ci: bump AWS credentials 6.3.0 and Docker build, buildx, and QEMU pins - #70
Merged
Merged
Conversation
Refresh the ratchet-managed pins to the newest release inside each existing `# ratchet:` constraint. No constraint comments change, so no action moves to a new major. aws-actions/configure-aws-credentials v6.2.4 -> v6.3.0 (@v6) docker/build-push-action v7.3.0 -> v7.4.0 (@v7) docker/setup-buildx-action v4.3.0 -> v4.4.1 (@v4) docker/setup-qemu-action v4.3.0 -> v4.4.0 (@v4) None of the upstream releases is labelled breaking. action.yml is byte-identical across all three Docker action bumps; the only interface change anywhere is configure-aws-credentials' new optional `translate-env-variables` input, which defaults to true and therefore preserves the previous behavior.
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
All changes are valid full-SHA pin updates that preserve existing major-version constraints and workflow configuration.
Review effort: Balanced
Findings: None
What changed in this PR
Refreshes ratchet-managed GitHub Action pins within their existing major-version constraints.
Changes:
- Updates AWS credentials action at two call sites.
- Updates three Docker actions used for image builds.
| File | Description |
|---|---|
.github/workflows/eif-build.yml |
Updates the AWS credentials action pin. |
.github/workflows/docker.yml |
Updates AWS and Docker action pins. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Routine refresh of the ratchet-managed Action pins under
.github/. Each pin moves to the newest release inside its existing# ratchet:constraint; no constraint comment changes, so no action moves to a new major. Four actions moved across five call sites in two workflow files.No major version was held back: after this update every pinned action is simultaneously the newest release within its major and the newest release overall, so there is no pending major upgrade to consider in a follow-up.
Refs that moved
aws-actions/configure-aws-credentialsdocker.yml,eif-build.yml@v6cbe3b3927387→e1253824e5c1docker/build-push-actiondocker.yml@v753b7df96c91f→c3c9e263c25ddocker/setup-buildx-actiondocker.yml@v437fe63102785→f87e5991a6d7docker/setup-qemu-actiondocker.yml@v41f40c72289ef→990126619549The remaining seven pinned actions were already at the tip of their constraint and are untouched.
Upstream changelog
aws-actions/configure-aws-credentials v6.2.4 → v6.3.0
A single feature, add translate-env-variables option (#1961). The action has always translated a fixed list of
AWS_*/role-related environment variables into their equivalent action inputs; v6.3.0 puts that translation behind a new optionaltranslate-env-variablesinput that defaults totrue, so the default path is byte-for-byte the previous behavior. The release also adds an info log line when a translation actually occurs, and trims an example from thests-endpointinput description.This is the only
action.ymlchange in the whole set — the new optional input plus that description edit.docker/setup-buildx-action v4.3.0 → v4.4.1
Two releases. v4.4.0 adds Pull BuildKit image before builder creation (#609), switches the cloud driver to official Buildx releases (#606), routes command failures through shared error helpers (#620), and bumps
@docker/actions-toolkit0.95.0 → 0.100.0. v4.4.1 then adds Skip BuildKit image pre-pulls for explicit endpoints (#624), refining the pre-pull introduced one release earlier. Landing directly on v4.4.1 means this repo never runs the unrefined v4.4.0 form of that behavior.docker/build-push-action v7.3.0 → v7.4.0
v7.4.0 contains Prevent workflow command injection in metadata logs (#1617), the shared error helper change (#1620), and
@docker/actions-toolkit0.92.0 → 0.100.0 plus routine dependency bumps.docker/setup-qemu-action v4.3.0 → v4.4.0
v4.4.0 is the shared error helper change (#345) plus
@docker/actions-toolkit0.96.0 → 0.100.0 and routine dependency bumps. The only source change is the error handling described below.Risk assessment
None of the four releases is labelled breaking, and
action.ymlis byte-identical across all three Docker action bumps, so no input, output, or runtime contract changed for them. Three behavior changes do reach this repository and are worth reading closely.BuildKit image pre-pull is reachable and changes the Docker Build workflow's step sequence. The build job calls
docker/setup-buildx-actionwith onlyplatforms, so it uses the defaultdocker-containerdriver with noendpoint,append, ordriver-opts, and the builder never pre-exists on a fresh runner. Every guard on the new pre-pull path is therefore satisfied, and the action now runs an explicitdocker pull moby/buildkit:buildx-stable-1in a new "Pulling BuildKit image(s)" group before creating the builder. That is the same image from the same registry thatbuildx create/bootstrap pulled implicitly before; what changes is that it happens earlier and goes through the toolkit's five-attempt retry helper rather than a single unretried implicit pull. The practical effect is better resilience to transient registry failures and an extra log group. The v4.4.1 follow-up skips the pre-pull when an explicit endpoint is configured, which is inert here because no endpoint is set.Command failure detection is now stricter in all three Docker actions. The shared error helper work changed the failure condition from
res.stderr.length > 0 && res.exitCode != 0to simplyres.exitCode != 0, with messages routed throughgetErrorMessage, which strips terminal control characters and returns the last non-empty stderr line behind a step-specific prefix. This is reachable at every Docker action call site in this repo. Previously a docker or buildx command that exited non-zero while writing nothing to stderr was silently treated as success; it now raises an error. This is a correctness improvement, and the only way it turns a previously green build red is if a command was genuinely failing and being swallowed.Build metadata logging is hardened.
docker/build-push-actionnow prints the build metadata JSON via the toolkit'sprintUntrusted, which brackets the output with::stop-commands::<random token>so the Actions runner cannot interpret workflow-command syntax embedded in that JSON. This reaches the Docker Build workflow, which prints that group on every build. It is defense in depth with no behavior change for well-formed metadata.The AWS credentials bump is inert here. Neither call site sets the new
translate-env-variablesinput, and itstruedefault reproduces the prior unconditional translation exactly. The only variable from the translated list that this repo sets isAWS_REGION, at workflow level in the Build EIF workflow, and both credential steps already passaws-regionexplicitly — so the corresponding input is already populated and the new guard skips the assignment, resolving to the same value as before. Both call sites also pass onlyrole-to-assumeandaws-regionin jobs grantingid-token: write, so nothing else in the release surface applies.Nothing newer has shipped, and the upstream issue trackers show no open reports against any of these four releases.
CI coverage caveat
All five moved call sites live in
docker.ymlandeif-build.yml, which trigger onworkflow_runandworkflow_dispatchrather thanpull_request. PR CI therefore confirms the workflow files are well-formed and correctly pinned, but does not execute any of the four updated actions. The behavior changes above are first exercised after merge, which is what the post-merge section covers.Pre-merge checklist
mise run //:ratchet:updateproduced exactly the ref changes in this diff and nothing else. — Verification: The historical update invocation was not rerun; changed pins match their claimed release tags and CI proves pin idempotence.mise run //:ratchet:lintpasses — every external ref is still pinned to a full SHA (19 of 19uses:call sites). — Verification: Confirmed in the successful Ratchet Lint job, including pinning and the clean-diff check.mise run //:ratchet:pinis idempotent and produces no further diff. — Verification: Confirmed in the successful Ratchet Lint job, including pinning and the clean-diff check.Ratchet Lint. — Verification: All 3 reported checks are successful or intentionally skipped at6605eb41bf09; Ratchet Lint passed.Post-merge verification
mainresolve to the new pins. — Verification: All five changed call sites were read at merge commit97896822e4ae968ffa80c92bcd65bd84ede990d2; AWS credentials ise1253824e5c1in both workflows, QEMU990126619549, Buildxf87e5991a6d7, and build-pushc3c9e263c25d. Main Go and Ratchet passed.moby/buildkit:buildx-stable-1before the builder is created. — Verification: Docker Build 35611407488 passed. Its log records the explicit pull at 14:20:31Z beforedocker buildx createat 14:20:35Z.linux/arm64to the merge-SHA andlatest-arm64tags, with image index digestsha256:03d114f1bccc46413b5bdfe573a3792402272de2ee8c9a9f541ebcae51082b92. Logs show SBOM generation,--attest type=provenance,mode=max, and exported attestation manifestsha256:5441fdd72634da5d5348d1dbdac3ffc0bf507ee67bb59cb3d264da53d1eac538. This verifies the automatic arm64 emulation path; the opt-in amd64 dispatch was not run.Weekly verification, 2026-09-21
6605eb41bf09; Ratchet Lint passed.aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd=v6.3.0.docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1=v4.4.0;docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069=v4.4.1;docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc=v7.4.0.