Sourced from docker/login-action's releases.
v4.4.0
- Skip empty
registry-authsecret mask by@crazy-maxin docker/login-action#1035- Bump
@aws-sdk/client-ecrand@aws-sdk/client-ecr-publicto 3.1077.0 docker/login-action#1034Full Changelog: https://github.com/docker/login-action/compare/v4.3.0...v4.4.0
v4.3.0
- Preserve names in esbuild bundle by
@crazy-maxin docker/login-action#1022- Bump
@aws-sdk/client-ecrand@aws-sdk/client-ecr-publicto 3.1076.0 docker/login-action#999 docker/login-action#1030- Bump
@docker/actions-toolkitfrom 0.90.0 to 0.92.0 in docker/login-action#1004 docker/login-action#1027- Bump
@sigstore/corefrom 3.1.0 to 3.2.1 in docker/login-action#1023- Bump
@sigstore/verifyfrom 3.1.0 to 3.1.1 in docker/login-action#1029- Bump http-proxy-agent and https-proxy-agent to 9.1.0 in docker/login-action#1017
- Bump js-yaml from 4.1.1 to 5.2.0 in docker/login-action#1028
- Bump sigstore from 4.1.0 to 4.1.1 in docker/login-action#1031
- Bump tmp from 0.2.5 to 0.2.7 in docker/login-action#1002
- Bump undici from 6.24.1 to 6.27.0 in docker/login-action#1020
- Bump vite from 7.3.3 to 7.3.6 in docker/login-action#1019
Full Changelog: https://github.com/docker/login-action/compare/v4.2.0...v4.3.0
af1e73f
Merge pull request #1034
from docker/dependabot/npm_and_yarn/aws-sdk-dependen...da722bd
[dependabot skip] chore: update generated content2916ad6
build(deps): bump the aws-sdk-dependencies group across 1 directory with
2 up...ca0a662
Merge pull request #1035
from crazy-max/fix-registry-auth-empty-maskc455755
chore: update generated content4835190
skip empty registry-auth secret mask992421c
Merge pull request #1033
from docker/dependabot/github_actions/docker/bake-ac...b249b43
Merge pull request #1032
from docker/dependabot/github_actions/docker/bake-ac...1b67977
build(deps): bump docker/bake-action from 7.2.0 to 7.3.09d49d6a
build(deps): bump docker/bake-action/subaction/matrixSourced from docker/metadata-action's releases.
v6.2.0
- Preserve names in esbuild bundle by
@crazy-maxin docker/metadata-action#689- Bump
@actions/corefrom 3.0.0 to 3.0.1 in docker/metadata-action#663- Bump
@actions/githubfrom 9.0.0 to 9.1.1 in docker/metadata-action#666- Bump
@docker/actions-toolkitfrom 0.90.0 to 0.92.0 in docker/metadata-action#672 docker/metadata-action#696- Bump
@sigstore/corefrom 3.1.0 to 3.2.1 in docker/metadata-action#690- Bump
@sigstore/verifyfrom 3.1.0 to 3.1.1 in docker/metadata-action#693- Bump csv-parse from 6.2.1 to 7.0.0 in docker/metadata-action#683
- Bump js-yaml from 4.1.1 to 4.3.0 in docker/metadata-action#688
- Bump moment-timezone from 0.6.1 to 0.6.2 in docker/metadata-action#664
- Bump semver from 7.7.4 to 7.8.5 in docker/metadata-action#665 docker/metadata-action#695
- Bump sigstore from 4.1.0 to 4.1.1 in docker/metadata-action#694
- Bump tmp from 0.2.5 to 0.2.7 in docker/metadata-action#673
- Bump undici from 6.25.0 to 6.27.0 in docker/metadata-action#686
- Bump vite from 7.3.2 to 7.3.6 in docker/metadata-action#685
Full Changelog: https://github.com/docker/metadata-action/compare/v6.1.0...v6.2.0
dc80280
Merge pull request #696
from docker/dependabot/npm_and_yarn/docker/actions-to...2b9fe83
[dependabot skip] chore: update generated content8128ce3
chore(deps): Bump @docker/actions-toolkit from 0.91.0 to
0.92.01d1c895
Merge pull request #695
from docker/dependabot/npm_and_yarn/semver-7.8.57f0c2dd
Merge pull request #694
from docker/dependabot/npm_and_yarn/sigstore-4.1.1025f8c5
[dependabot skip] chore: update generated contente98d63c
chore(deps): Bump semver from 7.8.1 to 7.8.537d9379
chore(deps): Bump sigstore from 4.1.0 to 4.1.1a1b8072
Merge pull request #690
from docker/dependabot/npm_and_yarn/sigstore/core-3.2.1e0e3381
[dependabot skip] chore: update generated contentSourced from docker/setup-buildx-action's releases.
v4.2.0
- Preserve names in esbuild bundle by
@crazy-maxin docker/setup-buildx-action#572- Bump
@actions/corefrom 3.0.0 to 3.0.1 in docker/setup-buildx-action#551- Bump
@docker/actions-toolkitfrom 0.90.0 to 0.92.0 in docker/setup-buildx-action#557 docker/setup-buildx-action#580- Bump
@sigstore/corefrom 3.1.0 to 3.2.1 in docker/setup-buildx-action#573- Bump
@sigstore/verifyfrom 3.1.0 to 3.1.1 in docker/setup-buildx-action#576- Bump js-yaml from 4.1.1 to 5.2.0 in docker/setup-buildx-action#562
- Bump sigstore from 4.1.0 to 4.1.1 in docker/setup-buildx-action#577
- Bump tmp from 0.2.5 to 0.2.7 in docker/setup-buildx-action#556
- Bump undici from 6.25.0 to 6.27.0 in docker/setup-buildx-action#570
- Bump vite from 7.3.2 to 7.3.6 in docker/setup-buildx-action#569
Full Changelog: https://github.com/docker/setup-buildx-action/compare/v4.1.0...v4.2.0
bb05f3f
Merge pull request #580
from docker/dependabot/npm_and_yarn/docker/actions-to...321c814
[dependabot skip] chore: update generated contentb9a36ef
build(deps): bump @docker/actions-toolkit from 0.91.0 to
0.92.0ebeab24
Merge pull request #570
from docker/dependabot/npm_and_yarn/undici-6.27.05c7b8ae
[dependabot skip] chore: update generated content037e618
build(deps): bump undici from 6.25.0 to 6.27.066080e5
Merge pull request #577
from docker/dependabot/npm_and_yarn/sigstore-4.1.1409aef0
Merge pull request #562
from docker/dependabot/npm_and_yarn/js-yaml-4.2.049c6e42
build(deps): bump sigstore from 4.1.0 to 4.1.12211273
[dependabot skip] chore: update generated contentSourced from docker/build-push-action's releases.
v7.3.0
- Preserve names in esbuild bundle by
@crazy-maxin docker/build-push-action#1567- Bump
@docker/actions-toolkitfrom 0.90.0 to 0.92.0 in docker/build-push-action#1545 docker/build-push-action#1572- Bump
@sigstore/corefrom 3.1.0 to 3.2.1 in docker/build-push-action#1568- Bump js-yaml from 4.1.1 to 4.3.0 in docker/build-push-action#1566
- Bump tmp from 0.2.5 to 0.2.7 in docker/build-push-action#1547
- Bump undici from 6.24.1 to 6.27.0 in docker/build-push-action#1564
- Bump vite from 7.3.2 to 7.3.6 in docker/build-push-action#1563
Full Changelog: https://github.com/docker/build-push-action/compare/v7.2.0...v7.3.0
53b7df9
Merge pull request #1572
from docker/dependabot/npm_and_yarn/docker/actions-t...154298c
[dependabot skip] chore: update generated contentcb1238b
chore(deps): Bump @docker/actions-toolkit from 0.91.0 to
0.92.024f845d
Merge pull request #1566
from docker/dependabot/npm_and_yarn/js-yaml-4.2.09c69730
[dependabot skip] chore: update generated contentbc3a3a5
Merge pull request #1574
from docker/dependabot/github_actions/aws-actions/co...a82c504
chore(deps): Bump js-yaml from 4.1.1 to 4.3.00285a75
Merge pull request #1573
from docker/dependabot/github_actions/actions/cache-...c6ad2a3
Merge pull request #1575
from docker/dependabot/github_actions/actions/checko...d37484f
Merge pull request #1564
from docker/dependabot/npm_and_yarn/undici-6.27.011f9893
chore: roll up Dependabot updates (#948)f798556
docs: update version references to v8.3.1 (#946)e80544d
chore: update known checksums for 0.11.28 (#947)f98e069
Change update-docs PR labels from 'update-docs' to 'documentation' (#945)cd46263
chore: update known checksums for 0.11.27 (#944)11245c7
docs: update version references to v8.3.0 (#939)d31148d
Strip environment markers from detected uv dependency pins (#938)17c3989
Fix cache keys for Python version ranges (#937)3cc3c11
chore(deps): roll up Dependabot updates (#936)9225f84
chore(deps): bump release-drafter/release-drafter from 7.3.1 to 7.4.0
(#924)Sourced from actions/setup-node's releases.
v7.0.0
What's Changed
Enhancements:
- Add cache-primary-key and cache-matched-key as outputs by
@gowridurgadin actions/setup-node#1577- Migrate to ESM and upgrade dependencies by
@gowridurgadin actions/setup-node#1574Bug fixes:
- Remove dummy NODE_AUTH_TOKEN export by
@gowridurgadin actions/setup-node#1558- Only use
mirrorTokeningetManifestif it's provided by@deigain actions/setup-node#1548Documentation updates:
- Add documentation for publishing to npm with Trusted Publisher (OIDC) by
@chiranjib-swainin actions/setup-node#1536- docs: Update restore-only cache documentation by
@priya-kinthaliin actions/setup-node#1550- docs: Update caching recommendations to mitigate cache poisoning risks by
@chiranjib-swainin actions/setup-node#1567Dependency update:
- Upgrade
@actions/cacheto 5.1.0, log cache write denied by@jasonginin actions/setup-node#1569New Contributors
@chiranjib-swainmade their first contribution in actions/setup-node#1536@deigamade their first contribution in actions/setup-node#1548@jasonginmade their first contribution in actions/setup-node#1569Full Changelog: https://github.com/actions/setup-node/compare/v6...v7.0.0
v6.5.0
What's Changed
- Update
@actions/cacheto 5.1.0 and add security overrides for undici and fast-xml-parser by@HarithaVattikutiin actions/setup-node#1579Full Changelog: https://github.com/actions/setup-node/compare/v6.4.0...v6.5.0
8207627
Migrate to ESM and upgrade dependencies (#1574)04be95c
Add cache-primary-key and cache-matched-key as outputs (#1577)7c2c68d
docs: Update caching recommendations to mitigate cache poisoning risks
(#1567)6a61c03
Merge pull request #1569
from jasongin/update-actions-cache-5.1.030eb73b
Resolve high-severity audit issues4e1a87a
Update dist360237f
Strict equality4f8aac5
Bump @actions/cache to 5.1.0, log cache write deniedf4a67bb
Only use mirrorToken in getManifest if it's
provided (#1548)0355742
Remove dummy NODE_AUTH_TOKEN export (#1558)Sourced from github/codeql-action/init's releases.
v4.37.0
- Update default CodeQL bundle version to 2.26.0. #3995
- In addition to the existing input format, the
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973v4.36.3
No user facing changes.
Sourced from github/codeql-action/init's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
4.37.1 - 16 Jul 2026
- Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
- Update default CodeQL bundle version to 2.26.1. #4019
4.37.0 - 08 Jul 2026
- Update default CodeQL bundle version to 2.26.0. #3995
- In addition to the existing input format, the
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #39734.36.3 - 01 Jul 2026
No user facing changes.
4.36.2 - 04 Jun 2026
- Cache CodeQL CLI version information across Actions steps. #3943
- Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
- Update default CodeQL bundle version to 2.25.6. #3948
4.36.1 - 02 Jun 2026
No user facing changes.
4.36.0 - 22 May 2026
- Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #3894
- Add support for SHA-256 Git object IDs. #3893
- Update default CodeQL bundle version to 2.25.5. #3926
4.35.5 - 15 May 2026
- We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. #3899
- For performance and accuracy reasons, improved incremental analysis will now only be enabled on a pull request when diff-informed analysis is also enabled for that run. If diff-informed analysis is unavailable (for example, because the PR diff ranges could not be computed), the action will fall back to a full analysis. #3791
- If multiple inputs are provided for the GitHub-internal
analysis-kindsinput, onlycode-scanningwill be enabled. Theanalysis-kindsinput is experimental, for GitHub-internal use only, and may change without notice at any time. #3892- Added an experimental change which, when running a Code Scanning analysis for a PR with improved incremental analysis enabled, prefers CodeQL CLI versions that have a cached overlay-base database for the configured languages. This speeds up analysis for a repository when there is not yet a cached overlay-base database for the latest CLI version. We expect to roll this change out to everyone in May. #3880
4.35.4 - 07 May 2026
4.35.3 - 01 May 2026
... (truncated)
99df26d
Merge pull request #3996
from github/update-v4.37.0-c7c896d7131c2707
Add changenote for #397372df218
Update changelog for v4.37.0c7c896d
Merge pull request #3995
from github/update-bundle/codeql-bundle-v2.26.03f34ff0
Add changelog note43bec09
Update default bundle to codeql-bundle-v2.26.0f58f0d1
Merge pull request #3973
from github/mbg/repo-props/config-file-shorthands7dc37cb
Merge remote-tracking branch 'origin/main' into
mbg/repo-props/config-file-sh...8e22350
Thread ActionState to initConfig69c9e8c
Mark some status-report imports as type-only
to avoid circular dependenciesSourced from github/codeql-action/autobuild's releases.
v4.37.0
- Update default CodeQL bundle version to 2.26.0. #3995
- In addition to the existing input format, the
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973v4.36.3
No user facing changes.
Sourced from github/codeql-action/autobuild's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
4.37.1 - 16 Jul 2026
- Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
- Update default CodeQL bundle version to 2.26.1. #4019
4.37.0 - 08 Jul 2026
- Update default CodeQL bundle version to 2.26.0. #3995
- In addition to the existing input format, the
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #39734.36.3 - 01 Jul 2026
No user facing changes.
4.36.2 - 04 Jun 2026
- Cache CodeQL CLI version information across Actions steps. #3943
- Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
- Update default CodeQL bundle version to 2.25.6. #3948
4.36.1 - 02 Jun 2026
No user facing changes.
4.36.0 - 22 May 2026
- Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #3894
- Add support for SHA-256 Git object IDs. #3893
- Update default CodeQL bundle version to 2.25.5. #3926
4.35.5 - 15 May 2026
- We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. #3899
- For performance and accuracy reasons, improved incremental analysis will now only be enabled on a pull request when diff-informed analysis is also enabled for that run. If diff-informed analysis is unavailable (for example, because the PR diff ranges could not be computed), the action will fall back to a full analysis. #3791
- If multiple inputs are provided for the GitHub-internal
analysis-kindsinput, onlycode-scanningwill be enabled. Theanalysis-kindsinput is experimental, for GitHub-internal use only, and may change without notice at any time. #3892- Added an experimental change which, when running a Code Scanning analysis for a PR with improved incremental analysis enabled, prefers CodeQL CLI versions that have a cached overlay-base database for the configured languages. This speeds up analysis for a repository when there is not yet a cached overlay-base database for the latest CLI version. We expect to roll this change out to everyone in May. #3880
4.35.4 - 07 May 2026
4.35.3 - 01 May 2026
... (truncated)
99df26d
Merge pull request #3996
from github/update-v4.37.0-c7c896d7131c2707
Add changenote for #397372df218
Update changelog for v4.37.0c7c896d
Merge pull request #3995
from github/update-bundle/codeql-bundle-v2.26.03f34ff0
Add changelog note43bec09
Update default bundle to codeql-bundle-v2.26.0f58f0d1
Merge pull request #3973
from github/mbg/repo-props/config-file-shorthands7dc37cb
Merge remote-tracking branch 'origin/main' into
mbg/repo-props/config-file-sh...8e22350
Thread ActionState to initConfig69c9e8c
Mark some status-report imports as type-only
to avoid circular dependenciesSourced from github/codeql-action/analyze's releases.
v4.37.0
- Update default CodeQL bundle version to 2.26.0. #3995
- In addition to the existing input format, the
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973v4.36.3
No user facing changes.
Sourced from github/codeql-action/analyze's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
4.37.1 - 16 Jul 2026
- Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
- Update default CodeQL bundle version to 2.26.1. #4019
4.37.0 - 08 Jul 2026
- Update default CodeQL bundle version to 2.26.0. #3995
- In addition to the existing input format, the
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #39734.36.3 - 01 Jul 2026
No user facing changes.
4.36.2 - 04 Jun 2026
- Cache CodeQL CLI version information across Actions steps. #3943
- Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
- Update default CodeQL bundle version to 2.25.6. #3948
4.36.1 - 02 Jun 2026
No user facing changes.
4.36.0 - 22 May 2026
- Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #3894
- Add support for SHA-256 Git object IDs. #3893
- Update default CodeQL bundle version to 2.25.5. #3926
4.35.5 - 15 May 2026
- We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. #3899
- For performance and accuracy reasons, improved incremental analysis will now only be enabled on a pull request when diff-informed analysis is also enabled for that run. If diff-informed analysis is unavailable (for example, because the PR diff ranges could not be computed), the action will fall back to a full analysis. #3791
- If multiple inputs are provided for the GitHub-internal
analysis-kindsinput, onlycode-scanningwill be enabled. Theanalysis-kindsinput is experimental, for GitHub-internal use only, and may change without notice at any time. #3892- Added an experimental change which, when running a Code Scanning analysis for a PR with improved incremental analysis enabled, prefers CodeQL CLI versions that have a cached overlay-base database for the configured languages. This speeds up analysis for a repository when there is not yet a cached overlay-base database for the latest CLI version. We expect to roll this change out to everyone in May. #3880
4.35.4 - 07 May 2026
4.35.3 - 01 May 2026
... (truncated)
99df26d
Merge pull request #3996
from github/update-v4.37.0-c7c896d7131c2707
Add changenote for #397372df218
Update changelog for v4.37.0c7c896d
Merge pull request #3995
from github/update-bundle/codeql-bundle-v2.26.03f34ff0
Add changelog note43bec09
Update default bundle to codeql-bundle-v2.26.0f58f0d1
Merge pull request #3973
from github/mbg/repo-props/config-file-shorthands7dc37cb
Merge remote-tracking branch 'origin/main' into
mbg/repo-props/config-file-sh...8e22350
Thread ActionState to initConfig69c9e8c
Mark some status-report imports as type-only
to avoid circular dependenciesSourced from dorny/paths-filter's releases.
v4.0.2
What's Changed
- fix warning message by
@cgundyin dorny/paths-filter#282- chore: fix GitHub spelling in logs by
@squatin dorny/paths-filter#278- fix: use rev-parse instead of branch --show-current for older git compat by
@saschabrattonin dorny/paths-filter#303- fix: work around git dubious ownership errors in container jobs by
@saschabrattonin dorny/paths-filter#317- docs: update changelog for v4.0.2 by
@saschabrattonin dorny/paths-filter#318New Contributors
@cgundymade their first contribution in dorny/paths-filter#282@squatmade their first contribution in dorny/paths-filter#278Full Changelog: https://github.com/dorny/paths-filter/compare/v4.0.1...v4.0.2
7b450ff
docs: update changelog for v4.0.2 (#318)9280377
fix: work around git dubious ownership errors in container jobs (#317)f3ceefd
fix: use rev-parse instead of branch --show-current for older git compat
(#303)61f87a1
chore: fix GitHub spelling in logs (#278)b82ff81
fix warning message (#282)