1299 Commits

Author SHA1 Message Date
CrazyMax
53b7df96c9 Merge pull request #1572 from docker/dependabot/npm_and_yarn/docker/actions-toolkit-0.92.0
chore(deps): Bump @docker/actions-toolkit from 0.91.0 to 0.92.0
v7 v7.3.0
2026-07-01 16:11:18 +02:00
github-actions[bot]
154298c1ca [dependabot skip] chore: update generated content 2026-07-01 14:05:44 +00:00
dependabot[bot]
cb1238b9c9 chore(deps): Bump @docker/actions-toolkit from 0.91.0 to 0.92.0
Bumps [@docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.91.0 to 0.92.0.
- [Release notes](https://github.com/docker/actions-toolkit/releases)
- [Commits](https://github.com/docker/actions-toolkit/compare/v0.91.0...v0.92.0)

---
updated-dependencies:
- dependency-name: "@docker/actions-toolkit"
  dependency-version: 0.92.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 14:04:40 +00:00
CrazyMax
24f845d5cb Merge pull request #1566 from docker/dependabot/npm_and_yarn/js-yaml-4.2.0
chore(deps): Bump js-yaml from 4.1.1 to 4.3.0
2026-07-01 16:02:16 +02:00
github-actions[bot]
9c6973007b [dependabot skip] chore: update generated content 2026-07-01 13:58:59 +00:00
CrazyMax
bc3a3a5f72 Merge pull request #1574 from docker/dependabot/github_actions/aws-actions/configure-aws-credentials-6.2.1
chore(deps): Bump aws-actions/configure-aws-credentials from 6.2.0 to 6.2.1
2026-07-01 15:58:09 +02:00
dependabot[bot]
a82c504a23 chore(deps): Bump js-yaml from 4.1.1 to 4.3.0
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.1.1 to 4.3.0.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.1.1...4.3.0)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.2.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 13:57:51 +00:00
CrazyMax
0285a75190 Merge pull request #1573 from docker/dependabot/github_actions/actions/cache-6.1.0
chore(deps): Bump actions/cache from 5.0.5 to 6.1.0
2026-07-01 15:57:46 +02:00
CrazyMax
c6ad2a3f96 Merge pull request #1575 from docker/dependabot/github_actions/actions/checkout-7.0.0
chore(deps): Bump actions/checkout from 6.0.3 to 7.0.0
2026-07-01 15:57:22 +02:00
CrazyMax
d37484fb97 Merge pull request #1564 from docker/dependabot/npm_and_yarn/undici-6.27.0
chore(deps): Bump undici from 6.24.1 to 6.27.0
2026-07-01 15:54:52 +02:00
dependabot[bot]
0448735411 chore(deps): Bump actions/checkout from 6.0.3 to 7.0.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](df4cb1c069...9c091bb21b)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 13:54:16 +00:00
dependabot[bot]
3af9982280 chore(deps): Bump aws-actions/configure-aws-credentials
Bumps [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) from 6.2.0 to 6.2.1.
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](e7f100cf4c...254c19bd24)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 13:54:03 +00:00
github-actions[bot]
f53c18c0cf [dependabot skip] chore: update generated content 2026-07-01 13:52:19 +00:00
dependabot[bot]
6e67ee033d chore(deps): Bump actions/cache from 5.0.5 to 6.1.0
Bumps [actions/cache](https://github.com/actions/cache) from 5.0.5 to 6.1.0.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](27d5ce7f10...55cc834586)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 13:52:14 +00:00
dependabot[bot]
11e972a040 chore(deps): Bump undici from 6.24.1 to 6.27.0
Bumps [undici](https://github.com/nodejs/undici) from 6.24.1 to 6.27.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](https://github.com/nodejs/undici/compare/v6.24.1...v6.27.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 6.27.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 13:51:16 +00:00
CrazyMax
910f6850a6 Merge pull request #1568 from docker/dependabot/npm_and_yarn/sigstore/core-3.2.1
chore(deps): Bump @sigstore/core from 3.1.0 to 3.2.1
2026-07-01 15:49:14 +02:00
CrazyMax
33baeb834f Merge pull request #1563 from docker/dependabot/npm_and_yarn/vite-7.3.5
chore(deps): Bump vite from 7.3.2 to 7.3.6
2026-07-01 15:48:47 +02:00
CrazyMax
841b976440 Merge pull request #1560 from docker/dependabot/github_actions/github/codeql-action-4.36.2
chore(deps): Bump github/codeql-action from 4.36.0 to 4.36.2
2026-07-01 15:46:24 +02:00
CrazyMax
dd7abbf170 Merge pull request #1559 from docker/dependabot/github_actions/codecov/codecov-action-7.0.0
chore(deps): Bump codecov/codecov-action from 6.0.1 to 7.0.0
2026-07-01 15:46:01 +02:00
CrazyMax
7c45d1eb06 Merge pull request #1558 from docker/dependabot/github_actions/crazy-max-dot-github-a6a0ecf511
chore(deps): Bump the crazy-max-dot-github group across 1 directory with 2 updates
2026-07-01 15:45:36 +02:00
CrazyMax
8a43ac101c Merge pull request #1556 from docker/dependabot/github_actions/actions/checkout-6.0.3
chore(deps): Bump actions/checkout from 6.0.2 to 6.0.3
2026-07-01 15:45:12 +02:00
CrazyMax
b40e3ca8bc Merge pull request #1552 from docker/dependabot/github_actions/docker/setup-qemu-action-4.1.0
chore(deps): Bump docker/setup-qemu-action from 4.0.0 to 4.1.0
2026-07-01 15:44:47 +02:00
CrazyMax
5f1f2303ad Merge pull request #1569 from crazy-max/dependabot-skip-update-dist
dependabot: skip for update-dist commits
2026-07-01 13:59:34 +02:00
CrazyMax
55f5969fae Merge pull request #1570 from crazy-max/fix-yarn-preapprove-actions-toolkit
chore: allow actions-toolkit to bypass yarn age gate
2026-07-01 13:59:31 +02:00
CrazyMax
4876fd8314 chore: allow actions-toolkit to bypass yarn age gate
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-01 11:43:30 +02:00
dependabot[bot]
d187480585 chore(deps): Bump the crazy-max-dot-github group across 1 directory with 2 updates
Bumps the crazy-max-dot-github group with 2 updates in the / directory: [crazy-max/.github/.github/workflows/pr-assign-author.yml](https://github.com/crazy-max/.github) and [crazy-max/.github/.github/workflows/zizmor.yml](https://github.com/crazy-max/.github).


Updates `crazy-max/.github/.github/workflows/pr-assign-author.yml` from 1.8.0 to 1.10.1
- [Release notes](https://github.com/crazy-max/.github/releases)
- [Commits](9ba6e6f945...46267a6e61)

Updates `crazy-max/.github/.github/workflows/zizmor.yml` from 1.8.0 to 1.10.1
- [Release notes](https://github.com/crazy-max/.github/releases)
- [Commits](9ba6e6f945...46267a6e61)

---
updated-dependencies:
- dependency-name: crazy-max/.github/.github/workflows/pr-assign-author.yml
  dependency-version: 1.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: crazy-max-dot-github
- dependency-name: crazy-max/.github/.github/workflows/zizmor.yml
  dependency-version: 1.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: crazy-max-dot-github
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-30 11:52:20 +00:00
CrazyMax
a64725ae19 dependabot: skip for update-dist commits
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-06-30 11:08:52 +02:00
dependabot[bot]
2aea2d4e15 chore(deps): Bump vite from 7.3.2 to 7.3.6
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 7.3.2 to 7.3.6.
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/v7.3.6/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v7.3.6/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 7.3.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-29 14:17:53 +00:00
github-actions[bot]
f28b5fb763 chore: update generated content 2026-06-29 14:17:29 +00:00
dependabot[bot]
15204538a5 chore(deps): Bump @sigstore/core from 3.1.0 to 3.2.1
Bumps [@sigstore/core](https://github.com/sigstore/sigstore-js) from 3.1.0 to 3.2.1.
- [Release notes](https://github.com/sigstore/sigstore-js/releases)
- [Commits](https://github.com/sigstore/sigstore-js/compare/sigstore@3.1.0...@sigstore/core@3.2.1)

---
updated-dependencies:
- dependency-name: "@sigstore/core"
  dependency-version: 3.2.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-29 14:16:26 +00:00
CrazyMax
b99c92828a Merge pull request #1567 from crazy-max/fix-esbuild
preserve names in esbuild bundle
2026-06-29 16:14:40 +02:00
CrazyMax
16ce5c6012 preserve names in esbuild bundle
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-06-29 14:58:08 +02:00
CrazyMax
ff26911fd3 Merge pull request #1562 from docker/sec-cli/npm-ci-20260612-145940
fix: replace npm install with npm ci (20260612-145940)
2026-06-12 17:16:13 +02:00
securityeng-bot[bot]
c2245a368f fix: use lockfile-aware install commands 2026-06-12 14:59:41 +00:00
CrazyMax
d2aace88c2 Merge pull request #1561 from docker/e2e-aws-ecr-oidc
ci(e2e): use OIDC for AWS ECR
2026-06-11 23:21:40 +02:00
CrazyMax
ffca5157f0 ci(e2e): use OIDC for AWS ECR
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-06-11 21:54:33 +02:00
CrazyMax
f72b3cf665 Merge pull request #1555 from crazy-max/e2e-dockerhub
ci(e2e): use org-owned Docker Hub credentials for e2e pushes
2026-06-08 19:08:26 +02:00
dependabot[bot]
371801e73e chore(deps): Bump github/codeql-action from 4.36.0 to 4.36.2
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.0 to 4.36.2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](7211b7c807...8aad20d150)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.36.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 11:54:12 +00:00
dependabot[bot]
b3a9933cc8 chore(deps): Bump codecov/codecov-action from 6.0.1 to 7.0.0
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 6.0.1 to 7.0.0.
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](e79a6962e0...fb8b3582c8)

---
updated-dependencies:
- dependency-name: codecov/codecov-action
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 11:52:43 +00:00
CrazyMax
405b217da0 ci(e2e): use org-owned Docker Hub credentials for e2e pushes
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-06-04 16:03:24 +02:00
CrazyMax
7b93b2b85c Merge pull request #1554 from crazy-max/e2e-ghcr
ci(e2e): use GITHUB_TOKEN for GHCR e2e
2026-06-04 16:00:12 +02:00
dependabot[bot]
27ef6d9c76 chore(deps): Bump actions/checkout from 6.0.2 to 6.0.3
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](de0fac2e45...df4cb1c069)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-04 00:14:44 +00:00
CrazyMax
f55bd083f2 ci(e2e): use GITHUB_TOKEN for GHCR e2e
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-06-02 14:18:39 +02:00
dependabot[bot]
1ff3662da6 chore(deps): Bump docker/setup-qemu-action from 4.0.0 to 4.1.0
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 4.0.0 to 4.1.0.
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](ce360397dd...06116385d9)

---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-29 12:40:56 +00:00
Tõnis Tiigi
1d0c110a5d Merge pull request #1548 from crazy-max/docs-link-secret-inputs
readme: link secret inputs to the GitHub Actions secrets guide
2026-05-28 17:30:01 -07:00
Tõnis Tiigi
8db8ba8e45 Merge pull request #1549 from crazy-max/ci-e2e-dockerhub-push-scope
ci(e2e): limit push-scoped login to Docker Hub
2026-05-28 17:29:24 -07:00
CrazyMax
abf612226d Merge pull request #1551 from crazy-max/yarn-update
update yarn to 4.15.0
2026-05-28 18:41:31 +02:00
CrazyMax
fe2165d9f3 update yarn to 4.15.0
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-05-28 15:13:15 +02:00
CrazyMax
77c0af9da9 ci(e2e): limit push-scoped login to Docker Hub
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-05-28 11:38:49 +02:00
CrazyMax
2258452e7c readme: link secret inputs to the GitHub Actions secrets guide
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-05-28 11:22:02 +02:00