1297 Commits

Author SHA1 Message Date
dependabot[bot]
cb1238b9c9
chore(deps): Bump @docker/actions-toolkit from 0.91.0 to 0.92.0
Bumps [@docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.91.0 to 0.92.0.
- [Release notes](https://github.com/docker/actions-toolkit/releases)
- [Commits](https://github.com/docker/actions-toolkit/compare/v0.91.0...v0.92.0)

---
updated-dependencies:
- dependency-name: "@docker/actions-toolkit"
  dependency-version: 0.92.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 14:04:40 +00:00
CrazyMax
24f845d5cb
Merge pull request #1566 from docker/dependabot/npm_and_yarn/js-yaml-4.2.0
chore(deps): Bump js-yaml from 4.1.1 to 4.3.0
2026-07-01 16:02:16 +02:00
github-actions[bot]
9c6973007b [dependabot skip] chore: update generated content 2026-07-01 13:58:59 +00:00
CrazyMax
bc3a3a5f72
Merge pull request #1574 from docker/dependabot/github_actions/aws-actions/configure-aws-credentials-6.2.1
chore(deps): Bump aws-actions/configure-aws-credentials from 6.2.0 to 6.2.1
2026-07-01 15:58:09 +02:00
dependabot[bot]
a82c504a23
chore(deps): Bump js-yaml from 4.1.1 to 4.3.0
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.1.1 to 4.3.0.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.1.1...4.3.0)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.2.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 13:57:51 +00:00
CrazyMax
0285a75190
Merge pull request #1573 from docker/dependabot/github_actions/actions/cache-6.1.0
chore(deps): Bump actions/cache from 5.0.5 to 6.1.0
2026-07-01 15:57:46 +02:00
CrazyMax
c6ad2a3f96
Merge pull request #1575 from docker/dependabot/github_actions/actions/checkout-7.0.0
chore(deps): Bump actions/checkout from 6.0.3 to 7.0.0
2026-07-01 15:57:22 +02:00
CrazyMax
d37484fb97
Merge pull request #1564 from docker/dependabot/npm_and_yarn/undici-6.27.0
chore(deps): Bump undici from 6.24.1 to 6.27.0
2026-07-01 15:54:52 +02:00
dependabot[bot]
0448735411
chore(deps): Bump actions/checkout from 6.0.3 to 7.0.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](df4cb1c069...9c091bb21b)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 13:54:16 +00:00
dependabot[bot]
3af9982280
chore(deps): Bump aws-actions/configure-aws-credentials
Bumps [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) from 6.2.0 to 6.2.1.
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](e7f100cf4c...254c19bd24)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 13:54:03 +00:00
github-actions[bot]
f53c18c0cf [dependabot skip] chore: update generated content 2026-07-01 13:52:19 +00:00
dependabot[bot]
6e67ee033d
chore(deps): Bump actions/cache from 5.0.5 to 6.1.0
Bumps [actions/cache](https://github.com/actions/cache) from 5.0.5 to 6.1.0.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](27d5ce7f10...55cc834586)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 13:52:14 +00:00
dependabot[bot]
11e972a040
chore(deps): Bump undici from 6.24.1 to 6.27.0
Bumps [undici](https://github.com/nodejs/undici) from 6.24.1 to 6.27.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](https://github.com/nodejs/undici/compare/v6.24.1...v6.27.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 6.27.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 13:51:16 +00:00
CrazyMax
910f6850a6
Merge pull request #1568 from docker/dependabot/npm_and_yarn/sigstore/core-3.2.1
chore(deps): Bump @sigstore/core from 3.1.0 to 3.2.1
2026-07-01 15:49:14 +02:00
CrazyMax
33baeb834f
Merge pull request #1563 from docker/dependabot/npm_and_yarn/vite-7.3.5
chore(deps): Bump vite from 7.3.2 to 7.3.6
2026-07-01 15:48:47 +02:00
CrazyMax
841b976440
Merge pull request #1560 from docker/dependabot/github_actions/github/codeql-action-4.36.2
chore(deps): Bump github/codeql-action from 4.36.0 to 4.36.2
2026-07-01 15:46:24 +02:00
CrazyMax
dd7abbf170
Merge pull request #1559 from docker/dependabot/github_actions/codecov/codecov-action-7.0.0
chore(deps): Bump codecov/codecov-action from 6.0.1 to 7.0.0
2026-07-01 15:46:01 +02:00
CrazyMax
7c45d1eb06
Merge pull request #1558 from docker/dependabot/github_actions/crazy-max-dot-github-a6a0ecf511
chore(deps): Bump the crazy-max-dot-github group across 1 directory with 2 updates
2026-07-01 15:45:36 +02:00
CrazyMax
8a43ac101c
Merge pull request #1556 from docker/dependabot/github_actions/actions/checkout-6.0.3
chore(deps): Bump actions/checkout from 6.0.2 to 6.0.3
2026-07-01 15:45:12 +02:00
CrazyMax
b40e3ca8bc
Merge pull request #1552 from docker/dependabot/github_actions/docker/setup-qemu-action-4.1.0
chore(deps): Bump docker/setup-qemu-action from 4.0.0 to 4.1.0
2026-07-01 15:44:47 +02:00
CrazyMax
5f1f2303ad
Merge pull request #1569 from crazy-max/dependabot-skip-update-dist
dependabot: skip for update-dist commits
2026-07-01 13:59:34 +02:00
CrazyMax
55f5969fae
Merge pull request #1570 from crazy-max/fix-yarn-preapprove-actions-toolkit
chore: allow actions-toolkit to bypass yarn age gate
2026-07-01 13:59:31 +02:00
CrazyMax
4876fd8314
chore: allow actions-toolkit to bypass yarn age gate
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-07-01 11:43:30 +02:00
dependabot[bot]
d187480585
chore(deps): Bump the crazy-max-dot-github group across 1 directory with 2 updates
Bumps the crazy-max-dot-github group with 2 updates in the / directory: [crazy-max/.github/.github/workflows/pr-assign-author.yml](https://github.com/crazy-max/.github) and [crazy-max/.github/.github/workflows/zizmor.yml](https://github.com/crazy-max/.github).


Updates `crazy-max/.github/.github/workflows/pr-assign-author.yml` from 1.8.0 to 1.10.1
- [Release notes](https://github.com/crazy-max/.github/releases)
- [Commits](9ba6e6f945...46267a6e61)

Updates `crazy-max/.github/.github/workflows/zizmor.yml` from 1.8.0 to 1.10.1
- [Release notes](https://github.com/crazy-max/.github/releases)
- [Commits](9ba6e6f945...46267a6e61)

---
updated-dependencies:
- dependency-name: crazy-max/.github/.github/workflows/pr-assign-author.yml
  dependency-version: 1.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: crazy-max-dot-github
- dependency-name: crazy-max/.github/.github/workflows/zizmor.yml
  dependency-version: 1.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: crazy-max-dot-github
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-30 11:52:20 +00:00
CrazyMax
a64725ae19
dependabot: skip for update-dist commits
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-06-30 11:08:52 +02:00
dependabot[bot]
2aea2d4e15
chore(deps): Bump vite from 7.3.2 to 7.3.6
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 7.3.2 to 7.3.6.
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/v7.3.6/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v7.3.6/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 7.3.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-29 14:17:53 +00:00
github-actions[bot]
f28b5fb763 chore: update generated content 2026-06-29 14:17:29 +00:00
dependabot[bot]
15204538a5
chore(deps): Bump @sigstore/core from 3.1.0 to 3.2.1
Bumps [@sigstore/core](https://github.com/sigstore/sigstore-js) from 3.1.0 to 3.2.1.
- [Release notes](https://github.com/sigstore/sigstore-js/releases)
- [Commits](https://github.com/sigstore/sigstore-js/compare/sigstore@3.1.0...@sigstore/core@3.2.1)

---
updated-dependencies:
- dependency-name: "@sigstore/core"
  dependency-version: 3.2.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-29 14:16:26 +00:00
CrazyMax
b99c92828a
Merge pull request #1567 from crazy-max/fix-esbuild
preserve names in esbuild bundle
2026-06-29 16:14:40 +02:00
CrazyMax
16ce5c6012
preserve names in esbuild bundle
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-06-29 14:58:08 +02:00
CrazyMax
ff26911fd3
Merge pull request #1562 from docker/sec-cli/npm-ci-20260612-145940
fix: replace npm install with npm ci (20260612-145940)
2026-06-12 17:16:13 +02:00
securityeng-bot[bot]
c2245a368f
fix: use lockfile-aware install commands 2026-06-12 14:59:41 +00:00
CrazyMax
d2aace88c2
Merge pull request #1561 from docker/e2e-aws-ecr-oidc
ci(e2e): use OIDC for AWS ECR
2026-06-11 23:21:40 +02:00
CrazyMax
ffca5157f0
ci(e2e): use OIDC for AWS ECR
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-06-11 21:54:33 +02:00
CrazyMax
f72b3cf665
Merge pull request #1555 from crazy-max/e2e-dockerhub
ci(e2e): use org-owned Docker Hub credentials for e2e pushes
2026-06-08 19:08:26 +02:00
dependabot[bot]
371801e73e
chore(deps): Bump github/codeql-action from 4.36.0 to 4.36.2
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.0 to 4.36.2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](7211b7c807...8aad20d150)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.36.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 11:54:12 +00:00
dependabot[bot]
b3a9933cc8
chore(deps): Bump codecov/codecov-action from 6.0.1 to 7.0.0
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 6.0.1 to 7.0.0.
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](e79a6962e0...fb8b3582c8)

---
updated-dependencies:
- dependency-name: codecov/codecov-action
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 11:52:43 +00:00
CrazyMax
405b217da0
ci(e2e): use org-owned Docker Hub credentials for e2e pushes
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-06-04 16:03:24 +02:00
CrazyMax
7b93b2b85c
Merge pull request #1554 from crazy-max/e2e-ghcr
ci(e2e): use GITHUB_TOKEN for GHCR e2e
2026-06-04 16:00:12 +02:00
dependabot[bot]
27ef6d9c76
chore(deps): Bump actions/checkout from 6.0.2 to 6.0.3
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](de0fac2e45...df4cb1c069)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-04 00:14:44 +00:00
CrazyMax
f55bd083f2
ci(e2e): use GITHUB_TOKEN for GHCR e2e
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-06-02 14:18:39 +02:00
dependabot[bot]
1ff3662da6
chore(deps): Bump docker/setup-qemu-action from 4.0.0 to 4.1.0
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 4.0.0 to 4.1.0.
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](ce360397dd...06116385d9)

---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-29 12:40:56 +00:00
Tõnis Tiigi
1d0c110a5d
Merge pull request #1548 from crazy-max/docs-link-secret-inputs
readme: link secret inputs to the GitHub Actions secrets guide
2026-05-28 17:30:01 -07:00
Tõnis Tiigi
8db8ba8e45
Merge pull request #1549 from crazy-max/ci-e2e-dockerhub-push-scope
ci(e2e): limit push-scoped login to Docker Hub
2026-05-28 17:29:24 -07:00
CrazyMax
abf612226d
Merge pull request #1551 from crazy-max/yarn-update
update yarn to 4.15.0
2026-05-28 18:41:31 +02:00
CrazyMax
fe2165d9f3
update yarn to 4.15.0
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-05-28 15:13:15 +02:00
CrazyMax
77c0af9da9
ci(e2e): limit push-scoped login to Docker Hub
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-05-28 11:38:49 +02:00
CrazyMax
2258452e7c
readme: link secret inputs to the GitHub Actions secrets guide
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-05-28 11:22:02 +02:00
CrazyMax
c0132ad86b
Merge pull request #1545 from docker/dependabot/npm_and_yarn/docker/actions-toolkit-0.91.0
chore(deps): Bump @docker/actions-toolkit from 0.90.0 to 0.91.0
2026-05-28 10:27:20 +02:00
github-actions[bot]
eaa27f4741 chore: update generated content 2026-05-28 08:19:42 +00:00