Skip to content

Upgrade GitHub Actions to latest versions - #615

Open
salmanmkc wants to merge 1 commit into
666ghj:mainfrom
salmanmkc:upgrade-github-actions-node24-general
Open

Upgrade GitHub Actions to latest versions#615
salmanmkc wants to merge 1 commit into
666ghj:mainfrom
salmanmkc:upgrade-github-actions-node24-general

Conversation

@salmanmkc

Copy link
Copy Markdown

Summary

Upgrade GitHub Actions to their latest versions for improved features, bug fixes, and security updates.

Changes

Action Old Version(s) New Version Release Files
docker/build-push-action v5 v7 Release docker_ci.yml
docker/login-action v3 v4 Release docker_ci.yml
docker/metadata-action v5 v6 Release docker_ci.yml
docker/setup-buildx-action v3 v4 Release docker_ci.yml
docker/setup-qemu-action v3 v4 Release docker_ci.yml

Why upgrade?

Keeping GitHub Actions up to date ensures:

  • Security: Latest security patches and fixes
  • Features: Access to new functionality and improvements
  • Compatibility: Better support for current GitHub features
  • Performance: Optimizations and efficiency improvements

⚠️ Breaking Changes

  • docker/login-action (v3 → v4): Major version upgrade — review the release notes for breaking changes
  • docker/metadata-action (v5 → v6): Major version upgrade — review the release notes for breaking changes
  • docker/setup-qemu-action (v3 → v4): Major version upgrade — review the release notes for breaking changes
  • docker/setup-buildx-action (v3 → v4): Major version upgrade — review the release notes for breaking changes
  • docker/build-push-action (v5 → v7): Major version upgrade — review the release notes for breaking changes

Security Note

Actions that were previously pinned to commit SHAs remain pinned to SHAs (updated to the latest release SHA) to maintain the security benefits of immutable references.

Testing

These changes only affect CI/CD workflow configurations and should not impact application functionality. The workflows should be tested by running them on a branch before merging.

Signed-off-by: Salman Muin Kayser Chishti <13schishti@gmail.com>
@dosubot dosubot Bot added size:S This PR changes 10-29 lines, ignoring generated files. improvement New feature or request labels Mar 10, 2026
@666ghj 666ghj added the Docker label Jul 20, 2026

@666ghj 666ghj left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated Agent review on behalf of the maintainer.

Thank you for updating the Docker Actions. The five proposed Docker Action major versions are current and the YAML parses successfully, but the publishing workflow is not yet safe to approve:

  • no pull-request validation path exists and no checks have run;
  • actions/checkout@v4 remains outdated;
  • the PR description says the Actions remain pinned to commit SHAs, while the workflow uses floating major tags;
  • simply adding a pull_request trigger would be unsafe while the build step still has push: true.

Please add a non-publishing PR build (push: false), guard login and publishing steps so they run only for release tags, update checkout, align the pinning policy with the implementation, and provide a successful validation run. We are keeping the PR open for those changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Docker improvement New feature or request size:S This PR changes 10-29 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants