Skip to content

ci: bump AWS credentials 6.3.0 and Docker build, buildx, and QEMU pins - #70

Merged
nickpell merged 1 commit into
mainfrom
cursor/ratchet-dependency-updates-b347
Sep 21, 2026
Merged

nickpell merged 1 commit into
mainfrom
cursor/ratchet-dependency-updates-b347

Conversation

@cursor

@cursor cursor Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Routine refresh of the ratchet-managed Action pins under .github/. Each pin moves to the newest release inside its existing # ratchet: constraint; no constraint comment changes, so no action moves to a new major. Four actions moved across five call sites in two workflow files.

No major version was held back: after this update every pinned action is simultaneously the newest release within its major and the newest release overall, so there is no pending major upgrade to consider in a follow-up.

Refs that moved

Action Files Constraint Version (from → to) SHA (from → to)
aws-actions/configure-aws-credentials docker.yml, eif-build.yml @v6 v6.2.4 → v6.3.0 cbe3b3927387 → e1253824e5c1
docker/build-push-action docker.yml @v7 v7.3.0 → v7.4.0 53b7df96c91f → c3c9e263c25d
docker/setup-buildx-action docker.yml @v4 v4.3.0 → v4.4.1 37fe63102785 → f87e5991a6d7
docker/setup-qemu-action docker.yml @v4 v4.3.0 → v4.4.0 1f40c72289ef → 990126619549

The remaining seven pinned actions were already at the tip of their constraint and are untouched.

Upstream changelog

aws-actions/configure-aws-credentials v6.2.4 → v6.3.0

A single feature, add translate-env-variables option (#1961). The action has always translated a fixed list of AWS_*/role-related environment variables into their equivalent action inputs; v6.3.0 puts that translation behind a new optional translate-env-variables input that defaults to true, so the default path is byte-for-byte the previous behavior. The release also adds an info log line when a translation actually occurs, and trims an example from the sts-endpoint input description.

This is the only action.yml change in the whole set — the new optional input plus that description edit.

docker/setup-buildx-action v4.3.0 → v4.4.1

Two releases. v4.4.0 adds Pull BuildKit image before builder creation (#609), switches the cloud driver to official Buildx releases (#606), routes command failures through shared error helpers (#620), and bumps @docker/actions-toolkit 0.95.0 → 0.100.0. v4.4.1 then adds Skip BuildKit image pre-pulls for explicit endpoints (#624), refining the pre-pull introduced one release earlier. Landing directly on v4.4.1 means this repo never runs the unrefined v4.4.0 form of that behavior.

docker/build-push-action v7.3.0 → v7.4.0

v7.4.0 contains Prevent workflow command injection in metadata logs (#1617), the shared error helper change (#1620), and @docker/actions-toolkit 0.92.0 → 0.100.0 plus routine dependency bumps.

docker/setup-qemu-action v4.3.0 → v4.4.0

v4.4.0 is the shared error helper change (#345) plus @docker/actions-toolkit 0.96.0 → 0.100.0 and routine dependency bumps. The only source change is the error handling described below.

Risk assessment

None of the four releases is labelled breaking, and action.yml is byte-identical across all three Docker action bumps, so no input, output, or runtime contract changed for them. Three behavior changes do reach this repository and are worth reading closely.

BuildKit image pre-pull is reachable and changes the Docker Build workflow's step sequence. The build job calls docker/setup-buildx-action with only platforms, so it uses the default docker-container driver with no endpoint, append, or driver-opts, and the builder never pre-exists on a fresh runner. Every guard on the new pre-pull path is therefore satisfied, and the action now runs an explicit docker pull moby/buildkit:buildx-stable-1 in a new "Pulling BuildKit image(s)" group before creating the builder. That is the same image from the same registry that buildx create/bootstrap pulled implicitly before; what changes is that it happens earlier and goes through the toolkit's five-attempt retry helper rather than a single unretried implicit pull. The practical effect is better resilience to transient registry failures and an extra log group. The v4.4.1 follow-up skips the pre-pull when an explicit endpoint is configured, which is inert here because no endpoint is set.

Command failure detection is now stricter in all three Docker actions. The shared error helper work changed the failure condition from res.stderr.length > 0 && res.exitCode != 0 to simply res.exitCode != 0, with messages routed through getErrorMessage, which strips terminal control characters and returns the last non-empty stderr line behind a step-specific prefix. This is reachable at every Docker action call site in this repo. Previously a docker or buildx command that exited non-zero while writing nothing to stderr was silently treated as success; it now raises an error. This is a correctness improvement, and the only way it turns a previously green build red is if a command was genuinely failing and being swallowed.

Build metadata logging is hardened. docker/build-push-action now prints the build metadata JSON via the toolkit's printUntrusted, which brackets the output with ::stop-commands::<random token> so the Actions runner cannot interpret workflow-command syntax embedded in that JSON. This reaches the Docker Build workflow, which prints that group on every build. It is defense in depth with no behavior change for well-formed metadata.

The AWS credentials bump is inert here. Neither call site sets the new translate-env-variables input, and its true default reproduces the prior unconditional translation exactly. The only variable from the translated list that this repo sets is AWS_REGION, at workflow level in the Build EIF workflow, and both credential steps already pass aws-region explicitly — so the corresponding input is already populated and the new guard skips the assignment, resolving to the same value as before. Both call sites also pass only role-to-assume and aws-region in jobs granting id-token: write, so nothing else in the release surface applies.

Nothing newer has shipped, and the upstream issue trackers show no open reports against any of these four releases.

CI coverage caveat

All five moved call sites live in docker.yml and eif-build.yml, which trigger on workflow_run and workflow_dispatch rather than pull_request. PR CI therefore confirms the workflow files are well-formed and correctly pinned, but does not execute any of the four updated actions. The behavior changes above are first exercised after merge, which is what the post-merge section covers.

Pre-merge checklist

  • mise run //:ratchet:update produced exactly the ref changes in this diff and nothing else. — Verification: The historical update invocation was not rerun; changed pins match their claimed release tags and CI proves pin idempotence.
  • mise run //:ratchet:lint passes — every external ref is still pinned to a full SHA (19 of 19 uses: call sites). — Verification: Confirmed in the successful Ratchet Lint job, including pinning and the clean-diff check.
  • mise run //:ratchet:pin is idempotent and produces no further diff. — Verification: Confirmed in the successful Ratchet Lint job, including pinning and the clean-diff check.
  • PR CI is green, including Ratchet Lint. — Verification: All 3 reported checks are successful or intentionally skipped at 6605eb41bf09; Ratchet Lint passed.
  • Diff touches only pinned SHA values; no constraint comments, workflow logic, or unrelated files changed. — Verification: Verified every added/deleted line after replacing SHA and digest values with a common placeholder.

Post-merge verification

  • Workflows on main resolve to the new pins. — Verification: All five changed call sites were read at merge commit 97896822e4ae968ffa80c92bcd65bd84ede990d2; AWS credentials is e1253824e5c1 in both workflows, QEMU 990126619549, Buildx f87e5991a6d7, and build-push c3c9e263c25d. Main Go and Ratchet passed.
  • The next Docker Build run succeeds, and the new "Pulling BuildKit image(s)" group pulls moby/buildkit:buildx-stable-1 before the builder is created. — Verification: Docker Build 35611407488 passed. Its log records the explicit pull at 14:20:31Z before docker buildx create at 14:20:35Z.
  • The Docker Build image build, push, and multi-architecture emulation behave as before, with SBOM and provenance still attached. — Verification: The same successful run configured QEMU and built/pushed linux/arm64 to the merge-SHA and latest-arm64 tags, with image index digest sha256:03d114f1bccc46413b5bdfe573a3792402272de2ee8c9a9f541ebcae51082b92. Logs show SBOM generation, --attest type=provenance,mode=max, and exported attestation manifest sha256:5441fdd72634da5d5348d1dbdac3ffc0bf507ee67bb59cb3d264da53d1eac538. This verifies the automatic arm64 emulation path; the opt-in amd64 dispatch was not run.
  • The next Build EIF run authenticates successfully with the updated credentials action. — Verification: Build EIF 35611777072 passed at the merge SHA. Its credentials step logged successful OIDC authentication at 14:23:09Z; EIF publication, instance/security-group/key cleanup, and the PCR validation update all succeeded.

Weekly verification, 2026-09-21

  • Current HEAD CI verified. All 3 reported checks are successful or intentionally skipped at 6605eb41bf09; Ratchet Lint passed.
  • Copilot reviewed this HEAD. No unresolved review threads.
  • Upstream release commits verified through the GitHub API: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd = v6.3.0.
  • Docker action release commits verified: docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1 = v4.4.0; docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 = v4.4.1; docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc = v7.4.0.
  • Diff normalization verified: changes are only action SHAs and, for SSP, the documented image digests; no workflow logic or ratchet constraint changes.
Open in Web View Automation 

Refresh the ratchet-managed pins to the newest release inside each
existing `# ratchet:` constraint. No constraint comments change, so no
action moves to a new major.

  aws-actions/configure-aws-credentials  v6.2.4 -> v6.3.0  (@v6)
  docker/build-push-action               v7.3.0 -> v7.4.0  (@v7)
  docker/setup-buildx-action             v4.3.0 -> v4.4.1  (@v4)
  docker/setup-qemu-action               v4.3.0 -> v4.4.0  (@v4)

None of the upstream releases is labelled breaking. action.yml is
byte-identical across all three Docker action bumps; the only interface
change anywhere is configure-aws-credentials' new optional
`translate-env-variables` input, which defaults to true and therefore
preserves the previous behavior.
@nickpell
nickpell marked this pull request as ready for review September 21, 2026 13:45
@nickpell
nickpell self-requested a review as a code owner September 21, 2026 13:45
@nickpell
nickpell requested a balanced review from Copilot September 21, 2026 13:45

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

All changes are valid full-SHA pin updates that preserve existing major-version constraints and workflow configuration.

Review effort: Balanced
Findings: None

What changed in this PR

Refreshes ratchet-managed GitHub Action pins within their existing major-version constraints.

Changes:

  • Updates AWS credentials action at two call sites.
  • Updates three Docker actions used for image builds.
File Description
.github/​workflows/​eif-build.yml Updates the AWS credentials action pin.
.github/​workflows/​docker.yml Updates AWS and Docker action pins.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@nickpell nickpell changed the title ci: update pinned GitHub Actions within existing constraints ci: bump AWS credentials 6.3.0 and Docker build, buildx, and QEMU pins Sep 21, 2026
@nickpell
nickpell merged commit 9789682 into main Sep 21, 2026
4 checks passed
@nickpell
nickpell deleted the cursor/ratchet-dependency-updates-b347 branch September 21, 2026 14:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants