Skip to content

chore(deps): Bump docker/login-action from 4 to 4.5.1 - #125

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/docker/login-action-4.5.1
Open

chore(deps): Bump docker/login-action from 4 to 4.5.1#125
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/docker/login-action-4.5.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 1, 2026

Copy link
Copy Markdown
Contributor

Bumps docker/login-action from 4 to 4.5.1.

Release notes

Sourced from docker/login-action's releases.

v4.5.1

Full Changelog: docker/login-action@v4.5.0...v4.5.1

v4.5.0

Full Changelog: docker/login-action@v4.4.0...v4.5.0

v4.4.0

Full Changelog: docker/login-action@v4.3.0...v4.4.0

v4.3.0

Full Changelog: docker/login-action@v4.2.0...v4.3.0

v4.2.0

Full Changelog: docker/login-action@v4.1.0...v4.2.0

v4.1.0

... (truncated)

Commits
  • a5e9150 Merge pull request #1048 from docker/dockerhub-oidc-support
  • a482ba4 build(deps): bump the codeql-actions group with 2 updates
  • 9e3d36e chore: update generated content
  • 14d6a79 docker hub oidc support
  • 03c8510 Merge pull request #1044 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • ad8a81f Merge pull request #1046 from docker/dependabot/npm_and_yarn/brace-expansion-...
  • 6d219a4 [dependabot skip] chore: update generated content
  • b320069 build(deps): bump @​docker/actions-toolkit from 0.92.0 to 0.93.0
  • 08d3680 [dependabot skip] chore: update generated content
  • 381f5a4 Merge pull request #1042 from docker/dependabot/github_actions/codeql-actions...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [docker/login-action](https://github.com/docker/login-action) from 4 to 4.5.1.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@v4...v4.5.1)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 4.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 1, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 1, 2026 20:25
@dependabot dependabot Bot added the github_actions Pull requests that update GitHub Actions code label Aug 1, 2026

- name: Login to Quay.io
uses: docker/login-action@v4
uses: docker/login-action@v4.5.1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep identified an issue in your code:

The docker/login-action@v4.5.1 step uses a mutable version tag instead of a pinned commit SHA, allowing the action owner to silently inject malicious code that would execute with access to your secrets.

More details about this

The GitHub Actions step uses: docker/login-action@v4.5.1 references the action using a mutable version tag (v4.5.1) instead of a pinned commit SHA. This creates a supply-chain attack risk: the owner of docker/login-action could silently push new code to the v4.5.1 tag at any time, and your workflow would automatically execute that new code without any warning or visibility.

Exploit scenario:

  1. An attacker compromises the docker/login-action repository on GitHub
  2. The attacker pushes malicious code to the v4.5.1 tag (e.g., code that exfiltrates the QUAY_ROBOT_TOKEN secret passed into this step via with.password)
  3. On your next workflow run, your workflow silently pulls and executes the compromised v4.5.1 version
  4. The malicious code in the step runs with access to your secrets and registry credentials, allowing the attacker to push backdoored container images to your quay.io/wire/github-app repository
  5. Your users pull and run the backdoored image, compromising their systems

This is the exact attack pattern seen in real incidents like the trivy-action and kics-github-action compromises.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
uses: docker/login-action@v4.5.1
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567
View step-by-step instructions
  1. Replace the mutable action version in the uses line with a full 40-character commit SHA for docker/login-action.
    Change uses: docker/login-action@v4.5.1 to uses: docker/login-action@<full-commit-sha>.

  2. Resolve the SHA from the exact action release you want to keep using, so the workflow behavior stays the same while the reference becomes immutable.
    For example, pin the current v4.5.1 release commit from the docker/login-action repository and use uses: docker/login-action@0123456789abcdef0123456789abcdef01234567.

  3. Keep the rest of the step unchanged, including the existing with: values for registry, username, and password.
    Pinning to a commit SHA prevents the action owner from silently moving the referenced version to different code later.

  4. Alternatively, if you intentionally want to upgrade to a newer action release instead of keeping v4.5.1, first choose that release, then pin uses: to the full 40-character commit SHA for that release rather than to a tag like @v4 or @v4.5.1.

💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.

You can view more details about this finding in the Semgrep AppSec Platform.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants