skip BuildKit image pre-pulls for explicit endpoints - #624
Merged
Merged
Conversation
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
1 task
doonga
pushed a commit
to greyrock-labs/cert-manager-webhook-cloudns
that referenced
this pull request
Sep 16, 2026
…dx-action (v4.4.0 ➔ v4.4.1) (#19) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [https://github.com/docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | action | patch | `v4.4.0` → `v4.4.1` | --- ### Release Notes <details> <summary>docker/setup-buildx-action (https://github.com/docker/setup-buildx-action)</summary> ### [`v4.4.1`](https://github.com/docker/setup-buildx-action/releases/tag/v4.4.1) [Compare Source](docker/setup-buildx-action@v4.4.0...v4.4.1) - Skip BuildKit image pre-pulls for explicit endpoints by [@​crazy-max](https://github.com/crazy-max) in [#​624](docker/setup-buildx-action#624) **Full Changelog**: <docker/setup-buildx-action@v4.4.0...v4.4.1> </details> --- ### Configuration 📅 **Schedule**: (in timezone America/New_York) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC44NC4wIiwidXBkYXRlZEluVmVyIjoiNDQuODQuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUvZ2l0aHViLWFjdGlvbiIsInJlbm92YXRlL2dpdGh1Yi1yZWxlYXNlIiwidHlwZS9wYXRjaCJdfQ==--> Reviewed-on: https://git.greyrock.io/todd/cert-manager-webhook-cloudns/pulls/19
Merged
14 tasks
marcocot
pushed a commit
to marcocot/vinted-search-mcp
that referenced
this pull request
Sep 21, 2026
…ion to v4 (#9) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [https://github.com/docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | action | major | `v3` → `v4` | --- ### Release Notes <details> <summary>docker/setup-buildx-action (https://github.com/docker/setup-buildx-action)</summary> ### [`v4.4.1`](https://github.com/docker/setup-buildx-action/releases/tag/v4.4.1) [Compare Source](docker/setup-buildx-action@v4.4.0...v4.4.1) - Skip BuildKit image pre-pulls for explicit endpoints by [@​crazy-max](https://github.com/crazy-max) in [#​624](docker/setup-buildx-action#624) **Full Changelog**: <docker/setup-buildx-action@v4.4.0...v4.4.1> ### [`v4.4.0`](https://github.com/docker/setup-buildx-action/releases/tag/v4.4.0) [Compare Source](docker/setup-buildx-action@v4.3.0...v4.4.0) - Use official Buildx releases for cloud driver by [@​crazy-max](https://github.com/crazy-max) in [#​606](docker/setup-buildx-action#606) - Pull BuildKit image before builder creation by [@​crazy-max](https://github.com/crazy-max) in [#​609](docker/setup-buildx-action#609) - Use shared error helpers for Buildx and Docker commands by [@​crazy-max](https://github.com/crazy-max) in [#​620](docker/setup-buildx-action#620) - Bump [@​docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.95.0 to 0.100.0 in [#​610](docker/setup-buildx-action#610) [#​618](docker/setup-buildx-action#618) [#​619](docker/setup-buildx-action#619) - Bump [@​humanfs/node](https://github.com/humanfs/node) from 0.16.7 to 0.16.8 in [#​614](docker/setup-buildx-action#614) - Bump js-yaml from 5.3.0 to 5.4.2 in [#​608](docker/setup-buildx-action#608) [#​617](docker/setup-buildx-action#617) - Bump postcss-selector-parser from 7.1.1 to 7.1.5 in [#​611](docker/setup-buildx-action#611) **Full Changelog**: <docker/setup-buildx-action@v4.3.0...v4.4.0> ### [`v4.3.0`](https://github.com/docker/setup-buildx-action/releases/tag/v4.3.0) [Compare Source](docker/setup-buildx-action@v4.2.0...v4.3.0) - Bump [@​docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.92.0 to 0.95.0 in [#​595](docker/setup-buildx-action#595) - Bump brace-expansion from 1.1.13 to 1.1.18 in [#​600](docker/setup-buildx-action#600) - Bump js-yaml from 5.2.0 to 5.3.0 in [#​585](docker/setup-buildx-action#585) - Bump postcss from 8.5.10 to 8.5.25 in [#​598](docker/setup-buildx-action#598) - Bump undici from 6.27.0 to 6.28.0 in [#​601](docker/setup-buildx-action#601) **Full Changelog**: <docker/setup-buildx-action@v4.2.0...v4.3.0> ### [`v4.2.0`](https://github.com/docker/setup-buildx-action/releases/tag/v4.2.0) [Compare Source](docker/setup-buildx-action@v4.1.0...v4.2.0) - Preserve names in esbuild bundle by [@​crazy-max](https://github.com/crazy-max) in [#​572](docker/setup-buildx-action#572) - Bump [@​actions/core](https://github.com/actions/core) from 3.0.0 to 3.0.1 in [#​551](docker/setup-buildx-action#551) - Bump [@​docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.90.0 to 0.92.0 in [#​557](docker/setup-buildx-action#557) [#​580](docker/setup-buildx-action#580) - Bump [@​sigstore/core](https://github.com/sigstore/core) from 3.1.0 to 3.2.1 in [#​573](docker/setup-buildx-action#573) - Bump [@​sigstore/verify](https://github.com/sigstore/verify) from 3.1.0 to 3.1.1 in [#​576](docker/setup-buildx-action#576) - Bump js-yaml from 4.1.1 to 5.2.0 in [#​562](docker/setup-buildx-action#562) - Bump sigstore from 4.1.0 to 4.1.1 in [#​577](docker/setup-buildx-action#577) - Bump tmp from 0.2.5 to 0.2.7 in [#​556](docker/setup-buildx-action#556) - Bump undici from 6.25.0 to 6.27.0 in [#​570](docker/setup-buildx-action#570) - Bump vite from 7.3.2 to 7.3.6 in [#​569](docker/setup-buildx-action#569) **Full Changelog**: <docker/setup-buildx-action@v4.1.0...v4.2.0> ### [`v4.1.0`](https://github.com/docker/setup-buildx-action/releases/tag/v4.1.0) [Compare Source](docker/setup-buildx-action@v4.0.0...v4.1.0) - Bump [@​docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.79.0 to 0.90.0 in [#​489](docker/setup-buildx-action#489) - Bump brace-expansion from 1.1.12 to 5.0.6 in [#​547](docker/setup-buildx-action#547) [#​508](docker/setup-buildx-action#508) - Bump fast-xml-builder from 1.0.0 to 1.2.0 in [#​540](docker/setup-buildx-action#540) - Bump fast-xml-parser from 5.4.2 to 5.8.0 in [#​496](docker/setup-buildx-action#496) - Bump flatted from 3.3.3 to 3.4.2 in [#​499](docker/setup-buildx-action#499) - Bump glob from 10.3.12 to 13.0.6 in [#​495](docker/setup-buildx-action#495) - Bump handlebars from 4.7.8 to 4.7.9 in [#​504](docker/setup-buildx-action#504) - Bump lodash from 4.17.23 to 4.18.1 in [#​523](docker/setup-buildx-action#523) - Bump picomatch from 4.0.3 to 4.0.4 in [#​503](docker/setup-buildx-action#503) - Bump postcss from 8.5.6 to 8.5.10 in [#​537](docker/setup-buildx-action#537) - Bump tar from 6.2.1 to 7.5.15 in [#​545](docker/setup-buildx-action#545) - Bump undici from 6.23.0 to 6.25.0 in [#​492](docker/setup-buildx-action#492) - Bump vite from 7.3.1 to 7.3.2 in [#​520](docker/setup-buildx-action#520) **Full Changelog**: <docker/setup-buildx-action@v4.0.0...v4.1.0> ### [`v4.0.0`](https://github.com/docker/setup-buildx-action/releases/tag/v4.0.0) [Compare Source](docker/setup-buildx-action@v3.12.0...v4.0.0) - Node 24 as default runtime (requires [Actions Runner v2.327.1](https://github.com/actions/runner/releases/tag/v2.327.1) or later) by [@​crazy-max](https://github.com/crazy-max) in [#​483](docker/setup-buildx-action#483) - Remove deprecated inputs/outputs by [@​crazy-max](https://github.com/crazy-max) in [#​464](docker/setup-buildx-action#464) - Switch to ESM and update config/test wiring by [@​crazy-max](https://github.com/crazy-max) in [#​481](docker/setup-buildx-action#481) - Bump [@​actions/core](https://github.com/actions/core) from 1.11.1 to 3.0.0 in [#​475](docker/setup-buildx-action#475) - Bump [@​docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.63.0 to 0.79.0 in [#​482](docker/setup-buildx-action#482) [#​485](docker/setup-buildx-action#485) - Bump js-yaml from 4.1.0 to 4.1.1 in [#​452](docker/setup-buildx-action#452) - Bump lodash from 4.17.21 to 4.17.23 in [#​472](docker/setup-buildx-action#472) - Bump minimatch from 3.1.2 to 3.1.5 in [#​480](docker/setup-buildx-action#480) **Full Changelog**: <docker/setup-buildx-action@v3.12.0...v4.0.0> </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Rome) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDMuMiIsInVwZGF0ZWRJblZlciI6IjQ0LjEwMy4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJjaG9yZSIsImRlcHMiLCJtYWpvciJdfQ==--> Reviewed-on: https://git.homelab.devncode.it/marco/vinted-search-mcp/pulls/9
