fix(deps): bump docker/login-action from 4.5.2 to 4.6.0 - #209
Conversation
d9f034c to
a7ee712
Compare
Aligns the release-workflow contract test with the dependabot bump of docker/login-action from 4.5.2 to 4.6.0 in release-image.yml (PR #209).
Bumps [docker/login-action](https://github.com/docker/login-action) from 4.5.2 to 4.6.0. - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@v4.5.2...v4.6.0) --- updated-dependencies: - dependency-name: docker/login-action dependency-version: 4.6.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Aligns the release-workflow contract test with the dependabot bump of docker/login-action from 4.5.2 to 4.6.0 in release-image.yml (PR #209).
f5aaef0 to
25f880c
Compare
athena-omt
left a comment
There was a problem hiding this comment.
Athena governance review — APPROVE (pinned to exact head 25f880cdfbf284551b98fcb5b75e3e0b6d4debb9)
Reconciliation (live, authenticated): head 25f880cd matches live PR head; base main@cd32cad7 == merge-base (2 ahead / 0 behind); non-draft; mergeable; mergeStateStatus BLOCKED on this review only; all 31 check-runs at head complete (required green; skips are path-filtered callers); 0 prior reviews.
Substance: Dependabot + Hephaestus pin-alignment bump of docker/login-action v4.5.2 → v4.6.0 (semver-minor; upstream release 2026-07-29).
.github/workflows/release-image.yml: tag refv4.5.2→v4.6.0..github/workflows/rg-release.yml: full-SHA pin371161bb…→dbcb8138…; verified upstream tagv4.6.0resolves to exactlydbcb813823bdd20940b903addbd779551569679f.test/release-workflow.test.ts: release-workflow step expectation pinned tov4.6.0(addresses the #204-style Fast Checks lock failure).- No stale
4.5.2/old-SHA references remain in tree; no lockfile or code changes.
Local verification at exact head (node OMT-NAS): pnpm install --frozen-lockfile exit 0; pnpm lint exit 0; pnpm test 54 files / 324 tests passed exit 0 (incl. release-workflow.test.ts).
Route proof: hostname=OMT-NAS, Linux 4.4.302+ x86_64, root, pwd=/, gh identity athena-omt. Review only; no merge performed.
Bumps docker/login-action from 4.5.2 to 4.6.0.
Release notes
Sourced from docker/login-action's releases.
Commits
dbcb813Merge pull request #1051 from docker/dependabot/npm_and_yarn/aws-sdk-dependen...5bcb015[dependabot skip] chore: update generated contentb30b2f2build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...9087f1eMerge pull request #1057 from docker/dependabot/npm_and_yarn/js-yaml-5.2.20009830[dependabot skip] chore: update generated content2325523build(deps): bump js-yaml from 5.2.1 to 5.2.24ec1d4aMerge pull request #1056 from docker/dependabot/npm_and_yarn/postcss-8.5.225fc99baMerge pull request #1053 from docker/dependabot/github_actions/aws-actions/co...e512bd5Merge pull request #1052 from docker/dependabot/github_actions/codeql-actions...a146c91Merge pull request #1059 from crazy-max/harden-buildx-scope-pathsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)