This is an automated email from the ASF dual-hosted git repository.

paleolimbot pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/arrow-nanoarrow.git


The following commit(s) were added to refs/heads/main by this push:
     new b27fd93d chore: bump docker/login-action from 4.5.2 to 4.6.0 (#921)
b27fd93d is described below

commit b27fd93d0f519cf1504190420e87b001406f4855
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
AuthorDate: Fri Aug 7 09:14:02 2026 -0500

    chore: bump docker/login-action from 4.5.2 to 4.6.0 (#921)
    
    Bumps [docker/login-action](https://github.com/docker/login-action) from
    4.5.2 to 4.6.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/docker/login-action/releases";>docker/login-action's
    releases</a>.</em></p>
    <blockquote>
    <h2>v4.6.0</h2>
    <ul>
    <li>Harden buildx scoped config path handling by <a
    href="https://github.com/crazy-max";><code>@​crazy-max</code></a> in <a
    
href="https://redirect.github.com/docker/login-action/pull/1059";>docker/login-action#1059</a></li>
    <li>Bump <code>@​aws-sdk/client-ecr</code> and
    <code>@​aws-sdk/client-ecr-public</code> to 3.1095.0 in <a
    
href="https://redirect.github.com/docker/login-action/pull/1051";>docker/login-action#1051</a></li>
    <li>Bump js-yaml from 5.2.1 to 5.2.2 in <a
    
href="https://redirect.github.com/docker/login-action/pull/1057";>docker/login-action#1057</a></li>
    <li>Bump postcss from 8.5.10 to 8.5.22 in <a
    
href="https://redirect.github.com/docker/login-action/pull/1056";>docker/login-action#1056</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    
href="https://github.com/docker/login-action/compare/v4.5.2...v4.6.0";>https://github.com/docker/login-action/compare/v4.5.2...v4.6.0</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    
href="https://github.com/docker/login-action/commit/dbcb813823bdd20940b903addbd779551569679f";><code>dbcb813</code></a>
    Merge pull request <a
    href="https://redirect.github.com/docker/login-action/issues/1051";>#1051</a>
    from docker/dependabot/npm_and_yarn/aws-sdk-dependen...</li>
    <li><a
    
href="https://github.com/docker/login-action/commit/5bcb015ee6ec720ecdeaef2dc1164122e9b209fc";><code>5bcb015</code></a>
    [dependabot skip] chore: update generated content</li>
    <li><a
    
href="https://github.com/docker/login-action/commit/b30b2f2d3196c1714318ba0c3c3bec211d949752";><code>b30b2f2</code></a>
    build(deps): bump the aws-sdk-dependencies group across 1 directory with
    2 up...</li>
    <li><a
    
href="https://github.com/docker/login-action/commit/9087f1e6d666fe0292409e3c819680c18526e108";><code>9087f1e</code></a>
    Merge pull request <a
    href="https://redirect.github.com/docker/login-action/issues/1057";>#1057</a>
    from docker/dependabot/npm_and_yarn/js-yaml-5.2.2</li>
    <li><a
    
href="https://github.com/docker/login-action/commit/0009830ea169ca16c24c0ea4cac1c325bfa3aee4";><code>0009830</code></a>
    [dependabot skip] chore: update generated content</li>
    <li><a
    
href="https://github.com/docker/login-action/commit/23255232d3e43c8f0052d9a0dba82a515a88ce92";><code>2325523</code></a>
    build(deps): bump js-yaml from 5.2.1 to 5.2.2</li>
    <li><a
    
href="https://github.com/docker/login-action/commit/4ec1d4a769e8b05a89a7396551dc38b329211688";><code>4ec1d4a</code></a>
    Merge pull request <a
    href="https://redirect.github.com/docker/login-action/issues/1056";>#1056</a>
    from docker/dependabot/npm_and_yarn/postcss-8.5.22</li>
    <li><a
    
href="https://github.com/docker/login-action/commit/5fc99ba47bca274c5a499688f71c7ea79c0ea1b3";><code>5fc99ba</code></a>
    Merge pull request <a
    href="https://redirect.github.com/docker/login-action/issues/1053";>#1053</a>
    from docker/dependabot/github_actions/aws-actions/co...</li>
    <li><a
    
href="https://github.com/docker/login-action/commit/e512bd59d16c53d79ea5c0f0e345fe554453c4bb";><code>e512bd5</code></a>
    Merge pull request <a
    href="https://redirect.github.com/docker/login-action/issues/1052";>#1052</a>
    from docker/dependabot/github_actions/codeql-actions...</li>
    <li><a
    
href="https://github.com/docker/login-action/commit/a146c91b8f371700d323bae808af7cbdc2766ed5";><code>a146c91</code></a>
    Merge pull request <a
    href="https://redirect.github.com/docker/login-action/issues/1059";>#1059</a>
    from crazy-max/harden-buildx-scope-paths</li>
    <li>Additional commits viewable in <a
    
href="https://github.com/docker/login-action/compare/371161bbe7024a29a25c5e19bfcbc0804fe9ad2c...dbcb813823bdd20940b903addbd779551569679f";>compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=docker/login-action&package-manager=github_actions&previous-version=4.5.2&new-version=4.6.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] 
<49699333+dependabot[bot]@users.noreply.github.com>
---
 .github/workflows/docker-build.yaml | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/.github/workflows/docker-build.yaml 
b/.github/workflows/docker-build.yaml
index b0548b2e..3c0eb1f3 100644
--- a/.github/workflows/docker-build.yaml
+++ b/.github/workflows/docker-build.yaml
@@ -74,7 +74,7 @@ jobs:
           endpoint: builders
 
       - name: Login to GitHub Container Registry
-        uses: docker/login-action@371161bbe7024a29a25c5e19bfcbc0804fe9ad2c # 
v4.5.2
+        uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # 
v4.6.0
         with:
           registry: ghcr.io
           username: ${{ github.actor }}
@@ -108,7 +108,7 @@ jobs:
     needs: build-docker
     steps:
     - name: Login to GitHub Container Registry
-      uses: docker/login-action@371161bbe7024a29a25c5e19bfcbc0804fe9ad2c # 
v4.5.2
+      uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # 
v4.6.0
       with:
         registry: ghcr.io
         username: ${{ github.actor }}

Reply via email to