Compare commits

..
Author SHA1 Message Date
dependabot[bot] 17e42a47e7 chore(deps): Bump the codeql-actions group with 2 updates
Bumps the codeql-actions group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/cdf488f595d80d6e07e03d4674febd5ab45fa938...b96794f015dfd88f77b49b1c93e0fa7110f94c63)

Updates `github/codeql-action/analyze` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/cdf488f595d80d6e07e03d4674febd5ab45fa938...b96794f015dfd88f77b49b1c93e0fa7110f94c63)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.38.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codeql-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.38.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codeql-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-11 11:54:32 +00:00
CrazyMax 91670ba5a4 Merge pull request #1618 from docker/dependabot/npm_and_yarn/docker/actions-toolkit-0.99.0
chore(deps): Bump @docker/actions-toolkit from 0.98.0 to 0.99.0
2026-09-11 13:41:48 +02:00
github-actions[bot] 80dbc8614a [dependabot skip] chore: update generated content 2026-09-11 11:38:45 +00:00
dependabot[bot] 50cac3a3b6 chore(deps): Bump @docker/actions-toolkit from 0.98.0 to 0.99.0
Bumps [@docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.98.0 to 0.99.0.
- [Release notes](https://github.com/docker/actions-toolkit/releases)
- [Commits](https://github.com/docker/actions-toolkit/compare/v0.98.0...v0.99.0)

---
updated-dependencies:
- dependency-name: "@docker/actions-toolkit"
  dependency-version: 0.99.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-11 11:37:44 +00:00
Tõnis Tiigi 03b4d6cac0 Merge pull request #1617 from crazy-max/fix-metadata-workflow-commands
prevent workflow command injection in metadata logs
2026-09-10 18:13:15 -07:00
CrazyMax dcc3c70566 chore: update generated content
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-09-10 10:11:25 +02:00
CrazyMax 2145b7d858 prevent workflow command injection in metadata logs
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-09-10 10:11:24 +02:00
CrazyMax 104b27ceb2 Merge pull request #1616 from docker/dependabot/github_actions/codeql-actions-f1ba23a83b
chore(deps): Bump the codeql-actions group with 2 updates
2026-09-09 15:39:13 +02:00
CrazyMax 9b2a2073c3 Merge pull request #1615 from docker/dependabot/npm_and_yarn/js-yaml-4.3.2
chore(deps): Bump js-yaml from 4.3.1 to 4.3.2
2026-09-09 15:38:48 +02:00
dependabot[bot] 5f00bd7ece chore(deps): Bump the codeql-actions group with 2 updates
Bumps the codeql-actions group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.37.6 to 4.37.9
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/5595ccaf912efad79be6eef63a5619ff05969be3...cdf488f595d80d6e07e03d4674febd5ab45fa938)

Updates `github/codeql-action/analyze` from 4.37.6 to 4.37.9
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/5595ccaf912efad79be6eef63a5619ff05969be3...cdf488f595d80d6e07e03d4674febd5ab45fa938)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-09 11:54:23 +00:00
dependabot[bot] aeeb70cc49 chore(deps): Bump js-yaml from 4.3.1 to 4.3.2
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.1 to 4.3.2.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.3.1...4.3.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-09 10:53:55 +00:00
CrazyMax 27c552b342 Merge pull request #1614 from docker/dependabot/npm_and_yarn/docker/actions-toolkit-0.98.0
chore(deps): Bump @docker/actions-toolkit from 0.92.0 to 0.98.0
2026-09-09 12:52:05 +02:00
github-actions[bot] 35a05cc103 [dependabot skip] chore: update generated content 2026-09-09 09:13:01 +00:00
dependabot[bot] 4e660f2e30 chore(deps): Bump @docker/actions-toolkit from 0.92.0 to 0.98.0
Bumps [@docker/actions-toolkit](https://github.com/docker/actions-toolkit) from 0.92.0 to 0.98.0.
- [Release notes](https://github.com/docker/actions-toolkit/releases)
- [Commits](https://github.com/docker/actions-toolkit/compare/v0.92.0...v0.98.0)

---
updated-dependencies:
- dependency-name: "@docker/actions-toolkit"
  dependency-version: 0.98.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-09 09:12:13 +00:00
CrazyMax bb0f4e3f0e Merge pull request #1592 from docker/dependabot/npm_and_yarn/brace-expansion-1.1.18
chore(deps): Bump brace-expansion from 1.1.13 to 1.1.18
2026-09-09 11:10:10 +02:00
github-actions[bot] 213f379438 [dependabot skip] chore: update generated content 2026-09-09 09:08:06 +00:00
dependabot[bot] 9faad81e8c chore(deps): Bump brace-expansion from 1.1.13 to 1.1.18
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.13 to 1.1.18.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.13...v1.1.18)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.18
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-09 09:07:16 +00:00
CrazyMax d1b4d6a4ee Merge pull request #1605 from docker/dependabot/npm_and_yarn/js-yaml-4.3.1
chore(deps): Bump js-yaml from 4.3.0 to 4.3.1
2026-09-09 11:04:47 +02:00
CrazyMax 12f4b5e353 Merge pull request #1613 from docker/dependabot/npm_and_yarn/csv-parse-7.0.2
chore(deps): Bump csv-parse from 7.0.0 to 7.0.2
2026-09-09 11:04:24 +02:00
CrazyMax 5d2ba96cd6 Merge pull request #1611 from docker/dependabot/npm_and_yarn/nanoid-3.3.18
chore(deps): Bump nanoid from 3.3.16 to 3.3.18
2026-09-09 11:03:24 +02:00
github-actions[bot] c4f5168a02 [dependabot skip] chore: update generated content 2026-09-09 09:02:52 +00:00
dependabot[bot] b2993c26f2 chore(deps): Bump csv-parse from 7.0.0 to 7.0.2
Bumps [csv-parse](https://github.com/adaltas/node-csv/tree/HEAD/packages/csv-parse) from 7.0.0 to 7.0.2.
- [Changelog](https://github.com/adaltas/node-csv/blob/master/packages/csv-parse/CHANGELOG.md)
- [Commits](https://github.com/adaltas/node-csv/commits/csv-parse@7.0.2/packages/csv-parse)

---
updated-dependencies:
- dependency-name: csv-parse
  dependency-version: 7.0.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-09 09:01:54 +00:00
dependabot[bot] da299cd21b chore(deps): Bump nanoid from 3.3.16 to 3.3.18
Bumps [nanoid](https://github.com/ai/nanoid) from 3.3.16 to 3.3.18.
- [Release notes](https://github.com/ai/nanoid/releases)
- [Changelog](https://github.com/ai/nanoid/blob/3.3.18/CHANGELOG.md)
- [Commits](https://github.com/ai/nanoid/compare/3.3.16...3.3.18)

---
updated-dependencies:
- dependency-name: nanoid
  dependency-version: 3.3.18
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-09 09:01:30 +00:00
dependabot[bot] 5ea3152e64 chore(deps): Bump js-yaml from 4.3.0 to 4.3.1
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.0 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.3.0...4.3.1)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-28 00:41:10 +00:00
7 changed files with 161 additions and 161 deletions
+2 -2
View File
@@ -35,12 +35,12 @@ jobs:
node-version: ${{ env.NODE_VERSION }}
-
name: Initialize CodeQL
uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6
uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
with:
languages: javascript-typescript
build-mode: none
-
name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6
uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
with:
category: "/language:javascript-typescript"
Generated Vendored
+138 -138
View File
File diff suppressed because one or more lines are too long
Generated Vendored
+3 -3
View File
File diff suppressed because one or more lines are too long
Generated Vendored
+2 -2
View File
@@ -216,7 +216,7 @@ Apache License
The following npm package may be included in this product:
- @docker/actions-toolkit@0.98.0
- @docker/actions-toolkit@0.99.0
This package contains the following license:
@@ -3289,7 +3289,7 @@ USE OR OTHER DEALINGS IN THE SOFTWARE.
The following npm packages may be included in this product:
- brace-expansion@1.1.13
- brace-expansion@1.1.18
- brace-expansion@2.0.2
These packages each contain the following license:
+1 -1
View File
@@ -25,7 +25,7 @@
"packageManager": "yarn@4.15.0",
"dependencies": {
"@actions/core": "^3.0.1",
"@docker/actions-toolkit": "0.98.0",
"@docker/actions-toolkit": "0.99.0",
"handlebars": "^4.7.9"
},
"devDependencies": {
+1 -1
View File
@@ -137,7 +137,7 @@ actionsToolkit.run(
if (metadata) {
await core.group(`Metadata`, async () => {
const metadatadt = JSON.stringify(metadata, null, 2);
core.info(metadatadt);
GitHub.printUntrusted(metadatadt);
core.setOutput('metadata', metadatadt);
});
}
+14 -14
View File
@@ -437,9 +437,9 @@ __metadata:
languageName: node
linkType: hard
"@docker/actions-toolkit@npm:0.98.0":
version: 0.98.0
resolution: "@docker/actions-toolkit@npm:0.98.0"
"@docker/actions-toolkit@npm:0.99.0":
version: 0.99.0
resolution: "@docker/actions-toolkit@npm:0.99.0"
dependencies:
"@actions/artifact": "npm:^6.2.1"
"@actions/cache": "npm:^6.2.0"
@@ -462,7 +462,7 @@ __metadata:
semver: "npm:^7.8.5"
tar-stream: "npm:^3.2.1"
tmp: "npm:^0.2.7"
checksum: 10/9b8fed1455896812d913412a816ce2834aa908eee4db347672c204180bd0955163fabdfda27fb326f2255ec79b307297961205ac00f36803a12e5d076a5b3cf2
checksum: 10/60cf619154c3ef0cc84b7e9058b4b9a81e8e9820fec62b05d4acfe1c492251671426e8ea24053dca5f3408c803e3f4b2d57ec64506e74019f9d6977cd18948f8
languageName: node
linkType: hard
@@ -2436,12 +2436,12 @@ __metadata:
linkType: hard
"brace-expansion@npm:^1.1.7":
version: 1.1.13
resolution: "brace-expansion@npm:1.1.13"
version: 1.1.18
resolution: "brace-expansion@npm:1.1.18"
dependencies:
balanced-match: "npm:^1.0.0"
concat-map: "npm:0.0.1"
checksum: 10/b5f4329fdbe9d2e25fa250c8f866ebd054ba946179426e99b86dcccddabdb1d481f0e40ee5430032e62a7d0a6c2837605ace6783d015aa1d65d85ca72154d936
checksum: 10/b55a3c03239b8d2127c7cbb3408c9ad3a556a8c303bf3064df78bfb7c093160fc8f6e0a32e42a850a78eba12f29ccf6ef997690b9acf945d242c56c61c4aa977
languageName: node
linkType: hard
@@ -2841,7 +2841,7 @@ __metadata:
resolution: "docker-build-push@workspace:."
dependencies:
"@actions/core": "npm:^3.0.1"
"@docker/actions-toolkit": "npm:0.98.0"
"@docker/actions-toolkit": "npm:0.99.0"
"@eslint/js": "npm:^9.39.3"
"@types/node": "npm:^24.11.0"
"@typescript-eslint/eslint-plugin": "npm:^8.56.1"
@@ -4002,13 +4002,13 @@ __metadata:
linkType: hard
"js-yaml@npm:^4.1.0, js-yaml@npm:^4.1.1":
version: 4.3.0
resolution: "js-yaml@npm:4.3.0"
version: 4.3.2
resolution: "js-yaml@npm:4.3.2"
dependencies:
argparse: "npm:^2.0.1"
bin:
js-yaml: bin/js-yaml.js
checksum: 10/2bcec3a8118d7f744badeb04e14366578d234a736f353d41fe35d2305e4ce2409a8e041d277f07cd6bbc8aaa12128d650a68ce43247072519bede20962d2126f
checksum: 10/05c44b9c73e4901d92703b155e76518df64bf01ac62e4c036b47de4b391e19b72e32656e8954d51b436307f08cc9d0c0d4ec617d061cf2f65fffee9f3114bee7
languageName: node
linkType: hard
@@ -4543,11 +4543,11 @@ __metadata:
linkType: hard
"nanoid@npm:^3.3.16":
version: 3.3.16
resolution: "nanoid@npm:3.3.16"
version: 3.3.18
resolution: "nanoid@npm:3.3.18"
bin:
nanoid: bin/nanoid.cjs
checksum: 10/8004af92b5541af1dbd23b69845b5026f777d5b7ef07163cea1837aae86e052ced8b383cecbf8a4f1b5e77ae207df96dc45e16b9e0fa3c4b761d085f1e42851b
checksum: 10/1b3b4fdac831b92b56d1dbe8b1e63a372432faf86ea383134e3b53141ef8108a60b7f84343b5cefecac9550bb74edf8164da93ea07d1c4f757039bc75d8a5d9e
languageName: node
linkType: hard