Skip to content

chore(deps): bump docker/login-action from 4 to 4.5.1 - #87

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/docker/login-action-4.5.1
Open

chore(deps): bump docker/login-action from 4 to 4.5.1#87
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/docker/login-action-4.5.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 1, 2026

Copy link
Copy Markdown

Bumps docker/login-action from 4 to 4.5.1.

Release notes

Sourced from docker/login-action's releases.

v4.5.1

Full Changelog: docker/login-action@v4.5.0...v4.5.1

v4.5.0

Full Changelog: docker/login-action@v4.4.0...v4.5.0

v4.4.0

Full Changelog: docker/login-action@v4.3.0...v4.4.0

v4.3.0

Full Changelog: docker/login-action@v4.2.0...v4.3.0

v4.2.0

Full Changelog: docker/login-action@v4.1.0...v4.2.0

v4.1.0

... (truncated)

Commits
  • a5e9150 Merge pull request #1048 from docker/dockerhub-oidc-support
  • a482ba4 build(deps): bump the codeql-actions group with 2 updates
  • 9e3d36e chore: update generated content
  • 14d6a79 docker hub oidc support
  • 03c8510 Merge pull request #1044 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • ad8a81f Merge pull request #1046 from docker/dependabot/npm_and_yarn/brace-expansion-...
  • 6d219a4 [dependabot skip] chore: update generated content
  • b320069 build(deps): bump @​docker/actions-toolkit from 0.92.0 to 0.93.0
  • 08d3680 [dependabot skip] chore: update generated content
  • 381f5a4 Merge pull request #1042 from docker/dependabot/github_actions/codeql-actions...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [docker/login-action](https://github.com/docker/login-action) from 4 to 4.5.1.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@v4...v4.5.1)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 4.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 1, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 1, 2026 01:52
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 1, 2026

- name: Login to Quay.io
uses: docker/login-action@v4
uses: docker/login-action@v4.5.1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep identified an issue in your code:

GitHub Actions step uses mutable version tag v4.5.1 instead of a commit SHA, allowing the action owner to silently inject malicious code that could steal your repository secrets.

More details about this

The docker/login-action step is pinned to a mutable version tag (v4.5.1) instead of a specific commit SHA. This means the action maintainers can silently update the code at this tag without your knowledge.

Here's how an attacker could exploit this:

  1. Compromise the action repository: An attacker gains write access to the docker/login-action repository (e.g., through credential theft or social engineering).
  2. Modify the action code: They update the code at the v4.5.1 tag to include malicious logic—for example, exfiltrating the ${{ secrets.QUAY_ROBOT_TOKEN }} secret to an attacker-controlled server.
  3. Your workflow runs silently compromised: The next time your workflow runs after the tag is updated, it automatically pulls the poisoned action code. The step logs in to Quay.io as normal, but the secret is also sent to the attacker.
  4. Account takeover: With the leaked QUAY_ROBOT_TOKEN, the attacker can push malicious container images to your quay.io/wire/poll-app registry, compromising all deployments.

This attack pattern was used in real supply-chain compromises like trivy-action and kics-github-action. Version tags and branch names are mutable and can be repointed at any time by the action owner or a compromised maintainer.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
uses: docker/login-action@v4.5.1
# Replace the SHA below with the full 40-character commit SHA for the trusted
# docker/login-action release you intend to use (ideally the commit for v4.5.1).
# This pins the action to an immutable revision to satisfy Semgrep.
uses: docker/login-action@0123456789abcdef0123456789abcdef01234567
View step-by-step instructions
  1. Replace the mutable action reference with a full 40-character commit SHA in the uses line for the login step.
    Change uses: docker/login-action@v4.5.1 to uses: docker/login-action@<full-40-character-commit-sha>.

  2. Keep the same action and version when choosing the SHA by using the commit that corresponds to the v4.5.1 release from the docker/login-action repository.
    This makes the workflow use an immutable revision instead of a tag that can be moved later.

  3. Update the step so it still looks like uses: docker/login-action@0123456789abcdef0123456789abcdef01234567, replacing the example SHA with the real 40-character commit for that release.

  4. Manually verify that the workflow can still authenticate to Quay.io and that the login step still receives registry, username, and password exactly as before.

Alternatively, if you need an immediate temporary fix and already trust a newer release, pin directly to that release’s full commit SHA instead of v4.5.1, but still avoid any tag such as @v4 or @v4.5.1.

💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.

You can view more details about this finding in the Semgrep AppSec Platform.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants