Compare commits

...

65 Commits

Author SHA1 Message Date
github-actions[bot]
be18c6a1b1 [dependabot skip] chore: update generated content 2026-09-17 05:55:30 +00:00
dependabot[bot]
00b7db26e6 build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 updates
Bumps the aws-sdk-dependencies group with 2 updates in the / directory: [@aws-sdk/client-ecr](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ecr) and [@aws-sdk/client-ecr-public](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ecr-public).


Updates `@aws-sdk/client-ecr` from 3.1095.0 to 3.1132.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ecr/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1132.0/clients/client-ecr)

Updates `@aws-sdk/client-ecr-public` from 3.1095.0 to 3.1132.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ecr-public/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1132.0/clients/client-ecr-public)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-ecr"
  dependency-version: 3.1096.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk-dependencies
- dependency-name: "@aws-sdk/client-ecr-public"
  dependency-version: 3.1096.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-17 05:54:30 +00:00
CrazyMax
783ae9cac5 Merge pull request #1064 from docker/dependabot/github_actions/codeql-actions-ce612e0709
build(deps): bump the codeql-actions group across 1 directory with 2 updates
2026-09-16 10:57:53 +02:00
dependabot[bot]
b1725c2c93 build(deps): bump the codeql-actions group across 1 directory with 2 updates
Bumps the codeql-actions group with 2 updates in the / directory: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.37.3 to 4.37.8
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](e4fba868fa...db488ddef3)

Updates `github/codeql-action/analyze` from 4.37.3 to 4.37.8
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](e4fba868fa...db488ddef3)

---
updated-dependencies:
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-25 05:54:40 +00:00
CrazyMax
0a596b2e7a Merge pull request #1073 from quentin-laplanche-docker/ci/remove-docker-notation
ci: replace registry container action reference
2026-08-24 15:27:36 +02:00
Quentin Laplanche
5d1ee94869 ci: replace registry container action reference
Use a local Docker container action so the runner still exercises its container-action mounts and environment without a docker:// workflow reference.

Signed-off-by: Quentin Laplanche <quentin.laplanche@docker.com>

Co-authored-by: Codex <noreply@openai.com>
2026-08-24 15:15:07 +02:00
Tõnis Tiigi
af63523ba5 Merge pull request #1061 from docker/dockerhub-oidc-logs
log Docker Hub OIDC token exchange progress
2026-08-11 11:56:25 +03:00
CrazyMax
72edfa6c2e chore: update generated content
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-08-06 16:52:13 +02:00
CrazyMax
2b7517a3b4 log Docker Hub OIDC token exchange progress
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-08-06 16:51:47 +02:00
CrazyMax
eed2509203 Merge pull request #1068 from crazy-max/dockerhub-oidc-increase-expire-in
raise Docker Hub OIDC max expiry to 6 hours
2026-08-06 12:07:08 +02:00
CrazyMax
07573e7c18 chore: update generated content
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-08-06 11:54:13 +02:00
CrazyMax
99ffd0f38a raise Docker Hub OIDC max expiry to 6 hours
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-08-06 11:53:57 +02:00
CrazyMax
dbcb813823 Merge pull request #1051 from docker/dependabot/npm_and_yarn/aws-sdk-dependencies-46cc3261cb
build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 updates
2026-07-29 13:33:29 +02:00
github-actions[bot]
5bcb015ee6 [dependabot skip] chore: update generated content 2026-07-29 10:44:53 +00:00
dependabot[bot]
b30b2f2d31 build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 updates
Bumps the aws-sdk-dependencies group with 2 updates in the / directory: [@aws-sdk/client-ecr](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ecr) and [@aws-sdk/client-ecr-public](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ecr-public).


Updates `@aws-sdk/client-ecr` from 3.1091.0 to 3.1095.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ecr/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1095.0/clients/client-ecr)

Updates `@aws-sdk/client-ecr-public` from 3.1091.0 to 3.1095.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ecr-public/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1095.0/clients/client-ecr-public)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-ecr"
  dependency-version: 3.1092.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk-dependencies
- dependency-name: "@aws-sdk/client-ecr-public"
  dependency-version: 3.1092.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-29 10:43:57 +00:00
CrazyMax
9087f1e6d6 Merge pull request #1057 from docker/dependabot/npm_and_yarn/js-yaml-5.2.2
build(deps): bump js-yaml from 5.2.1 to 5.2.2
2026-07-29 12:40:51 +02:00
github-actions[bot]
0009830ea1 [dependabot skip] chore: update generated content 2026-07-29 10:32:28 +00:00
dependabot[bot]
23255232d3 build(deps): bump js-yaml from 5.2.1 to 5.2.2
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 5.2.1 to 5.2.2.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/5.2.1...5.2.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 5.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-29 10:31:34 +00:00
CrazyMax
4ec1d4a769 Merge pull request #1056 from docker/dependabot/npm_and_yarn/postcss-8.5.22
build(deps): bump postcss from 8.5.10 to 8.5.22
2026-07-29 12:28:53 +02:00
CrazyMax
5fc99ba47b Merge pull request #1053 from docker/dependabot/github_actions/aws-actions/configure-aws-credentials-6.2.3
build(deps): bump aws-actions/configure-aws-credentials from 6.2.2 to 6.2.3
2026-07-29 12:28:12 +02:00
CrazyMax
e512bd59d1 Merge pull request #1052 from docker/dependabot/github_actions/codeql-actions-73adf09e94
build(deps): bump the codeql-actions group across 1 directory with 2 updates
2026-07-29 12:26:59 +02:00
CrazyMax
a146c91b8f Merge pull request #1059 from crazy-max/harden-buildx-scope-paths
harden buildx scoped config path handling
2026-07-29 10:50:27 +02:00
CrazyMax
8ffd80ffa5 chore: update generated content
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-29 09:57:41 +02:00
CrazyMax
8305724bcf harden buildx scoped config path handling
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-29 09:57:00 +02:00
dependabot[bot]
91264757e1 build(deps): bump the codeql-actions group across 1 directory with 2 updates
Bumps the codeql-actions group with 2 updates in the / directory: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.37.2 to 4.37.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](e0647621c2...e4fba868fa)

Updates `github/codeql-action/analyze` from 4.37.2 to 4.37.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](e0647621c2...e4fba868fa)

---
updated-dependencies:
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-28 05:54:42 +00:00
CrazyMax
371161bbe7 Merge pull request #1058 from crazy-max/fix-dockerhub-oidc-error-handling
surface Docker Hub OIDC error responses
2026-07-27 18:30:08 +02:00
CrazyMax
5dc73df38e chore: update generated content
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-27 17:15:04 +02:00
CrazyMax
2aa1edee0b surface Docker Hub OIDC error responses
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-27 17:14:54 +02:00
dependabot[bot]
b472f5b276 build(deps): bump postcss from 8.5.10 to 8.5.22
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.10 to 8.5.22.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/postcss/postcss/compare/8.5.10...8.5.22)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.22
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-24 12:24:30 +00:00
CrazyMax
abd2ef45e7 Merge pull request #1055 from crazy-max/test-registry-auth-oidc
test: cover Docker Hub OIDC with registry-auth
2026-07-24 14:22:47 +02:00
CrazyMax
d49d3a9839 Merge pull request #1054 from crazy-max/oidc-missing-dhi
support dhi.io as Docker Hub OIDC registry
2026-07-24 14:22:20 +02:00
CrazyMax
b58b17c30b test: cover Docker Hub OIDC with registry-auth
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-24 10:37:01 +02:00
CrazyMax
be646c21ce chore: update generated content
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-24 10:33:14 +02:00
CrazyMax
d77c059cb9 support dhi.io as Docker Hub OIDC registry
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-24 10:26:38 +02:00
dependabot[bot]
9d876d6c33 build(deps): bump aws-actions/configure-aws-credentials
Bumps [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) from 6.2.2 to 6.2.3.
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](517a711dbc...e6de054238)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-24 05:54:30 +00:00
CrazyMax
06fb636fac Merge pull request #1037 from docker/dependabot/npm_and_yarn/aws-sdk-dependencies-001763bcc2
build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 updates
2026-07-23 13:48:53 +02:00
github-actions[bot]
a8bc953911 [dependabot skip] chore: update generated content 2026-07-23 11:45:23 +00:00
dependabot[bot]
f54b9019bf build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 updates
Bumps the aws-sdk-dependencies group with 2 updates in the / directory: [@aws-sdk/client-ecr](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ecr) and [@aws-sdk/client-ecr-public](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ecr-public).


Updates `@aws-sdk/client-ecr` from 3.1077.0 to 3.1091.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ecr/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1091.0/clients/client-ecr)

Updates `@aws-sdk/client-ecr-public` from 3.1077.0 to 3.1091.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ecr-public/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1091.0/clients/client-ecr-public)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-ecr"
  dependency-version: 3.1079.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk-dependencies
- dependency-name: "@aws-sdk/client-ecr-public"
  dependency-version: 3.1079.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-23 11:44:24 +00:00
CrazyMax
77f18f6713 Merge pull request #1049 from docker/dependabot/github_actions/codeql-actions-6a53124c02
build(deps): bump the codeql-actions group with 2 updates
2026-07-23 13:41:05 +02:00
CrazyMax
ec0bf287fb Merge pull request #1050 from docker/dependabot/npm_and_yarn/docker/actions-toolkit-0.94.0
build(deps): bump @docker/actions-toolkit from 0.93.0 to 0.94.0
2026-07-23 13:40:40 +02:00
github-actions[bot]
e37171e542 [dependabot skip] chore: update generated content 2026-07-23 11:36:42 +00:00
dependabot[bot]
1d3a7174ca build(deps): bump @docker/actions-toolkit from 0.93.0 to 0.94.0
Bumps [@docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.93.0 to 0.94.0.
- [Release notes](https://github.com/docker/actions-toolkit/releases)
- [Commits](https://github.com/docker/actions-toolkit/compare/v0.93.0...v0.94.0)

---
updated-dependencies:
- dependency-name: "@docker/actions-toolkit"
  dependency-version: 0.94.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-23 11:35:46 +00:00
CrazyMax
a5e9150fe2 Merge pull request #1048 from docker/dockerhub-oidc-support
Docker Hub OIDC login support
2026-07-23 13:24:10 +02:00
dependabot[bot]
a482ba4366 build(deps): bump the codeql-actions group with 2 updates
Bumps the codeql-actions group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.36.3 to 4.37.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](54f647b7e1...e0647621c2)

Updates `github/codeql-action/analyze` from 4.36.3 to 4.37.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](54f647b7e1...e0647621c2)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codeql-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codeql-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-23 05:54:58 +00:00
CrazyMax
9e3d36ea10 chore: update generated content
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-22 13:01:47 +02:00
CrazyMax
14d6a7934e docker hub oidc support
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-22 13:01:46 +02:00
CrazyMax
03c851098f Merge pull request #1044 from docker/dependabot/npm_and_yarn/docker/actions-toolkit-0.93.0
build(deps): bump @docker/actions-toolkit from 0.92.0 to 0.93.0
2026-07-22 08:53:04 +02:00
CrazyMax
ad8a81f098 Merge pull request #1046 from docker/dependabot/npm_and_yarn/brace-expansion-1.1.16
build(deps): bump brace-expansion from 1.1.13 to 1.1.16
2026-07-22 08:51:57 +02:00
github-actions[bot]
6d219a4928 [dependabot skip] chore: update generated content 2026-07-22 06:51:44 +00:00
dependabot[bot]
b3200694f4 build(deps): bump @docker/actions-toolkit from 0.92.0 to 0.93.0
Bumps [@docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.92.0 to 0.93.0.
- [Release notes](https://github.com/docker/actions-toolkit/releases)
- [Commits](https://github.com/docker/actions-toolkit/compare/v0.92.0...v0.93.0)

---
updated-dependencies:
- dependency-name: "@docker/actions-toolkit"
  dependency-version: 0.93.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-22 06:50:49 +00:00
github-actions[bot]
08d3680aa8 [dependabot skip] chore: update generated content 2026-07-22 06:50:38 +00:00
CrazyMax
381f5a4f5e Merge pull request #1042 from docker/dependabot/github_actions/codeql-actions-af2beed448
build(deps): bump the codeql-actions group with 2 updates
2026-07-22 08:49:44 +02:00
dependabot[bot]
4bc69ce4fd build(deps): bump brace-expansion from 1.1.13 to 1.1.16
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.13 to 1.1.16.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.13...v1.1.16)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.16
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-22 06:49:44 +00:00
CrazyMax
ddf94996dc Merge pull request #1043 from docker/dependabot/github_actions/actions/setup-node-7.0.0
build(deps): bump actions/setup-node from 6.4.0 to 7.0.0
2026-07-22 08:49:18 +02:00
CrazyMax
d870eb57d3 Merge pull request #1045 from docker/dependabot/github_actions/actions/checkout-7.0.1
build(deps): bump actions/checkout from 7.0.0 to 7.0.1
2026-07-22 08:48:31 +02:00
CrazyMax
4d7b1348c8 Merge pull request #1038 from docker/dependabot/npm_and_yarn/js-yaml-5.2.1
build(deps): bump js-yaml from 5.2.0 to 5.2.1
2026-07-22 08:47:43 +02:00
dependabot[bot]
608836776e build(deps): bump actions/checkout from 7.0.0 to 7.0.1
Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](9c091bb21b...3d3c42e5aa)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-21 05:52:59 +00:00
dependabot[bot]
3bab31f360 build(deps): bump actions/setup-node from 6.4.0 to 7.0.0
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.4.0 to 7.0.0.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](48b55a011b...8207627860)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-15 05:52:18 +00:00
dependabot[bot]
dc654b7be1 build(deps): bump the codeql-actions group with 2 updates
Bumps the codeql-actions group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.36.2 to 4.36.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](8aad20d150...54f647b7e1)

Updates `github/codeql-action/analyze` from 4.36.2 to 4.36.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](8aad20d150...54f647b7e1)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.36.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.36.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 12:01:00 +00:00
CrazyMax
c66a8fcb24 Merge pull request #1041 from crazy-max/group-codeql-dependabot-updates
chore: group codeql dependabot updates
2026-07-09 13:57:49 +02:00
CrazyMax
6d7f9d458a chore: group codeql dependabot updates
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-09 12:43:17 +02:00
CrazyMax
13169716da Merge pull request #1040 from docker/dependabot/github_actions/aws-actions/configure-aws-credentials-6.2.2
build(deps): bump aws-actions/configure-aws-credentials from 6.2.1 to 6.2.2
2026-07-09 10:17:14 +02:00
dependabot[bot]
c1aa9e5f45 build(deps): bump aws-actions/configure-aws-credentials
Bumps [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) from 6.2.1 to 6.2.2.
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](254c19bd24...517a711dbc)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 05:53:39 +00:00
github-actions[bot]
026f3975fd [dependabot skip] chore: update generated content 2026-07-06 05:55:36 +00:00
dependabot[bot]
3dbb99fd00 build(deps): bump js-yaml from 5.2.0 to 5.2.1
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 5.2.0 to 5.2.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/5.2.0...5.2.1)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 5.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-06 05:54:34 +00:00
21 changed files with 1078 additions and 443 deletions

View File

@@ -0,0 +1,3 @@
FROM docker:29.3@sha256:4d90f1f6c400315c2dba96d3ec93c01e64198395cbba04f79d12adce4f737029
ENTRYPOINT ["docker"]

15
.github/actions/docker-pull/action.yml vendored Normal file
View File

@@ -0,0 +1,15 @@
name: Pull Docker image
description: Pull an image from a Docker container action
inputs:
image:
description: Image reference to pull
required: true
runs:
using: docker
image: Dockerfile
args:
- pull
- ${{ inputs.image }}

View File

@@ -10,6 +10,9 @@ updates:
crazy-max-dot-github: crazy-max-dot-github:
patterns: patterns:
- "crazy-max/.github/*" - "crazy-max/.github/*"
codeql-actions:
patterns:
- "github/codeql-action/*"
labels: labels:
- "dependencies" - "dependencies"
- "bot" - "bot"

View File

@@ -25,7 +25,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Stop docker name: Stop docker
run: | run: |
@@ -49,7 +49,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to GitHub Container Registry name: Login to GitHub Container Registry
uses: ./ uses: ./
@@ -67,7 +67,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to GitHub Container Registry name: Login to GitHub Container Registry
uses: ./ uses: ./
@@ -97,7 +97,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to GitHub Container Registry name: Login to GitHub Container Registry
uses: ./ uses: ./
@@ -106,11 +106,10 @@ jobs:
username: ${{ github.actor }} username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }} password: ${{ secrets.GITHUB_TOKEN }}
- -
name: DinD name: Pull test image from Docker CLI container action
uses: docker://docker:29.3@sha256:4d90f1f6c400315c2dba96d3ec93c01e64198395cbba04f79d12adce4f737029 uses: ./.github/actions/docker-pull
with: with:
entrypoint: docker image: ${{ env.GHCR_TEST_IMAGE }}
args: pull ${{ env.GHCR_TEST_IMAGE }}
- -
name: Pull test image name: Pull test image
run: | run: |
@@ -122,7 +121,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to ACR name: Login to ACR
uses: ./ uses: ./
@@ -142,7 +141,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to Docker Hub name: Login to Docker Hub
uses: ./ uses: ./
@@ -150,6 +149,50 @@ jobs:
username: ${{ vars.DOCKERPUBLICBOT_USERNAME }} username: ${{ vars.DOCKERPUBLICBOT_USERNAME }}
password: ${{ secrets.DOCKERPUBLICBOT_READ_PAT }} password: ${{ secrets.DOCKERPUBLICBOT_READ_PAT }}
dockerhub-oidc:
permissions:
contents: read
id-token: write
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os:
- ubuntu-latest
- windows-latest
steps:
-
name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
-
name: Login to Docker Hub with OIDC
uses: ./
env:
DOCKERHUB_OIDC_CONNECTIONID: ${{ vars.DOCKERHUB_OIDC_CONNECTIONID }}
with:
username: ${{ vars.DOCKERHUB_OIDC_USERNAME }}
registry-auth-oidc:
permissions:
contents: read
id-token: write
runs-on: ubuntu-latest
steps:
-
name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
-
name: Login to registries
uses: ./
env:
DOCKERHUB_OIDC_CONNECTIONID: ${{ vars.DOCKERHUB_OIDC_CONNECTIONID }}
with:
registry-auth: |
- username: ${{ vars.DOCKERHUB_OIDC_USERNAME }}
- registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
ecr: ecr:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
strategy: strategy:
@@ -161,7 +204,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to ECR name: Login to ECR
uses: ./ uses: ./
@@ -181,10 +224,10 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Configure AWS Credentials name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@254c19bd240aabef8777f48595e9d2d7b972184b # v6.2.1 uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
with: with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
@@ -209,10 +252,10 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Configure AWS Credentials name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@254c19bd240aabef8777f48595e9d2d7b972184b # v6.2.1 uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
with: with:
role-to-assume: arn:aws:iam::175142243308:role/official_gha_cicd_login_action role-to-assume: arn:aws:iam::175142243308:role/official_gha_cicd_login_action
aws-region: us-east-1 aws-region: us-east-1
@@ -233,7 +276,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to Public ECR name: Login to Public ECR
continue-on-error: ${{ matrix.os == 'windows-latest' }} continue-on-error: ${{ matrix.os == 'windows-latest' }}
@@ -256,10 +299,10 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Configure AWS Credentials name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@254c19bd240aabef8777f48595e9d2d7b972184b # v6.2.1 uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
with: with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
@@ -285,10 +328,10 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Configure AWS Credentials name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@254c19bd240aabef8777f48595e9d2d7b972184b # v6.2.1 uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
with: with:
role-to-assume: arn:aws:iam::175142243308:role/official_gha_cicd_login_action role-to-assume: arn:aws:iam::175142243308:role/official_gha_cicd_login_action
aws-region: us-east-1 aws-region: us-east-1
@@ -310,7 +353,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to GitHub Container Registry name: Login to GitHub Container Registry
uses: ./ uses: ./
@@ -330,7 +373,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to GitLab name: Login to GitLab
uses: ./ uses: ./
@@ -350,7 +393,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to Google Artifact Registry name: Login to Google Artifact Registry
uses: ./ uses: ./
@@ -370,7 +413,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to Google Container Registry name: Login to Google Container Registry
uses: ./ uses: ./
@@ -384,7 +427,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to registries name: Login to registries
uses: ./ uses: ./
@@ -407,7 +450,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to registries name: Login to registries
uses: ./ uses: ./
@@ -428,7 +471,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to registries name: Login to registries
id: login id: login
@@ -460,7 +503,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to Docker Hub name: Login to Docker Hub
uses: ./ uses: ./
@@ -490,7 +533,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to Docker Hub name: Login to Docker Hub
uses: ./ uses: ./
@@ -520,7 +563,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to GitHub Container Registry name: Login to GitHub Container Registry
uses: ./ uses: ./
@@ -551,7 +594,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Login to GitHub Container Registry name: Login to GitHub Container Registry
uses: ./ uses: ./

View File

@@ -22,7 +22,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Enable corepack name: Enable corepack
run: | run: |
@@ -30,17 +30,17 @@ jobs:
yarn --version yarn --version
- -
name: Set up Node name: Set up Node
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with: with:
node-version: ${{ env.NODE_VERSION }} node-version: ${{ env.NODE_VERSION }}
- -
name: Initialize CodeQL name: Initialize CodeQL
uses: github/codeql-action/init@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 uses: github/codeql-action/init@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8
with: with:
languages: javascript-typescript languages: javascript-typescript
build-mode: none build-mode: none
- -
name: Perform CodeQL Analysis name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 uses: github/codeql-action/analyze@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8
with: with:
category: "/language:javascript-typescript" category: "/language:javascript-typescript"

View File

@@ -22,7 +22,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Publish name: Publish
uses: actions/publish-immutable-action@4bc8754ffc40f27910afb20287dbbbb675a4e978 # v0.0.4 uses: actions/publish-immutable-action@4bc8754ffc40f27910afb20287dbbbb675a4e978 # v0.0.4

View File

@@ -20,7 +20,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Test name: Test
uses: docker/bake-action@d3418bd7d0e9324001bca92fa8ba175ea7e6dc9b # v7.3.0 uses: docker/bake-action@d3418bd7d0e9324001bca92fa8ba175ea7e6dc9b # v7.3.0

View File

@@ -30,7 +30,7 @@ jobs:
permission-contents: write permission-contents: write
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with: with:
ref: ${{ github.event.pull_request.head.ref }} ref: ${{ github.event.pull_request.head.ref }}
fetch-depth: 0 fetch-depth: 0

View File

@@ -22,7 +22,7 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- -
name: Generate matrix name: Generate matrix
id: generate id: generate