nickpell
pushed a commit
to cloudx-io/openauction
that referenced
this pull request
Sep 21, 2026
#70) ## Summary Routine refresh of the ratchet-managed Action pins under `.github/`. Each pin moves to the newest release inside its existing `# ratchet:` constraint; no constraint comment changes, so **no action moves to a new major**. Four actions moved across five call sites in two workflow files. No major version was held back: after this update every pinned action is simultaneously the newest release within its major and the newest release overall, so there is no pending major upgrade to consider in a follow-up. ## Refs that moved | Action | Files | Constraint | Version (from → to) | SHA (from → to) | | --- | --- | --- | --- | --- | | `aws-actions/configure-aws-credentials` | `docker.yml`, `eif-build.yml` | `@v6` | v6.2.4 → v6.3.0 | `cbe3b3927387` → `e1253824e5c1` | | `docker/build-push-action` | `docker.yml` | `@v7` | v7.3.0 → v7.4.0 | `53b7df96c91f` → `c3c9e263c25d` | | `docker/setup-buildx-action` | `docker.yml` | `@v4` | v4.3.0 → v4.4.1 | `37fe63102785` → `f87e5991a6d7` | | `docker/setup-qemu-action` | `docker.yml` | `@v4` | v4.3.0 → v4.4.0 | `1f40c72289ef` → `990126619549` | The remaining seven pinned actions were already at the tip of their constraint and are untouched. ## Upstream changelog ### aws-actions/configure-aws-credentials v6.2.4 → v6.3.0 A single feature, [add translate-env-variables option (#1961)](aws-actions/configure-aws-credentials#1961). The action has always translated a fixed list of `AWS_*`/role-related environment variables into their equivalent action inputs; v6.3.0 puts that translation behind a new optional `translate-env-variables` input that **defaults to `true`**, so the default path is byte-for-byte the previous behavior. The release also adds an info log line when a translation actually occurs, and trims an example from the `sts-endpoint` input description. This is the only `action.yml` change in the whole set — the new optional input plus that description edit. ### docker/setup-buildx-action v4.3.0 → v4.4.1 Two releases. [v4.4.0](https://github.com/docker/setup-buildx-action/releases/tag/v4.4.0) adds [Pull BuildKit image before builder creation (#609)](docker/setup-buildx-action#609), switches the cloud driver to official Buildx releases ([#606](docker/setup-buildx-action#606)), routes command failures through shared error helpers ([#620](docker/setup-buildx-action#620)), and bumps `@docker/actions-toolkit` 0.95.0 → 0.100.0. [v4.4.1](https://github.com/docker/setup-buildx-action/releases/tag/v4.4.1) then adds [Skip BuildKit image pre-pulls for explicit endpoints (#624)](docker/setup-buildx-action#624), refining the pre-pull introduced one release earlier. Landing directly on v4.4.1 means this repo never runs the unrefined v4.4.0 form of that behavior. ### docker/build-push-action v7.3.0 → v7.4.0 [v7.4.0](https://github.com/docker/build-push-action/releases/tag/v7.4.0) contains [Prevent workflow command injection in metadata logs (#1617)](docker/build-push-action#1617), the shared error helper change ([#1620](docker/build-push-action#1620)), and `@docker/actions-toolkit` 0.92.0 → 0.100.0 plus routine dependency bumps. ### docker/setup-qemu-action v4.3.0 → v4.4.0 [v4.4.0](https://github.com/docker/setup-qemu-action/releases/tag/v4.4.0) is the shared error helper change ([#345](docker/setup-qemu-action#345)) plus `@docker/actions-toolkit` 0.96.0 → 0.100.0 and routine dependency bumps. The only source change is the error handling described below. ## Risk assessment None of the four releases is labelled breaking, and `action.yml` is byte-identical across all three Docker action bumps, so no input, output, or runtime contract changed for them. Three behavior changes do reach this repository and are worth reading closely. **BuildKit image pre-pull is reachable and changes the Docker Build workflow's step sequence.