Bump docker/build-push-action from 2 to 4
Created by: dependabot[bot]
Bumps docker/build-push-action from 2 to 4.
Release notes
Sourced from docker/build-push-action's releases.
v4.0.0
Note
Buildx v0.10 enables support for a minimal SLSA Provenance attestation, which requires support for OCI-compliant multi-platform images. This may introduce issues with registry and runtime support (e.g. Google Cloud Run and AWS Lambda). You can optionally disable the default provenance attestation functionality using
provenance: false
.
- Enable provenance by default if not set by
@crazy-max
in docker/build-push-action#784Full Changelog: https://github.com/docker/build-push-action/compare/v3.3.1...v4.0.0
v3.3.1
- Disable provenance by default if not set by
@crazy-max
(#781)Full Changelog: https://github.com/docker/build-push-action/compare/v3.3.0...v3.3.1
v3.3.0
Note
Buildx v0.10 enables support for a minimal SLSA Provenance attestation, which requires support for OCI-compliant multi-platform images. This may introduce issues with registry and runtime support (e.g. Google Cloud Run and AWS Lambda). You can optionally disable the default provenance attestation functionality using
provenance: false
.
- Add
attests
,provenance
andsbom
inputs by@crazy-max
(#746 #759)- Log GitHub Actions runtime token access controls by
@crazy-max
(#707)- Examples moved to docs website by
@crazy-max
(#718)- Bump minimatch from 3.0.4 to 3.1.2 (#732)
- Bump csv-parse from 5.3.0 to 5.3.3 (#729)
- Bump json5 from 2.2.0 to 2.2.3 (#749)
Full Changelog: https://github.com/docker/build-push-action/compare/v3.2.0...v3.3.0
v3.2.0
- Remove workaround for
setOutput
by@crazy-max
(#704)- Docs: fix Git context link and add more details about subdir support by
@crazy-max
(#685)- Docs: named context by
@baibaratsky
and@crazy-max
(#665)- Bump
@actions/core
from 1.9.0 to 1.10.0 (#667 #695)- Bump
@actions/github
from 5.0.3 to 5.1.1 (#696)Full Changelog: https://github.com/docker/build-push-action/compare/v3.1.1...v3.2.0
v3.1.1
- Fix GitHub token not passed with Git context if subdir defined by
@crazy-max
(#663)- Replace deprecated
fs.rmdir
withfs.rm
by@bendrucker
(#657)Full Changelog: https://github.com/docker/build-push-action/compare/v3.1.0...v3.1.1
v3.1.0
no-cache-filters
input by@crazy-max
(#653)- Bump
@actions/github
from 5.0.1 to 5.0.3 (#619)- Bump
@actions/core
from 1.6.0 to 1.9.0 (#620 #637)- Bump csv-parse from 5.0.4 to 5.3.0 (#623 #650)
Full Changelog: https://github.com/docker/build-push-action/compare/v3.0.0...v3.1.0
... (truncated)
Commits
-
44ea916
Merge pull request #875 from docker/dependabot/npm_and_yarn/docker/actions-to... -
0167eef
update generated content -
91bf8bf
chore(deps): Bump@docker/actions-toolkit
from 0.2.0 to 0.3.0 -
a799b4d
Merge pull request #860 from docker/dependabot/npm_and_yarn/docker/actions-to... -
87480bd
update generated content -
f9efed5
Merge pull request #871 from dvdksn/fix/secret-example-link -
3580b78
fix: broken link to secret example docs -
91df6b8
Merge pull request #859 from docker/dependabot/github_actions/docker/bake-act... -
ea92b18
chore(deps): Bump@docker/actions-toolkit
from 0.1.0 to 0.2.0 -
6f91eb3
chore(deps): Bump docker/bake-action from 2 to 3 - Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)