ -130,7 +130,7 @@ jobs:
         uses: 
docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0
 
       - name: Login to Docker Hub
-        uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # 
v4.2.0
+        uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # 
v4.6.0
         with:
           username: ${{ github.event.inputs.username }}
           password: ${{ secrets.DOCKER_REPOSITORY_PASSWORD }}

Reply via email to