** The build job calls `docker/setup-buildx-action` with only `platforms`, so it uses the default `docker-container` driver with no `endpoint`, `append`, or `driver-opts`, and the builder never pre-exists on a fresh runner. Every guard on the new pre-pull path is therefore satisfied, and the action now runs an explicit `docker pull moby/buildkit:buildx-stable-1` in a new "Pulling BuildKit image(s)" group before creating the builder. That is the same image from the same registry that `buildx create`/bootstrap pulled implicitly before; what changes is that it happens earlier and goes through the toolkit's five-attempt retry helper rather than a single unretried implicit pull. The practical effect is better resilience to transient registry failures and an extra log group. The v4.4.1 follow-up skips the pre-pull when an explicit endpoint is configured, which is inert here because no endpoint is set. **Command failure detection is now stricter in all three Docker actions.** The shared error helper work changed the failure condition from `res.stderr.length > 0 && res.exitCode != 0` to simply `res.exitCode != 0`, with messages routed through `getErrorMessage`, which strips terminal control characters and returns the last non-empty stderr line behind a step-specific prefix. This is reachable at every Docker action call site in this repo. Previously a docker or buildx command that exited non-zero while writing nothing to stderr was silently treated as success; it now raises an error. This is a correctness improvement, and the only way it turns a previously green build red is if a command was genuinely failing and being swallowed. **Build metadata logging is hardened.** `docker/build-push-action` now prints the build metadata JSON via the toolkit's `printUntrusted`, which brackets the output with `::stop-commands::<random token>` so the Actions runner cannot interpret workflow-command syntax embedded in that JSON. This reaches the Docker Build workflow, which prints that group on every build. It is defense in depth with no behavior change for well-formed metadata. **The AWS credentials bump is inert here.** Neither call site sets the new `translate-env-variables` input, and its `true` default reproduces the prior unconditional translation exactly. The only variable from the translated list that this repo sets is `AWS_REGION`, at workflow level in the Build EIF workflow, and both credential steps already pass `aws-region` explicitly — so the corresponding input is already populated and the new guard skips the assignment, resolving to the same value as before. Both call sites also pass only `role-to-assume` and `aws-region` in jobs granting `id-token: write`, so nothing else in the release surface applies. **Nothing newer has shipped**, and the upstream issue trackers show no open reports against any of these four releases. ## CI coverage caveat All five moved call sites live in `docker.yml` and `eif-build.yml`, which trigger on `workflow_run` and `workflow_dispatch` rather than `pull_request`. PR CI therefore confirms the workflow files are well-formed and correctly pinned, but does not execute any of the four updated actions. The behavior changes above are first exercised after merge, which is what the post-merge section covers. ## Pre-merge checklist - [ ] `mise run //:ratchet:update` produced exactly the ref changes in this diff and nothing else. — Verification: The historical update invocation was not rerun; changed pins match their claimed release tags and CI proves pin idempotence. - [x] `mise run //:ratchet:lint` passes — every external ref is still pinned to a full SHA (19 of 19 `uses:` call sites). — Verification: Confirmed in the successful [Ratchet Lint job](https://github.com/cloudx-io/openauction/actions/runs/35581678818/job/106275754741), including pinning and the clean-diff check. - [x] `mise run //:ratchet:pin` is idempotent and produces no further diff. — Verification: Confirmed in the successful [Ratchet Lint job](https://github.com/cloudx-io/openauction/actions/runs/35581678818/job/106275754741), including pinning and the clean-diff check. - [x] PR CI is green, including `Ratchet Lint`. — Verification: All 3 reported checks are successful or intentionally skipped at `6605eb41bf09`; [Ratchet Lint](https://github.com/cloudx-io/openauction/actions/runs/35581678818/job/106275754741) passed. - [x] Diff touches only pinned SHA values; no constraint comments, workflow logic, or unrelated files changed. — Verification: Verified every added/deleted line after replacing SHA and digest values with a common placeholder. ## Post-merge verification - [ ] Workflows on `main` resolve to the new pins. — Verification: Pending merge and deployment; this result has not been observed. - [ ] The next Docker Build run succeeds, and the new "Pulling BuildKit image(s)" group pulls `moby/buildkit:buildx-stable-1` before the builder is created. — Verification: Pending merge and deployment; this result has not been observed. - [ ] The Docker Build image build, push, and multi-architecture emulation behave as before, with SBOM and provenance still attached. — Verification: Pending merge and deployment; this result has not been observed. - [ ] The next Build EIF run authenticates successfully with the updated credentials action. — Verification: Pending merge and deployment; this result has not been observed. ## Weekly verification, 2026-09-21 - [x] Current HEAD CI verified. All 3 reported checks are successful or intentionally skipped at `6605eb41bf09`; [Ratchet Lint](https://github.com/cloudx-io/openauction/actions/runs/35581678818/job/106275754741) passed. - [x] Copilot reviewed this HEAD. No unresolved review threads. - [x] Upstream release commits verified through the GitHub API: `aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd` = `v6.3.0`. - [x] Docker action release commits verified: `docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1` = `v4.4.0`; `docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069` = `v4.4.1`; `docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc` = `v7.4.0`. - [x] Diff normalization verified: changes are only action SHAs and, for SSP, the documented image digests; no workflow logic or ratchet constraint changes. <div><a href="https://cursor.com/agents/bc-48004c83-b1d4-4fa3-b4a3-c77a3f9bf753?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-web-light.png"><img alt="Open in Web" width="114" height="28" src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a> <a href="https://cursor.com/automations/65e8572f-8209-11f1-a7d1-d6b4613131ce"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/view-automation-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/view-automation-light.png"><img alt="View Automation" width="141" height="28" src="https://cursor.com/assets/images/view-automation-dark.png"></picture></a> </div> Co-authored-by: Cursor Agent <cursoragent@cursor.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fixes #623
Rregression introduced in v4.4.0 where the BuildKit image pre-pull targets the default Docker daemon even when an endpoint is specified. Skip pre-pulls for nodes with explicit endpoints and let Buildx pull on the target daemon during bootstrap. CI now covers named contexts and TCP endpoints with an unavailable default daemon.
I'm working on a follow-up to restore pre-pulls for explicit endpoints using the endpoint support proposed in docker/actions-toolkit#1326.