Bump docker/build-push-action from 2 to 4
Bumps docker/build-push-action from 2 to 4.
Release notes
Sourced from docker/build-push-action's releases.
v4.0.0
Note
Buildx v0.10 enables support for a minimal SLSA Provenance attestation, which requires support for OCI-compliant multi-platform images. This may introduce issues with registry and runtime support (e.g. Google Cloud Run and AWS Lambda). You can optionally disable the default provenance attestation functionality using
provenance: false.
- Revert disable provenance by default if not set by
@crazy-maxin docker/build-push-action#784Full Changelog: https://github.com/docker/build-push-action/compare/v3.3.1...v4.0.0
v3.3.1
- Disable provenance by default if not set by
@crazy-max(#781)Full Changelog: https://github.com/docker/build-push-action/compare/v3.3.0...v3.3.1
v3.3.0
Note
Buildx v0.10 enables support for a minimal SLSA Provenance attestation, which requires support for OCI-compliant multi-platform images. This may introduce issues with registry and runtime support (e.g. Google Cloud Run and AWS Lambda). You can optionally disable the default provenance attestation functionality using
provenance: false.
- Add
attests,provenanceandsbominputs by@crazy-max(#746 #759)- Log GitHub Actions runtime token access controls by
@crazy-max(#707)- Examples moved to docs website by
@crazy-max(#718)- Bump minimatch from 3.0.4 to 3.1.2 (#732)
- Bump csv-parse from 5.3.0 to 5.3.3 (#729)
- Bump json5 from 2.2.0 to 2.2.3 (#749)
Full Changelog: https://github.com/docker/build-push-action/compare/v3.2.0...v3.3.0
v3.2.0
- Remove workaround for
setOutputby@crazy-max(#704)- Docs: fix Git context link and add more details about subdir support by
@crazy-max(#685)- Docs: named context by
@baibaratskyand@crazy-max(#665)- Bump
@actions/corefrom 1.9.0 to 1.10.0 (#667 #695)- Bump
@actions/githubfrom 5.0.3 to 5.1.1 (#696)Full Changelog: https://github.com/docker/build-push-action/compare/v3.1.1...v3.2.0
v3.1.1
- Fix GitHub token not passed with Git context if subdir defined by
@crazy-max(#663)- Replace deprecated
fs.rmdirwithfs.rmby@bendrucker(#657)Full Changelog: https://github.com/docker/build-push-action/compare/v3.1.0...v3.1.1
v3.1.0
no-cache-filtersinput by@crazy-max(#653)- Bump
@actions/githubfrom 5.0.1 to 5.0.3 (#619)- Bump
@actions/corefrom 1.6.0 to 1.9.0 (#620 #637)- Bump csv-parse from 5.0.4 to 5.3.0 (#623 #650)
Full Changelog: https://github.com/docker/build-push-action/compare/v3.0.0...v3.1.0
... (truncated)
Commits
3b5e802Merge pull request #784 from crazy-max/enable-provenance02d3266update generated contentf403dafrevert disable provenance by default if not set1104d47Merge pull request #781 from crazy-max/disable-provenance838bf90update generated content337a09ddisable provenance by default if not set37abcedMerge pull request #760 from crazy-max/test-envs67109bctest: move envs to jest configd1b0eb0Merge pull request #759 from crazy-max/fix-provenance-inputa0635feupdate generated content- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
This PR is stale because it has been open 60 days with no activity.
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.
If you change your mind, just re-open this PR and I'll resolve any conflicts on it.