View File

@@ -28,6 +28,7 @@ ___
* [Set scopes for the authentication token](#set-scopes-for-the-authentication-token) * [Set scopes for the authentication token](#set-scopes-for-the-authentication-token)
* [Customizing](#customizing) * [Customizing](#customizing)
* [inputs](#inputs) * [inputs](#inputs)
* [environment variables](#environment-variables)
* [Contributing](#contributing) * [Contributing](#contributing)
## Usage ## Usage
@@ -57,6 +58,36 @@ jobs:
password: ${{ secrets.DOCKERHUB_TOKEN }} password: ${{ secrets.DOCKERHUB_TOKEN }}
``` ```
You can also [authenticate to Docker Hub with OpenID Connect](https://docs.docker.com/enterprise/security/oidc-connections/)
when your Docker Hub organization has an OIDC connection configured. The
workflow must grant the `id-token: write` permission, pass the Docker Hub
organization name as `username`, omit `password`, and set the OIDC connection
ID in `DOCKERHUB_OIDC_CONNECTIONID` environment variable.
```yaml
name: ci
on:
push:
branches: main
permissions:
contents: read
id-token: write
jobs:
login:
runs-on: ubuntu-latest
steps:
-
name: Login to Docker Hub
uses: docker/login-action@v4
env:
DOCKERHUB_OIDC_CONNECTIONID: ${{ vars.DOCKERHUB_OIDC_CONNECTIONID }}
with:
username: ${{ vars.DOCKERHUB_ORGANIZATION }}
```
### GitHub Container Registry ### GitHub Container Registry
To authenticate to the [GitHub Container Registry](https://docs.github.com/en/packages/working-with-a-github-packages-registry/working-with-the-container-registry), To authenticate to the [GitHub Container Registry](https://docs.github.com/en/packages/working-with-a-github-packages-registry/working-with-the-container-registry),
@@ -617,6 +648,38 @@ jobs:
password: ${{ secrets.GITHUB_TOKEN }} password: ${{ secrets.GITHUB_TOKEN }}
``` ```
Docker Hub OIDC can also be used with `registry-auth`. Grant `id-token: write`,
set `DOCKERHUB_OIDC_CONNECTIONID`, pass the Docker Hub organization name as
`username`, and omit `password` for the Docker Hub object:
```yaml
name: ci
on:
push:
branches: main
permissions:
contents: read
id-token: write
jobs:
login:
runs-on: ubuntu-latest
steps:
-
name: Login to registries
uses: docker/login-action@v4
env:
DOCKERHUB_OIDC_CONNECTIONID: ${{ vars.DOCKERHUB_OIDC_CONNECTIONID }}
with:
registry-auth: |
- username: ${{ vars.DOCKERHUB_ORGANIZATION }}
- registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
```
### Set scopes for the authentication token ### Set scopes for the authentication token
The `scope` input allows limiting registry credentials to a specific repository The `scope` input allows limiting registry credentials to a specific repository
@@ -690,6 +753,15 @@ The following inputs can be used as `step.with` keys:
> [!NOTE] > [!NOTE]
> The `registry-auth` input cannot be used with other inputs except `logout`. > The `registry-auth` input cannot be used with other inputs except `logout`.
### environment variables
The following environment variables can be set as `step.env` keys:
| Name | Type | Default | Description |
|-------------------------------|--------|---------|----------------------------------------------------------------------------------------------------|
| `DOCKERHUB_OIDC_CONNECTIONID` | String | | Docker Hub OIDC connection ID. Required for Docker Hub OIDC login |
| `DOCKERHUB_OIDC_EXPIREIN` | Number | `300` | Docker Hub OIDC token lifetime in seconds. Must be between `300` (5 minutes) and `21600` (6 hours) |
## Contributing ## Contributing
Want to contribute? Awesome! You can find information about contributing to Want to contribute? Awesome! You can find information about contributing to

View File

@@ -35,6 +35,87 @@ test('getAuthList uses the default Docker Hub registry when computing scoped con
}); });
}); });
test('getAuthList supports @ scopes appended to the registry config dir', async () => {
process.env['INPUT_USERNAME'] = 'dbowie';
process.env['INPUT_PASSWORD'] = 'groundcontrol';
process.env['INPUT_SCOPE'] = '@push';
process.env['INPUT_LOGOUT'] = 'false';
const [auth] = getAuthList(getInputs());
expect(auth).toMatchObject({
configDir: path.join(Buildx.configDir, 'config', 'registry-1.docker.io') + '@push'
});
});
test('getAuthList supports repository scopes with appended actions', async () => {
process.env['INPUT_USERNAME'] = 'dbowie';
process.env['INPUT_PASSWORD'] = 'groundcontrol';
process.env['INPUT_SCOPE'] = 'docker/buildx-bin@push';
process.env['INPUT_LOGOUT'] = 'false';
const [auth] = getAuthList(getInputs());
expect(auth).toMatchObject({
configDir: path.join(Buildx.configDir, 'config', 'registry-1.docker.io', 'docker', 'buildx-bin@push')
});
});
test('getAuthList supports comma-separated scope actions', async () => {
process.env['INPUT_USERNAME'] = 'dbowie';
process.env['INPUT_PASSWORD'] = 'groundcontrol';
process.env['INPUT_SCOPE'] = 'docker/buildx-bin@pull,push';
process.env['INPUT_LOGOUT'] = 'false';
const [auth] = getAuthList(getInputs());
expect(auth).toMatchObject({
configDir: path.join(Buildx.configDir, 'config', 'registry-1.docker.io', 'docker', 'buildx-bin@pull,push')
});
});
// prettier-ignore
test.each([
'../../../../work/leaked',
'..',
'foo/../../../../etc',
'@../../../leaked',
'foo/bar@../../../leaked',
'@push@pull',
'foo/bar@push@pull',
'@push,',
'@,push',
'@pull,,push',
'@Push',
path.join(path.parse(Buildx.configDir).root, 'work', 'leaked')
])('getAuthList rejects unsafe or unsupported scope path: %s', async scope => {
expect(() => {
getAuthList({
registry: '',
username: 'dbowie',
password: 'groundcontrol',
scope,
ecr: '',
logout: false,
registryAuth: ''
});
}).toThrow(/Invalid scope/);
});
// prettier-ignore
test.each([
'../../../../work/leaked',
'..',
'foo/../../../../etc',
path.join(path.parse(Buildx.configDir).root, 'work', 'leaked')
])('getAuthList rejects unsafe registry path: %s', async registry => {
expect(() => {
getAuthList({
registry,
username: 'dbowie',
password: 'groundcontrol',
scope: '@push',
ecr: '',
logout: false,
registryAuth: ''
});
}).toThrow(/Invalid registry/);
});
test('getAuthList skips secret masking when registry-auth password is absent', async () => { test('getAuthList skips secret masking when registry-auth password is absent', async () => {
const stdoutWriteSpy = vi.spyOn(process.stdout, 'write').mockImplementation(() => true); const stdoutWriteSpy = vi.spyOn(process.stdout, 'write').mockImplementation(() => true);
const [auth] = getAuthList({ const [auth] = getAuthList({
@@ -54,6 +135,25 @@ test('getAuthList skips secret masking when registry-auth password is absent', a
}); });
}); });
test('getAuthList supports password-less Docker Hub registry-auth for OIDC', async () => {
const [auth] = getAuthList({
registry: '',
username: '',
password: '',
scope: '',
ecr: '',
logout: true,
registryAuth: '- username: docker-org\n'
});
expect(auth).toMatchObject({
registry: 'docker.io',
username: 'docker-org',
password: undefined,
ecr: 'auto'
});
});
test('getAuthList masks registry-auth password when present', async () => { test('getAuthList masks registry-auth password when present', async () => {
const stdoutWriteSpy = vi.spyOn(process.stdout, 'write').mockImplementation(() => true); const stdoutWriteSpy = vi.spyOn(process.stdout, 'write').mockImplementation(() => true);
getAuthList({ getAuthList({

View File

@@ -1,8 +1,14 @@
import {expect, test, vi} from 'vitest'; import {afterEach, expect, test, vi} from 'vitest';
import {Docker} from '@docker/actions-toolkit/lib/docker/docker.js'; import {Docker} from '@docker/actions-toolkit/lib/docker/docker.js';
import {loginStandard, logout} from '../src/docker.js'; import {login, loginStandard, logout} from '../src/docker.js';
import * as dockerhub from '../src/dockerhub.js';
afterEach(() => {
vi.restoreAllMocks();
delete process.env.DOCKERHUB_OIDC_CONNECTIONID;
});
test('loginStandard calls exec', async () => { test('loginStandard calls exec', async () => {
const execSpy = vi.spyOn(Docker, 'getExecOutput').mockImplementation(async () => { const execSpy = vi.spyOn(Docker, 'getExecOutput').mockImplementation(async () => {
@@ -32,6 +38,37 @@ test('loginStandard calls exec', async () => {
}); });
}); });
test('login exchanges Docker Hub OIDC token for password-less auth', async () => {
process.env.DOCKERHUB_OIDC_CONNECTIONID = '123e4567-e89b-42d3-a456-426614174000';
const execSpy = vi.spyOn(Docker, 'getExecOutput').mockImplementation(async () => {
return {
exitCode: 0,
stdout: '',
stderr: ''
};
});
const oidcSpy = vi.spyOn(dockerhub, 'getOIDCToken').mockResolvedValue({
username: 'docker-org',
token: 'hub-token'
});
await login({
registry: 'docker.io',
username: 'docker-org',
password: '',
scope: '',
ecr: 'auto',
configDir: ''
});
expect(oidcSpy).toHaveBeenCalledWith('docker.io', 'docker-org');
expect(execSpy).toHaveBeenCalledWith(['login', '--password-stdin', '--username', 'docker-org', 'docker.io'], {
input: Buffer.from('hub-token'),
silent: true,
ignoreReturnCode: true
});
});
test('logout calls exec', async () => { test('logout calls exec', async () => {
const execSpy = vi.spyOn(Docker, 'getExecOutput').mockImplementation(async () => { const execSpy = vi.spyOn(Docker, 'getExecOutput').mockImplementation(async () => {
return { return {

149
__tests__/dockerhub.test.ts Normal file
View File

@@ -0,0 +1,149 @@
import * as core from '@actions/core';
import * as httpm from '@actions/http-client';
import {beforeEach, describe, expect, test, vi} from 'vitest';
import * as dockerhub from '../src/dockerhub.js';
vi.mock('@actions/core', () => ({
debug: vi.fn(),
getIDToken: vi.fn(),
info: vi.fn(),
setSecret: vi.fn()
}));
const validConnectionID = '123e4567-e89b-42d3-a456-426614174000';
const httpResponse = (statusCode: number, body: string, headers: Record<string, string> = {}): httpm.HttpClientResponse => {
return {
message: {
statusCode,
headers
},
readBody: vi.fn(async () => body)
} as unknown as httpm.HttpClientResponse;
};
describe('isDockerHubOIDC', () => {
beforeEach(() => {
delete process.env.DOCKERHUB_OIDC_CONNECTIONID;
});
test.each(['', 'docker.io', 'registry-1.docker.io', 'registry-1-stage.docker.io'])('detects Docker Hub registry %p with empty password', registry => {
process.env.DOCKERHUB_OIDC_CONNECTIONID = validConnectionID;
expect(dockerhub.isDockerHubOIDC(registry, '')).toBe(true);
});
test('requires connection ID env var', () => {
expect(dockerhub.isDockerHubOIDC('docker.io', '')).toBe(false);
});
test('requires empty password', () => {
process.env.DOCKERHUB_OIDC_CONNECTIONID = validConnectionID;
expect(dockerhub.isDockerHubOIDC('docker.io', 'groundcontrol')).toBe(false);
});
test('ignores non-Docker Hub registries', () => {
process.env.DOCKERHUB_OIDC_CONNECTIONID = validConnectionID;
expect(dockerhub.isDockerHubOIDC('ghcr.io', '')).toBe(false);
});
});
describe('getOIDCToken', () => {
const getIDTokenMock = vi.mocked(core.getIDToken);
const setSecretMock = vi.mocked(core.setSecret);
let postSpy: ReturnType<typeof vi.spyOn>;
beforeEach(() => {
process.env.DOCKERHUB_OIDC_CONNECTIONID = validConnectionID;
delete process.env.DOCKERHUB_OIDC_EXPIREIN;
getIDTokenMock.mockResolvedValue('github-id-token');
postSpy = vi.spyOn(httpm.HttpClient.prototype, 'post').mockResolvedValue(httpResponse(200, JSON.stringify({access_token: 'hub-token'})));
});
test('exchanges GitHub OIDC token for Docker Hub token', async () => {
const credentials = await dockerhub.getOIDCToken('docker.io', 'dbowie');
expect(credentials).toEqual({
username: 'dbowie',
token: 'hub-token'
});
expect(getIDTokenMock).toHaveBeenCalledWith('https://identity.docker.com');
expect(postSpy).toHaveBeenCalledTimes(1);
expect(postSpy.mock.calls[0][0]).toBe('https://identity.docker.com/oauth/token');
const http = postSpy.mock.contexts[0] as httpm.HttpClient;
expect(http.userAgent).toBe('github.com/docker/login-action');
expect(http.requestOptions?.headers).toEqual({
'Content-Type': 'application/x-www-form-urlencoded'
});
const body = new URLSearchParams(postSpy.mock.calls[0][1]);
expect(body.get('grant_type')).toBe('urn:ietf:params:oauth:grant-type:token-exchange');
expect(body.get('subject_token_type')).toBe('urn:ietf:params:oauth:token-type:id_token');
expect(body.get('subject_token')).toBe('github-id-token');
expect(body.get('connection_id')).toBe(validConnectionID);
expect(body.get('expires_in')).toBe('300');
expect(setSecretMock).toHaveBeenCalledWith('hub-token');
expect(core.info).toHaveBeenCalledWith('Docker Hub OIDC detected for docker.io');
expect(core.info).toHaveBeenCalledWith('Retrieving GitHub OIDC token for Docker Hub');
expect(core.info).toHaveBeenCalledWith('Exchanging GitHub OIDC token for Docker Hub token');
expect(core.info).toHaveBeenCalledWith('Docker Hub OIDC token exchange succeeded');
expect(core.debug).toHaveBeenCalledWith('Docker Hub OIDC token audience: https://identity.docker.com');
expect(core.debug).toHaveBeenCalledWith('Docker Hub OIDC token expiration: 300s');
expect(core.debug).toHaveBeenCalledWith('Sending Docker Hub OIDC token request to https://identity.docker.com/oauth/token');
expect(core.debug).toHaveBeenCalledWith('Docker Hub OIDC token request returned status code 200');
expect(core.debug).toHaveBeenCalledWith('Docker Hub OIDC token response status code: 200');
});
test('uses custom token expiration', async () => {
process.env.DOCKERHUB_OIDC_EXPIREIN = '21600';
await dockerhub.getOIDCToken('docker.io', 'dbowie');
const body = new URLSearchParams(postSpy.mock.calls[0][1]);
expect(body.get('expires_in')).toBe('21600');
});
test('uses stage identity host for stage registry', async () => {
await dockerhub.getOIDCToken('registry-1-stage.docker.io', 'dbowie');
expect(getIDTokenMock).toHaveBeenCalledWith('https://identity-stage.docker.com');
expect(postSpy.mock.calls[0][0]).toBe('https://identity-stage.docker.com/oauth/token');
});
test('requires connection ID env var', async () => {
delete process.env.DOCKERHUB_OIDC_CONNECTIONID;
await expect(dockerhub.getOIDCToken('docker.io', 'dbowie')).rejects.toThrow('DOCKERHUB_OIDC_CONNECTIONID is required for Docker Hub OIDC login');
expect(getIDTokenMock).not.toHaveBeenCalled();
expect(postSpy).not.toHaveBeenCalled();
});
test('validates connection ID', async () => {
process.env.DOCKERHUB_OIDC_CONNECTIONID = 'not-a-uuid';
await expect(dockerhub.getOIDCToken('docker.io', 'dbowie')).rejects.toThrow('Invalid DOCKERHUB_OIDC_CONNECTIONID. Must be a valid UUID.');
expect(getIDTokenMock).not.toHaveBeenCalled();
expect(postSpy).not.toHaveBeenCalled();
});
test.each(['not-a-number', '299', '21601'])('validates token expiration %p', async expiresIn => {
process.env.DOCKERHUB_OIDC_EXPIREIN = expiresIn;
await expect(dockerhub.getOIDCToken('docker.io', 'dbowie')).rejects.toThrow(`Invalid DOCKERHUB_OIDC_EXPIREIN: ${expiresIn}. Must be between 300 and 21600`);
expect(getIDTokenMock).not.toHaveBeenCalled();
expect(postSpy).not.toHaveBeenCalled();
});
test('retries rate limited token requests with Retry-After', async () => {
postSpy.mockResolvedValueOnce(httpResponse(429, '', {'retry-after': '0'})).mockResolvedValueOnce(httpResponse(200, JSON.stringify({access_token: 'hub-token'})));
await dockerhub.getOIDCToken('docker.io', 'dbowie');
expect(postSpy).toHaveBeenCalledTimes(2);
expect(core.info).toHaveBeenCalledWith('Docker Hub OIDC token request rate limited, retrying in 0ms (attempt 1/5)');
});
test('throws Docker Hub OIDC error responses', async () => {
postSpy.mockResolvedValue(httpResponse(400, JSON.stringify({error: 'invalid_request', error_description: 'bad connection', error_uri: 'https://docs.docker.com'})));
await expect(dockerhub.getOIDCToken('docker.io', 'dbowie')).rejects.toThrow('Docker Hub API: bad status code 400: {"error":"invalid_request","error_description":"bad connection","error_uri":"https://docs.docker.com"}');
});
test('throws rate limited Docker Hub OIDC error response after retries', async () => {
postSpy.mockResolvedValue(httpResponse(429, JSON.stringify({error: 'rate_limited', error_description: 'slow down'}), {'retry-after': '0'}));
await expect(dockerhub.getOIDCToken('docker.io', 'dbowie')).rejects.toThrow('Docker Hub API: bad status code 429: {"error":"rate_limited","error_description":"slow down"}');
expect(postSpy).toHaveBeenCalledTimes(6);
});
});

271
dist/index.cjs generated vendored

File diff suppressed because one or more lines are too long

8
dist/index.cjs.map generated vendored

File diff suppressed because one or more lines are too long

79
dist/licenses.txt generated vendored
View File

@@ -3,7 +3,7 @@ https://www.npmjs.com/package/generate-license-file
The following npm package may be included in this product: The following npm package may be included in this product:
- @aws/lambda-invoke-store@0.2.3 - @aws/lambda-invoke-store@0.3.0
This package contains the following license: This package contains the following license:
@@ -399,7 +399,7 @@ Apache License
The following npm package may be included in this product: The following npm package may be included in this product:
- @docker/actions-toolkit@0.92.0 - @docker/actions-toolkit@0.94.0
This package contains the following license: This package contains the following license:
@@ -1913,8 +1913,8 @@ Apache License
The following npm packages may be included in this product: The following npm packages may be included in this product:
- @aws-sdk/client-ecr-public@3.1077.0 - @aws-sdk/client-ecr-public@3.1132.0
- @aws-sdk/client-ecr@3.1077.0 - @aws-sdk/client-ecr@3.1132.0
These packages each contain the following license: These packages each contain the following license:
@@ -2124,9 +2124,9 @@ Apache License
The following npm packages may be included in this product: The following npm packages may be included in this product:
- @aws-sdk/signature-v4-multi-region@3.996.37 - @aws-sdk/signature-v4-multi-region@3.996.46
- @smithy/core@3.28.0 - @smithy/core@3.34.1
- @smithy/types@4.15.0 - @smithy/types@4.18.0
These packages each contain the following license: These packages each contain the following license:
@@ -2396,11 +2396,12 @@ SOFTWARE.
----------- -----------
The following npm package may be included in this product: The following npm packages may be included in this product:
- js-yaml@5.2.0 - js-yaml@5.2.1
- js-yaml@5.2.2
This package contains the following license: These packages each contain the following license:
(The MIT License) (The MIT License)
@@ -3175,7 +3176,7 @@ software or this license, under any kind of legal claim.***
The following npm package may be included in this product: The following npm package may be included in this product:
- @aws-sdk/core@3.974.25 - @aws-sdk/core@3.978.0
This package contains the following license: This package contains the following license:
@@ -3385,16 +3386,16 @@ Apache License
The following npm packages may be included in this product: The following npm packages may be included in this product:
- @aws-sdk/credential-provider-env@3.972.51 - @aws-sdk/credential-provider-env@3.972.71
- @aws-sdk/credential-provider-ini@3.972.58 - @aws-sdk/credential-provider-ini@3.973.16
- @aws-sdk/credential-provider-node@3.972.60 - @aws-sdk/credential-provider-node@3.972.83
- @aws-sdk/token-providers@3.1077.0 - @aws-sdk/token-providers@3.1129.0
- @aws-sdk/types@3.973.14 - @aws-sdk/types@3.974.5
- @aws-sdk/xml-builder@3.972.32 - @aws-sdk/xml-builder@3.972.40
- @smithy/credential-provider-imds@4.4.4 - @smithy/credential-provider-imds@4.5.2
- @smithy/fetch-http-handler@5.6.1 - @smithy/fetch-http-handler@5.8.0
- @smithy/node-http-handler@4.9.1 - @smithy/node-http-handler@4.12.1
- @smithy/signature-v4@5.6.0 - @smithy/signature-v4@5.7.3
These packages each contain the following license: These packages each contain the following license:
@@ -3604,9 +3605,9 @@ Apache License
The following npm packages may be included in this product: The following npm packages may be included in this product:
- @aws-sdk/credential-provider-process@3.972.51 - @aws-sdk/credential-provider-process@3.972.71
- @aws-sdk/credential-provider-sso@3.972.57 - @aws-sdk/credential-provider-sso@3.973.15
- @aws-sdk/credential-provider-web-identity@3.972.57 - @aws-sdk/credential-provider-web-identity@3.972.77
These packages each contain the following license: These packages each contain the following license:
@@ -3880,9 +3881,9 @@ END OF TERMS AND CONDITIONS
The following npm packages may be included in this product: The following npm packages may be included in this product:
- @aws-sdk/credential-provider-http@3.972.53 - @aws-sdk/credential-provider-http@3.972.73
- @aws-sdk/credential-provider-login@3.972.57 - @aws-sdk/credential-provider-login@3.972.78
- @aws-sdk/nested-clients@3.997.25 - @aws-sdk/nested-clients@3.997.45
- @sigstore/verify@4.1.0 - @sigstore/verify@4.1.0
These packages each contain the following license: These packages each contain the following license:
@@ -4590,7 +4591,7 @@ USE OR OTHER DEALINGS IN THE SOFTWARE.
The following npm packages may be included in this product: The following npm packages may be included in this product:
- brace-expansion@1.1.13 - brace-expansion@1.1.16
- brace-expansion@2.0.3 - brace-expansion@2.0.3
These packages each contain the following license: These packages each contain the following license:
@@ -5562,7 +5563,7 @@ THE SOFTWARE.
The following npm package may be included in this product: The following npm package may be included in this product:
- csv-parse@7.0.0 - csv-parse@7.0.1
This package contains the following license: This package contains the following license:
@@ -5590,6 +5591,24 @@ SOFTWARE.
----------- -----------
The following npm package may be included in this product:
- uuid@14.0.1
This package contains the following license:
The MIT License (MIT)
Copyright (c) 2010-2020 Robert Kieffer and other contributors
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
-----------
The following npm package may be included in this product: The following npm package may be included in this product:
- tunnel@0.0.6 - tunnel@0.0.6
@@ -6207,7 +6226,7 @@ THE SOFTWARE.
The following npm packages may be included in this product: The following npm packages may be included in this product:
- @actions/artifact@6.2.1 - @actions/artifact@6.2.1
- @actions/cache@6.1.0 - @actions/cache@6.2.0
- @actions/core@3.0.0 - @actions/core@3.0.0
- @actions/core@3.0.1 - @actions/core@3.0.1
- @actions/exec@3.0.0 - @actions/exec@3.0.0

View File

@@ -24,12 +24,14 @@
"packageManager": "yarn@4.15.0", "packageManager": "yarn@4.15.0",
"dependencies": { "dependencies": {
"@actions/core": "^3.0.1", "@actions/core": "^3.0.1",
"@aws-sdk/client-ecr": "^3.1077.0", "@actions/http-client": "^4.0.1",
"@aws-sdk/client-ecr-public": "^3.1077.0", "@aws-sdk/client-ecr": "^3.1132.0",
"@docker/actions-toolkit": "^0.92.0", "@aws-sdk/client-ecr-public": "^3.1132.0",
"@docker/actions-toolkit": "^0.94.0",
"http-proxy-agent": "^9.1.0", "http-proxy-agent": "^9.1.0",
"https-proxy-agent": "^9.1.0", "https-proxy-agent": "^9.1.0",
"js-yaml": "^5.2.0" "js-yaml": "^5.2.2",
"uuid": "^14.0.1"
}, },
"devDependencies": { "devDependencies": {
"@eslint/js": "^9.39.3", "@eslint/js": "^9.39.3",

View File

@@ -77,13 +77,33 @@ export function scopeToConfigDir(registry: string, scope?: string): string {
if (scopeDisabled() || !scope || scope === '') { if (scopeDisabled() || !scope || scope === '') {
return ''; return '';
} }
let configDir = path.join(Buildx.configDir, 'config', registry === 'docker.io' ? 'registry-1.docker.io' : registry); const configRoot = path.resolve(Buildx.configDir, 'config');
if (scope.startsWith('@')) { const registryDir = path.resolve(configRoot, registry === 'docker.io' ? 'registry-1.docker.io' : registry);
configDir += scope; if (!isChildPath(configRoot, registryDir)) {
} else { throw new Error(`Invalid registry '${registry}': resolved config path escapes the Buildx config directory`);
configDir = path.join(configDir, scope);
} }
return configDir; const scopeParts = scope.split('@');
if (scopeParts.length > 2) {
throw new Error(`Invalid scope '${scope}': scope can contain at most one @ separator`);
}
const [scopePath, scopeActions] = scopeParts;
if (scopeActions !== undefined && !/^[a-z]+(,[a-z]+)*$/.test(scopeActions)) {
throw new Error(`Invalid scope '${scope}': scope actions must be lowercase names separated by commas`);
}
const scopeSuffix = scopeActions === undefined ? '' : `@${scopeActions}`;
if (scopePath === '') {
return `${registryDir}${scopeSuffix}`;
}
const configDir = path.resolve(registryDir, scopePath);
if (!isChildPath(registryDir, configDir)) {
throw new Error(`Invalid scope '${scope}': resolved config path escapes the Buildx config directory`);
}
return `${configDir}${scopeSuffix}`;
}
function isChildPath(parent: string, child: string): boolean {
const relativePath = path.relative(parent, child);
return relativePath !== '' && relativePath !== '..' && !relativePath.startsWith(`..${path.sep}`) && !path.isAbsolute(relativePath);
} }
function scopeDisabled(): boolean { function scopeDisabled(): boolean {

View File

@@ -4,12 +4,20 @@ import {Docker} from '@docker/actions-toolkit/lib/docker/docker.js';
import * as aws from './aws.js'; import * as aws from './aws.js';
import * as context from './context.js'; import * as context from './context.js';
import * as dockerhub from './dockerhub.js';
export async function login(auth: context.Auth): Promise<void> { export async function login(auth: context.Auth): Promise<void> {
if (/true/i.test(auth.ecr) || (auth.ecr == 'auto' && aws.isECR(auth.registry))) { if (/true/i.test(auth.ecr) || (auth.ecr == 'auto' && aws.isECR(auth.registry))) {
await loginECR(auth.registry, auth.username, auth.password, auth.scope); await loginECR(auth.registry, auth.username, auth.password, auth.scope);
} else { } else {
await loginStandard(auth.registry, auth.username, auth.password, auth.scope); let username = auth.username;
let password = auth.password;
if (dockerhub.isDockerHubOIDC(auth.registry, password)) {
const credentials = await dockerhub.getOIDCToken(auth.registry, username);
username = credentials.username;
password = credentials.token;
}
await loginStandard(auth.registry, username, password, auth.scope);
} }
} }

137
src/dockerhub.ts Normal file
View File

@@ -0,0 +1,137 @@
import * as core from '@actions/core';
import * as httpm from '@actions/http-client';
import {HttpCodes} from '@actions/http-client';
import {validate as uuidValidate} from 'uuid';
export interface LoginCredentials {
username: string;
token: string;
}
interface OIDCTokenResponse {
access_token: string;
}
const registries = new Set(['', 'docker.io', 'registry-1.docker.io', 'registry-1-stage.docker.io', 'dhi.io']);
const defaultExpiresIn = 300;
const minExpiresIn = 300;
const maxExpiresIn = 21600;
const maxRetries = 5;
export const isDockerHubOIDC = (registry: string, password: string): boolean => {
return process.env.DOCKERHUB_OIDC_CONNECTIONID !== undefined && !password && registries.has(registry);
};
export const getOIDCToken = async (registry: string, username: string): Promise<LoginCredentials> => {
const connectionID = process.env.DOCKERHUB_OIDC_CONNECTIONID?.trim();
if (!connectionID) {
throw new Error('DOCKERHUB_OIDC_CONNECTIONID is required for Docker Hub OIDC login');
}
if (!uuidValidate(connectionID)) {
throw new Error('Invalid DOCKERHUB_OIDC_CONNECTIONID. Must be a valid UUID.');
}
const expiresIn = getExpiresIn();
const identityHost = registry === 'registry-1-stage.docker.io' ? 'identity-stage.docker.com' : 'identity.docker.com';
const audience = `https://${identityHost}`;
core.info(`Docker Hub OIDC detected for ${registry || 'docker.io'}`);
core.debug(`Docker Hub OIDC token audience: ${audience}`);
core.debug(`Docker Hub OIDC token expiration: ${expiresIn}s`);
core.info(`Retrieving GitHub OIDC token for Docker Hub`);
const idToken = await core.getIDToken(audience);
const http: httpm.HttpClient = new httpm.HttpClient('github.com/docker/login-action', [], {
headers: {
'Content-Type': 'application/x-www-form-urlencoded'
}
});
const data = new URLSearchParams();
data.set('grant_type', 'urn:ietf:params:oauth:grant-type:token-exchange');
data.set('subject_token_type', 'urn:ietf:params:oauth:token-type:id_token');
data.set('subject_token', idToken);
data.set('connection_id', connectionID);
data.set('expires_in', expiresIn.toString());
core.info(`Exchanging GitHub OIDC token for Docker Hub token`);
const resp = await postWithRetry(http, `https://${identityHost}/oauth/token`, data.toString());
const tokenResp = <OIDCTokenResponse>JSON.parse(await handleResponse(resp));
core.setSecret(tokenResp.access_token);
core.info(`Docker Hub OIDC token exchange succeeded`);
return {
username,
token: tokenResp.access_token
};
};
const getExpiresIn = (): number => {
const expiresInInput = process.env.DOCKERHUB_OIDC_EXPIREIN?.trim() || defaultExpiresIn.toString();
const expiresIn = Number(expiresInInput);
if (isNaN(expiresIn) || expiresIn < minExpiresIn || expiresIn > maxExpiresIn) {
throw new Error(`Invalid DOCKERHUB_OIDC_EXPIREIN: ${expiresInInput}. Must be between ${minExpiresIn} and ${maxExpiresIn}`);
}
return expiresIn;
};
const postWithRetry = async (http: httpm.HttpClient, url: string, data: string): Promise<httpm.HttpClientResponse> => {
core.debug(`Sending Docker Hub OIDC token request to ${url}`);
let resp = await http.post(url, data);
core.debug(`Docker Hub OIDC token request returned status code ${resp.message.statusCode || HttpCodes.InternalServerError}`);
for (let attempt = 0; (resp.message.statusCode || HttpCodes.InternalServerError) === HttpCodes.TooManyRequests && attempt < maxRetries; attempt++) {
const delay = parseRetryAfter(resp.message.headers['retry-after']);
if (delay === null) {
core.debug(`Docker Hub OIDC token request rate limited without retry-after header`);
break;
}
await resp.readBody();
core.info(`Docker Hub OIDC token request rate limited, retrying in ${delay}ms (attempt ${attempt + 1}/${maxRetries})`);
await new Promise(resolve => setTimeout(resolve, delay));
resp = await http.post(url, data);
core.debug(`Docker Hub OIDC token request returned status code ${resp.message.statusCode || HttpCodes.InternalServerError}`);
}
return resp;
};
const parseRetryAfter = (value: string | string[] | undefined): number | null => {
if (value === undefined) {
return null;
}
if (Array.isArray(value)) {
value = value[0];
}
const seconds = Number(value);
if (isNaN(seconds)) {
return null;
}
return Math.max(0, seconds * 1000);
};
const handleResponse = async (resp: httpm.HttpClientResponse): Promise<string> => {
const body = await resp.readBody();
const statusCode = resp.message.statusCode || HttpCodes.InternalServerError;
core.debug(`Docker Hub OIDC token response status code: ${statusCode}`);
if (statusCode < HttpCodes.OK || statusCode >= HttpCodes.MultipleChoices) {
throw parseError(statusCode, body);
}
return body;
};
const parseError = (statusCode: number, body: string): Error => {
if (body) {
let errResp: unknown;
try {
errResp = JSON.parse(body);
} catch {
errResp = undefined;
}
if (errResp !== undefined) {
throw new Error(`Docker Hub API: bad status code ${statusCode}: ${JSON.stringify(errResp)}`);
}
}
if (statusCode === 401) {
throw new Error(`Docker Hub API: operation not permitted`);
}
throw new Error(`Docker Hub API: bad status code ${statusCode}`);
};

470
yarn.lock
View File

@@ -34,9 +34,9 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"@actions/cache@npm:^6.1.0": "@actions/cache@npm:^6.2.0":
version: 6.1.0 version: 6.2.0
resolution: "@actions/cache@npm:6.1.0" resolution: "@actions/cache@npm:6.2.0"
dependencies: dependencies:
"@actions/core": "npm:^3.0.1" "@actions/core": "npm:^3.0.1"
"@actions/exec": "npm:^3.0.0" "@actions/exec": "npm:^3.0.0"
@@ -47,7 +47,7 @@ __metadata:
"@azure/storage-blob": "npm:^12.31.0" "@azure/storage-blob": "npm:^12.31.0"
"@protobuf-ts/runtime-rpc": "npm:^2.11.1" "@protobuf-ts/runtime-rpc": "npm:^2.11.1"
semver: "npm:^7.7.4" semver: "npm:^7.7.4"
checksum: 10/0cd89f335c1e89f514d56060110bfddc6ab1112ec0091533364c32aec2621896112cde71cfc4089b86d00f3b5478996088e4c4e0aba0aec32aae0afeb4921b3d checksum: 10/b2b3d219d3458b6b7e8f47ff6a83a0566f0b3cd5b257e307636d2147f892e595ce8cecbc0675590a57d0eb4d4d73564d08d28753baa50934ad59a65cbee2d8fa
languageName: node languageName: node
linkType: hard linkType: hard
@@ -170,244 +170,244 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/client-ecr-public@npm:^3.1077.0": "@aws-sdk/client-ecr-public@npm:^3.1132.0":
version: 3.1077.0 version: 3.1132.0
resolution: "@aws-sdk/client-ecr-public@npm:3.1077.0" resolution: "@aws-sdk/client-ecr-public@npm:3.1132.0"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.978.0"
"@aws-sdk/credential-provider-node": "npm:^3.972.60" "@aws-sdk/credential-provider-node": "npm:^3.972.83"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.5"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.33.3"
"@smithy/fetch-http-handler": "npm:^5.6.1" "@smithy/fetch-http-handler": "npm:^5.7.2"
"@smithy/node-http-handler": "npm:^4.9.1" "@smithy/node-http-handler": "npm:^4.11.3"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/916cf62d4db13bfcecc8023b26e9cdcc69e1df9c7daa7cbbe8b205998ccb9443251cae24fe3a06f5f20d2fbffee4e400e0714c2963dc75536a3482fd60544f53 checksum: 10/f38abe9a4ac11397d7659364d17187855cb2c4b36c5598b341864d41e50bbcfd1c9eb32daaff885c5735e9b927eaf6d6c5e53351062c0dea3ecd279bafc801e4
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/client-ecr@npm:^3.1077.0": "@aws-sdk/client-ecr@npm:^3.1132.0":
version: 3.1077.0 version: 3.1132.0
resolution: "@aws-sdk/client-ecr@npm:3.1077.0" resolution: "@aws-sdk/client-ecr@npm:3.1132.0"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.978.0"
"@aws-sdk/credential-provider-node": "npm:^3.972.60" "@aws-sdk/credential-provider-node": "npm:^3.972.83"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.5"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.33.3"
"@smithy/fetch-http-handler": "npm:^5.6.1" "@smithy/fetch-http-handler": "npm:^5.7.2"
"@smithy/node-http-handler": "npm:^4.9.1" "@smithy/node-http-handler": "npm:^4.11.3"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/5c70110f9a3cac414701b97710ae40147e1e982ab6239ccd6a839f8726f490b548874fc4e4d968ccc548bdc187cd2864b54c2d3d5ed3bfe32285e555c6a413a8 checksum: 10/7653b26457215d4c6fe19a792f3cde91ea771fd5077d4415c731eb17ce13f26e87ba2c37771dc7fef0c397ab191ef99418972e308df011049e4b375878995b1c
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/core@npm:^3.974.25": "@aws-sdk/core@npm:^3.978.0":
version: 3.974.25 version: 3.978.0
resolution: "@aws-sdk/core@npm:3.974.25" resolution: "@aws-sdk/core@npm:3.978.0"
dependencies: dependencies:
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.5"
"@aws-sdk/xml-builder": "npm:^3.972.32" "@aws-sdk/xml-builder": "npm:^3.972.40"
"@aws/lambda-invoke-store": "npm:^0.2.2" "@aws/lambda-invoke-store": "npm:^0.3.0"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.33.3"
"@smithy/signature-v4": "npm:^5.6.0" "@smithy/signature-v4": "npm:^5.6.12"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
bowser: "npm:^2.11.0" bowser: "npm:^2.11.0"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/25ca1498913983d8f7c2f25485d3c825e9b23a48b15eeac3e695b70fd6393f815f644b4ca11bc8145eff2dec5cbee06360ae7bcf76b5fd9dbb214fd80abe81be checksum: 10/90747cbe497f71c90d5867c918e276338f2cae0d622f96ac359228792fe91ba6ec2ab30d14334556ad9e6afd4080f50edd514165b408b14088c3ea39101bd6dc
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/credential-provider-env@npm:^3.972.51": "@aws-sdk/credential-provider-env@npm:^3.972.71":
version: 3.972.51 version: 3.972.71
resolution: "@aws-sdk/credential-provider-env@npm:3.972.51" resolution: "@aws-sdk/credential-provider-env@npm:3.972.71"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.978.0"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.5"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.33.3"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/3e745169838f44f26828a6c860e32d662d9b52be6d7b63dd2407028b53567fdd24b8a2e92bfb27da73c2f71e07a051a17722bfe0c7dd5a665a0d3f302812a148 checksum: 10/f8e123108bcc9aabfee5ded9fdba3ec2a112f31cd0378704783089676fdff9782337414c15f9ad2cf95ac2695e343b317b0e3c05aea56ae11f181f08536a809e
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/credential-provider-http@npm:^3.972.53": "@aws-sdk/credential-provider-http@npm:^3.972.73":
version: 3.972.53 version: 3.972.73
resolution: "@aws-sdk/credential-provider-http@npm:3.972.53" resolution: "@aws-sdk/credential-provider-http@npm:3.972.73"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.978.0"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.5"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.33.3"
"@smithy/fetch-http-handler": "npm:^5.6.1" "@smithy/fetch-http-handler": "npm:^5.7.2"
"@smithy/node-http-handler": "npm:^4.9.1" "@smithy/node-http-handler": "npm:^4.11.3"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/94247a81a8d0235c3eb14a2e8ac41b70314efa585ca62d0c16c0293f96a2d2f1d0b0ed947d6e15e46d0fdc565725d6d2a37d5e847523995d11f21fe254eb0094 checksum: 10/05d13079ee8a56f91621c4ba6874e9c154b30720a7eb8e0f4f99a55e53cc9a1f108bacfb010d43d0bc6a0b0e7609c26c6fb924936734dff5a1a670ec0a21415a
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/credential-provider-ini@npm:^3.972.58": "@aws-sdk/credential-provider-ini@npm:^3.973.16":
version: 3.972.58 version: 3.973.16
resolution: "@aws-sdk/credential-provider-ini@npm:3.972.58" resolution: "@aws-sdk/credential-provider-ini@npm:3.973.16"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.978.0"
"@aws-sdk/credential-provider-env": "npm:^3.972.51" "@aws-sdk/credential-provider-env": "npm:^3.972.71"
"@aws-sdk/credential-provider-http": "npm:^3.972.53" "@aws-sdk/credential-provider-http": "npm:^3.972.73"
"@aws-sdk/credential-provider-login": "npm:^3.972.57" "@aws-sdk/credential-provider-login": "npm:^3.972.78"
"@aws-sdk/credential-provider-process": "npm:^3.972.51" "@aws-sdk/credential-provider-process": "npm:^3.972.71"
"@aws-sdk/credential-provider-sso": "npm:^3.972.57" "@aws-sdk/credential-provider-sso": "npm:^3.973.15"
"@aws-sdk/credential-provider-web-identity": "npm:^3.972.57" "@aws-sdk/credential-provider-web-identity": "npm:^3.972.77"
"@aws-sdk/nested-clients": "npm:^3.997.25" "@aws-sdk/nested-clients": "npm:^3.997.45"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.5"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.33.3"
"@smithy/credential-provider-imds": "npm:^4.4.4" "@smithy/credential-provider-imds": "npm:^4.4.16"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/d9d0024c120fbe0de0a6436fe7d5fd8056549cfd630f385b389d131417cf06ba6848c56a45b0afad5fdeec6b850d2c1dc91fc165d47a671d904e9e1facd7001b checksum: 10/eaa41b1b7b5b897e52b05236efc8c6a1251fe67a6dfd96bc79a205a73f3f7089534569500784cac29e29cce75db9ef98087cad1345e011bfeab856b88981cca8
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/credential-provider-login@npm:^3.972.57": "@aws-sdk/credential-provider-login@npm:^3.972.78":
version: 3.972.57 version: 3.972.78
resolution: "@aws-sdk/credential-provider-login@npm:3.972.57" resolution: "@aws-sdk/credential-provider-login@npm:3.972.78"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.978.0"
"@aws-sdk/nested-clients": "npm:^3.997.25" "@aws-sdk/nested-clients": "npm:^3.997.45"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.5"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.33.3"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/22b24eedad0620c15ed78f6e02a6add822357c778acd452adf76a492a41a6750654aa01bd6a7877ee4cf96968988b305dbaf9a15278989f7960dddb53a11ddd0 checksum: 10/2e0ba744c29a4e43847cf2de41c2c38694a3be45fbabb85fa2c4410d5b9e2013e5ee9be9e37280561b0105f97d654137fccefd08704c81272d5c04ba9537fbaa
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/credential-provider-node@npm:^3.972.60": "@aws-sdk/credential-provider-node@npm:^3.972.83":
version: 3.972.60 version: 3.972.83
resolution: "@aws-sdk/credential-provider-node@npm:3.972.60" resolution: "@aws-sdk/credential-provider-node@npm:3.972.83"
dependencies: dependencies:
"@aws-sdk/credential-provider-env": "npm:^3.972.51" "@aws-sdk/credential-provider-env": "npm:^3.972.71"
"@aws-sdk/credential-provider-http": "npm:^3.972.53" "@aws-sdk/credential-provider-http": "npm:^3.972.73"
"@aws-sdk/credential-provider-ini": "npm:^3.972.58" "@aws-sdk/credential-provider-ini": "npm:^3.973.16"
"@aws-sdk/credential-provider-process": "npm:^3.972.51" "@aws-sdk/credential-provider-process": "npm:^3.972.71"
"@aws-sdk/credential-provider-sso": "npm:^3.972.57" "@aws-sdk/credential-provider-sso": "npm:^3.973.15"
"@aws-sdk/credential-provider-web-identity": "npm:^3.972.57" "@aws-sdk/credential-provider-web-identity": "npm:^3.972.77"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.5"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.33.3"
"@smithy/credential-provider-imds": "npm:^4.4.4" "@smithy/credential-provider-imds": "npm:^4.4.16"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/5249e3bf1ded99f207ef8b4c80c4c19ab934115304790916def3f29877061c850e3089f71fd65cca3688327763175837a86f5afa100ef926c9749782ca0b7a44 checksum: 10/1b192bd6ae4ea086fe170ccb0a52607c37097a0718bace0a6f1e9edb65e3faa0bbcfc26e875bc65f4fa9501fed3e390478e2aaaaf0d1a57b062cfcc79b22cebb
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/credential-provider-process@npm:^3.972.51": "@aws-sdk/credential-provider-process@npm:^3.972.71":
version: 3.972.51 version: 3.972.71
resolution: "@aws-sdk/credential-provider-process@npm:3.972.51" resolution: "@aws-sdk/credential-provider-process@npm:3.972.71"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.978.0"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.5"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.33.3"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/bdbd1dbd6aadbc8737b03ff776fc3b9c8d7c773214f35113ac7cb796f56bbb9ae141cf282b15a5a17b77c5f06133a28fdbd363053772f5aad9021bd08d777e8d checksum: 10/4c35fe38e12b0215062b54b92f3fdcf482de724f10aaaaf4655c8914bee8963eedf849f836317678bb9c2b56e275287accdd7b84b94e6a5fedd6172420beb782
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/credential-provider-sso@npm:^3.972.57": "@aws-sdk/credential-provider-sso@npm:^3.973.15":
version: 3.972.57 version: 3.973.15
resolution: "@aws-sdk/credential-provider-sso@npm:3.972.57" resolution: "@aws-sdk/credential-provider-sso@npm:3.973.15"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.978.0"
"@aws-sdk/nested-clients": "npm:^3.997.25" "@aws-sdk/nested-clients": "npm:^3.997.45"
"@aws-sdk/token-providers": "npm:3.1077.0" "@aws-sdk/token-providers": "npm:3.1129.0"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.5"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.33.3"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/53fa4e00bcedd8673ac271503dfe452d3c4076ac780bb381012b0f71732511dcb63e83211b544db1f0bedc667925629af5dc5b3b5fa0e8c11372a4211cbf135d checksum: 10/f6e2578b6cab31a8dc573244c5f379338015bba34ca22a2240e204734642fbd18f3b75460ea3b8173e985a26edd6b9de07e598402745d4ac6f9568e0ea9882fd
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/credential-provider-web-identity@npm:^3.972.57": "@aws-sdk/credential-provider-web-identity@npm:^3.972.77":
version: 3.972.57 version: 3.972.77
resolution: "@aws-sdk/credential-provider-web-identity@npm:3.972.57" resolution: "@aws-sdk/credential-provider-web-identity@npm:3.972.77"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.978.0"
"@aws-sdk/nested-clients": "npm:^3.997.25" "@aws-sdk/nested-clients": "npm:^3.997.45"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.5"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.33.3"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/e3db324879b623695584fe4e591a360d930c82dc276fea4d344e537df29c1c821c52886562af51008573d0357e132fe6676a99ac49b545368f8e82ebd94a58f4 checksum: 10/15c4000a526a6416e6c7698c3f634a691275e0c5774efaa4151d8c2c08738c7b411451c0ebb7d5603789d006448743c8aa0cddd967500e0fe42afacd87d08d1b
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/nested-clients@npm:^3.997.25": "@aws-sdk/nested-clients@npm:^3.997.45":
version: 3.997.25 version: 3.997.45
resolution: "@aws-sdk/nested-clients@npm:3.997.25" resolution: "@aws-sdk/nested-clients@npm:3.997.45"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.978.0"
"@aws-sdk/signature-v4-multi-region": "npm:^3.996.37" "@aws-sdk/signature-v4-multi-region": "npm:^3.996.46"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.5"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.33.3"
"@smithy/fetch-http-handler": "npm:^5.6.1" "@smithy/fetch-http-handler": "npm:^5.7.2"
"@smithy/node-http-handler": "npm:^4.9.1" "@smithy/node-http-handler": "npm:^4.11.3"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/6e9507477672572d90e7802526f133b9956adb6306f401b51c1f76b55b60e93297943d9927e531cecba63303a157757bfadbf14524e164688a515e351f57d9de checksum: 10/56124872e9062187f319d3c97f99252cc2826a7c1128d86944adf20bc1f64bff84bc88c40e5f14deb16e0bf8fd5aac6f6be4ae3c116cb0bb0a306945e134817b
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/signature-v4-multi-region@npm:^3.996.37": "@aws-sdk/signature-v4-multi-region@npm:^3.996.46":
version: 3.996.37 version: 3.996.46
resolution: "@aws-sdk/signature-v4-multi-region@npm:3.996.37" resolution: "@aws-sdk/signature-v4-multi-region@npm:3.996.46"
dependencies: dependencies:
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.5"
"@smithy/signature-v4": "npm:^5.6.0" "@smithy/signature-v4": "npm:^5.6.12"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/16608054281ae2b29c409ef772572f27d51c05269efc5965bfb2a72405675fb2449087d635f62e9e6438a73cf2edad15c1161287ddb2672ad8f08e8bc598df0a checksum: 10/2f32c081210ba41f24f0adee3fbcdf8486d91b12c023cb6414e77dadd66737e472016c142154696fa97afd1bcdc3b1a0d3c3f9695ee2b0369ec1867d110fb65f
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/token-providers@npm:3.1077.0": "@aws-sdk/token-providers@npm:3.1129.0":
version: 3.1077.0 version: 3.1129.0
resolution: "@aws-sdk/token-providers@npm:3.1077.0" resolution: "@aws-sdk/token-providers@npm:3.1129.0"
dependencies: dependencies:
"@aws-sdk/core": "npm:^3.974.25" "@aws-sdk/core": "npm:^3.978.0"
"@aws-sdk/nested-clients": "npm:^3.997.25" "@aws-sdk/nested-clients": "npm:^3.997.45"
"@aws-sdk/types": "npm:^3.973.14" "@aws-sdk/types": "npm:^3.974.5"
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.33.3"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/7b026fd9a234c52424dba53c86208143dc87b009efee933cee5522ac815e77ac567cc25fba013df34b3616268697f36737ad47c4a9e274da57519d4c5cf024f4 checksum: 10/1d53d8d70f4939e765ae1bde296111655bd70d05d6464dbc9e1833d20be62946b8651b36ca1553b49fdfd65068bb2a0ef2e8a59167dd229632e97a72ab593649
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/types@npm:^3.973.14": "@aws-sdk/types@npm:^3.974.5":
version: 3.973.14 version: 3.974.5
resolution: "@aws-sdk/types@npm:3.973.14" resolution: "@aws-sdk/types@npm:3.974.5"
dependencies: dependencies:
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/2c960877e3d5bb83b81a2974bc8aab86baa83053179e8fb1a77fde223138a64f5e14bc95d20146292af7eed499dd2b38aefd47ae68b5f746828abea8532e96a8 checksum: 10/df23a788b562adc18c5833f07e5591a57428b74893e0603cba5866de9a4f7c3f3878a678a2509267a71be65265f9f5983276ab1c182bfbb98ba586c005d50fb4
languageName: node languageName: node
linkType: hard linkType: hard
"@aws-sdk/xml-builder@npm:^3.972.32": "@aws-sdk/xml-builder@npm:^3.972.40":
version: 3.972.32 version: 3.972.40
resolution: "@aws-sdk/xml-builder@npm:3.972.32" resolution: "@aws-sdk/xml-builder@npm:3.972.40"
dependencies: dependencies:
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/d42371e477fb55823d406fac361bd2288af56284c52265dfeaa60191f90fc4f9105760df23e803fd5e1ea7bb14cd2567bb101e551d06417dad8bbd16568cf452 checksum: 10/d23f0c0bc289045960982181d6979d0535fca6516a57e79ad3845bd6a5166d38a3ca4e755fc77c9fc674c55ec8f68eac2d4ccbda289d846a3734c572a08d6dc3
languageName: node languageName: node
linkType: hard linkType: hard
"@aws/lambda-invoke-store@npm:^0.2.2": "@aws/lambda-invoke-store@npm:^0.3.0":
version: 0.2.3 version: 0.3.0
resolution: "@aws/lambda-invoke-store@npm:0.2.3" resolution: "@aws/lambda-invoke-store@npm:0.3.0"
checksum: 10/d0efa8ca73b2d8dc0bf634525eefa1b72cda85f5d47366264849343a6f2860cfa5c52b7f766a16b78da8406bbd3ee975da3abb1dbe38183f8af95413eafeb256 checksum: 10/4a6c7af16477dd330d4dcd2269f89370be68295b54ae1e90ef8c2175efa4df6735f9a3f914ab7efa21ba7db5477031fe8488853adcd268eeb6cb8e34ad06b206
languageName: node languageName: node
linkType: hard linkType: hard
@@ -677,12 +677,12 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"@docker/actions-toolkit@npm:^0.92.0": "@docker/actions-toolkit@npm:^0.94.0":
version: 0.92.0 version: 0.94.0
resolution: "@docker/actions-toolkit@npm:0.92.0" resolution: "@docker/actions-toolkit@npm:0.94.0"
dependencies: dependencies:
"@actions/artifact": "npm:^6.2.1" "@actions/artifact": "npm:^6.2.1"
"@actions/cache": "npm:^6.1.0" "@actions/cache": "npm:^6.2.0"
"@actions/core": "npm:^3.0.1" "@actions/core": "npm:^3.0.1"
"@actions/exec": "npm:^3.0.0" "@actions/exec": "npm:^3.0.0"
"@actions/github": "npm:^9.1.1" "@actions/github": "npm:^9.1.1"
@@ -693,16 +693,16 @@ __metadata:
"@sigstore/tuf": "npm:^5.0.0" "@sigstore/tuf": "npm:^5.0.0"
"@sigstore/verify": "npm:^4.1.0" "@sigstore/verify": "npm:^4.1.0"
async-retry: "npm:^1.3.3" async-retry: "npm:^1.3.3"
csv-parse: "npm:^7.0.0" csv-parse: "npm:^7.0.1"
gunzip-maybe: "npm:^1.4.2" gunzip-maybe: "npm:^1.4.2"
handlebars: "npm:^4.7.9" handlebars: "npm:^4.7.9"
he: "npm:^1.2.0" he: "npm:^1.2.0"
js-yaml: "npm:^5.2.0" js-yaml: "npm:^5.2.1"
jwt-decode: "npm:^4.0.0" jwt-decode: "npm:^4.0.0"
semver: "npm:^7.8.5" semver: "npm:^7.8.5"
tar-stream: "npm:^3.2.0" tar-stream: "npm:^3.2.0"
tmp: "npm:^0.2.7" tmp: "npm:^0.2.7"
checksum: 10/599cea84b897069c53744a2f05371c6d9ad60da18448b4431273529b92fd2d77ddc718ee205cf0bf1da53083d412da90b1067f1e64a5fdac73fe71d486726064 checksum: 10/96f7b3e488dd50db0b77575e1a2bd7e92506b1a2695d5c31a57d361e4dc07871ef1a14a7ab87bf6fe27af2f817d34351c2e289446b126675a20d9776fe5ab8ce
languageName: node languageName: node
linkType: hard linkType: hard
@@ -1956,66 +1956,66 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"@smithy/core@npm:^3.28.0": "@smithy/core@npm:^3.33.2, @smithy/core@npm:^3.33.3":
version: 3.28.0 version: 3.34.1
resolution: "@smithy/core@npm:3.28.0" resolution: "@smithy/core@npm:3.34.1"
dependencies: dependencies:
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.18.0"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/b8fe9db961112b8dd36b48c9d692d0cbe83be3a5962b51874f52079a22595674a9bc30c01bb3868da74e0c9ab328cac1f71405982432434be3e5d9d57777b5d7 checksum: 10/e5f1af592334ffb7a4d5bafa851f00d276246398d7aebc1261ee83148282903e0de004ea987a626e05dc5bafe2cb58e338e5bd87b89fd4d54b83a2caf5a0af5b
languageName: node languageName: node
linkType: hard linkType: hard
"@smithy/credential-provider-imds@npm:^4.4.4": "@smithy/credential-provider-imds@npm:^4.4.16":
version: 4.4.4 version: 4.5.2
resolution: "@smithy/credential-provider-imds@npm:4.4.4" resolution: "@smithy/credential-provider-imds@npm:4.5.2"
dependencies: dependencies:
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.33.2"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/47950acf6e89480592466fec4e7e5d6eed8ff9b939d76ef83a584b39067c593ce06df2616f354fda084b284af1406ac9a82d759a38623066b28ad7efe05a736b checksum: 10/5db260066aa97e2a7eca5258ff1c1dd1234cd2ed28e3b7ec36cbcf578007878853fa787cb48df2fd070fb0440a8c537d628344b1fd4ec589aaa2fa154d150b3e
languageName: node languageName: node
linkType: hard linkType: hard
"@smithy/fetch-http-handler@npm:^5.6.1": "@smithy/fetch-http-handler@npm:^5.7.2":
version: 5.6.1 version: 5.8.0
resolution: "@smithy/fetch-http-handler@npm:5.6.1" resolution: "@smithy/fetch-http-handler@npm:5.8.0"
dependencies: dependencies:
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.33.3"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.18.0"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/e7a841ef750fcfd936e274cd1bd011d0749328d7597e9d5ba8ed286be883fde25e6629315428502aec343c072c826ed512dd26a08ee33609884812cbbc1e2d84 checksum: 10/9f5374a6d2db6a1314393a05f9500efc0b73a0ef9d491a9e64aab6fdc8e0ce39214a5ec0b6af3bf5c948e452c7f91f91b0cda13d3325399276811392b3ac36b7
languageName: node languageName: node
linkType: hard linkType: hard
"@smithy/node-http-handler@npm:^4.9.1": "@smithy/node-http-handler@npm:^4.11.3":
version: 4.9.1 version: 4.12.1
resolution: "@smithy/node-http-handler@npm:4.9.1" resolution: "@smithy/node-http-handler@npm:4.12.1"
dependencies: dependencies:
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.33.3"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.18.0"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/d12b489b301b71767036a33c3c6736f4f37ea5ae8f147b054acbebaf3a5b02df05cba38b764813fa0cd24cde3c3faa22842bda31e0840bb4d79dd737f801d82e checksum: 10/291ab9053afeefc7f6524c18dd5ade4aab42af7fddba7d5c087c23c23d4d686fc9f6674c5c28aa1af708d93db9fc2be18999cd64bbbbed8b88f2004a0aa37bbf
languageName: node languageName: node
linkType: hard linkType: hard
"@smithy/signature-v4@npm:^5.6.0": "@smithy/signature-v4@npm:^5.6.12":
version: 5.6.0 version: 5.7.3
resolution: "@smithy/signature-v4@npm:5.6.0" resolution: "@smithy/signature-v4@npm:5.7.3"
dependencies: dependencies:
"@smithy/core": "npm:^3.28.0" "@smithy/core": "npm:^3.33.3"
"@smithy/types": "npm:^4.15.0" "@smithy/types": "npm:^4.17.2"
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/e4036321b89bc522d2c1edad6e70151c155dc0e4780a0d828cfdf941d5f8a871fda50912e7b9ed87172916761e84e50030b05f020523873232877b3f814f0b8c checksum: 10/8f18091aedd508ac746570b1eb811fd30147112dc359909d8400d155f759bdda16a8f1b03ddfdb641190e18f8fac8915be151b2d68e200c58b1c6821800502f8
languageName: node languageName: node
linkType: hard linkType: hard
"@smithy/types@npm:^4.15.0": "@smithy/types@npm:^4.17.2, @smithy/types@npm:^4.18.0":
version: 4.15.0 version: 4.18.0
resolution: "@smithy/types@npm:4.15.0" resolution: "@smithy/types@npm:4.18.0"
dependencies: dependencies:
tslib: "npm:^2.6.2" tslib: "npm:^2.6.2"
checksum: 10/e41a84ec3eb9feb45040ccd541b1cacf0fc2375297802886459cb9311ff361080978c08ef98e9ad69f41d80ad212279d682a8fe30a993381b2f1dd376c1006c3 checksum: 10/18719c5ae8eef71ef10d79e8628b528a9f0aede5fb036c9a798f676b7b4a35efd10fc0d3b7e1f8921746c66c4ae2a8277570f99a0545fbc4eae6c994997f83cd
languageName: node languageName: node
linkType: hard linkType: hard
@@ -2762,12 +2762,12 @@ __metadata:
linkType: hard linkType: hard
"brace-expansion@npm:^1.1.7": "brace-expansion@npm:^1.1.7":
version: 1.1.13 version: 1.1.16
resolution: "brace-expansion@npm:1.1.13" resolution: "brace-expansion@npm:1.1.16"
dependencies: dependencies:
balanced-match: "npm:^1.0.0" balanced-match: "npm:^1.0.0"
concat-map: "npm:0.0.1" concat-map: "npm:0.0.1"
checksum: 10/b5f4329fdbe9d2e25fa250c8f866ebd054ba946179426e99b86dcccddabdb1d481f0e40ee5430032e62a7d0a6c2837605ace6783d015aa1d65d85ca72154d936 checksum: 10/94498bead66c51536df5b7bf1b0a0e581a5b7f86888be10481d06920c4bd9d976e003b13a3d19fddc733f21a09d162ff72f90e18b2c9d062b15121e973d0e13b
languageName: node languageName: node
linkType: hard linkType: hard
@@ -3103,10 +3103,10 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"csv-parse@npm:^7.0.0": "csv-parse@npm:^7.0.1":
version: 7.0.0 version: 7.0.1
resolution: "csv-parse@npm:7.0.0" resolution: "csv-parse@npm:7.0.1"
checksum: 10/53c96e6b4ff80047713bb4d2967d06495890d4b628284a80271860be089fdb5a74cd97c76fd535a00ad26b11cc6e4fc5a243658e5377c0a6334ddd104620d169 checksum: 10/5c914f01181dbb381068b98e17b49361d853faa95db3e8e82bc96b6a0de5313ecc8325a77db35ff66644d7747099965ba3167ec21bd9ce4500edf21b5bdd49bf
languageName: node languageName: node
linkType: hard linkType: hard
@@ -3155,9 +3155,10 @@ __metadata:
resolution: "docker-login@workspace:." resolution: "docker-login@workspace:."
dependencies: dependencies:
"@actions/core": "npm:^3.0.1" "@actions/core": "npm:^3.0.1"
"@aws-sdk/client-ecr": "npm:^3.1077.0" "@actions/http-client": "npm:^4.0.1"
"@aws-sdk/client-ecr-public": "npm:^3.1077.0" "@aws-sdk/client-ecr": "npm:^3.1132.0"
"@docker/actions-toolkit": "npm:^0.92.0" "@aws-sdk/client-ecr-public": "npm:^3.1132.0"
"@docker/actions-toolkit": "npm:^0.94.0"
"@eslint/js": "npm:^9.39.3" "@eslint/js": "npm:^9.39.3"
"@types/js-yaml": "npm:^4.0.9" "@types/js-yaml": "npm:^4.0.9"
"@types/node": "npm:^24.11.0" "@types/node": "npm:^24.11.0"
@@ -3173,9 +3174,10 @@ __metadata:
globals: "npm:^17.3.0" globals: "npm:^17.3.0"
http-proxy-agent: "npm:^9.1.0" http-proxy-agent: "npm:^9.1.0"
https-proxy-agent: "npm:^9.1.0" https-proxy-agent: "npm:^9.1.0"
js-yaml: "npm:^5.2.0" js-yaml: "npm:^5.2.2"
prettier: "npm:^3.8.1" prettier: "npm:^3.8.1"
typescript: "npm:^5.9.3" typescript: "npm:^5.9.3"
uuid: "npm:^14.0.1"
vitest: "npm:^4.0.18" vitest: "npm:^4.0.18"
languageName: unknown languageName: unknown
linkType: soft linkType: soft
@@ -4344,14 +4346,25 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"js-yaml@npm:^5.2.0": "js-yaml@npm:^5.2.1":
version: 5.2.0 version: 5.2.1
resolution: "js-yaml@npm:5.2.0" resolution: "js-yaml@npm:5.2.1"
dependencies: dependencies:
argparse: "npm:^2.0.1" argparse: "npm:^2.0.1"
bin: bin:
js-yaml: bin/js-yaml.mjs js-yaml: bin/js-yaml.mjs
checksum: 10/8a5e55c5d0fcafae4ac02114a99dc070048b8e5a82a056089ce1f69f8a00fd8eb05b622e76ad50aac1f9d409010636c9616c6b2ed4e58dae138379a60d301220 checksum: 10/e1eca2d21c15572585bb236d9fde31d6789eb50b9c63e8753fa7e0777bc480f7521cad517bd7a0c66f27dfc27ddcd7100beeefa51c1a50e10e98f2e009633c3d
languageName: node
linkType: hard
"js-yaml@npm:^5.2.2":
version: 5.2.2
resolution: "js-yaml@npm:5.2.2"
dependencies:
argparse: "npm:^2.0.1"
bin:
js-yaml: bin/js-yaml.mjs
checksum: 10/2b4c2933af12c97e1c4894a4f27fe9b06dab70a64a96bb50624b4429bef6bf11008bde20d868bce52a36784473314efc30078ba6025b58cf7537961e23b1ae9c
languageName: node languageName: node
linkType: hard linkType: hard
@@ -4851,12 +4864,12 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"nanoid@npm:^3.3.11": "nanoid@npm:^3.3.16":
version: 3.3.11 version: 3.3.16
resolution: "nanoid@npm:3.3.11" resolution: "nanoid@npm:3.3.16"
bin: bin:
nanoid: bin/nanoid.cjs nanoid: bin/nanoid.cjs
checksum: 10/73b5afe5975a307aaa3c95dfe3334c52cdf9ae71518176895229b8d65ab0d1c0417dd081426134eb7571c055720428ea5d57c645138161e7d10df80815527c48 checksum: 10/8004af92b5541af1dbd23b69845b5026f777d5b7ef07163cea1837aae86e052ced8b383cecbf8a4f1b5e77ae207df96dc45e16b9e0fa3c4b761d085f1e42851b
languageName: node languageName: node
linkType: hard linkType: hard
@@ -5279,13 +5292,13 @@ __metadata:
linkType: hard linkType: hard
"postcss@npm:^8.5.6": "postcss@npm:^8.5.6":
version: 8.5.10 version: 8.5.22
resolution: "postcss@npm:8.5.10" resolution: "postcss@npm:8.5.22"
dependencies: dependencies:
nanoid: "npm:^3.3.11" nanoid: "npm:^3.3.16"
picocolors: "npm:^1.1.1" picocolors: "npm:^1.1.1"
source-map-js: "npm:^1.2.1" source-map-js: "npm:^1.2.1"
checksum: 10/7eac6169e535b63c8412e94d4f6047fc23efa3e9dde804b541940043c831b25f1cd867d83cd2c4371ad2450c8abcb42c208aa25668c1f0f3650d7f72faf711a8 checksum: 10/7944444f267f2d94c7caeed66f3da56d5b947bd4a7e57a166a5161af25c6006dd73f40e2a1a6822f3d7fccc2fa005778c03058368eb7efca1b5038aec55abd14
languageName: node languageName: node
linkType: hard linkType: hard
@@ -6300,6 +6313,15 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"uuid@npm:^14.0.1":
version: 14.0.1
resolution: "uuid@npm:14.0.1"
bin:
uuid: dist-node/bin/uuid
checksum: 10/0f978fd5b0269d7acb615342aeb131f0b8d85eeb8ec34f2915d906baa3befcc14a079a430d0f8116aec6fd20c850cbfab65d1b3d1643fa81ed373c0cf9574f18
languageName: node
linkType: hard
"validate-npm-package-name@npm:^7.0.0": "validate-npm-package-name@npm:^7.0.0":
version: 7.0.2 version: 7.0.2
resolution: "validate-npm-package-name@npm:7.0.2" resolution: "validate-npm-package-name@npm:7.0.2"