Skip to content

chore(deps): bump hoverkraft-tech/ci-github-container/.github/workflows/docker-build-images.yml from 0.38.0 to 0.39.0 in the github-actions-dependencies group across 1 directory - #544

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-dependencies-c248582561
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-dependencies-c248582561

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions-dependencies group with 1 update in the / directory: hoverkraft-tech/ci-github-container/.github/workflows/docker-build-images.yml.

Updates hoverkraft-tech/ci-github-container/.github/workflows/docker-build-images.yml from 0.38.0 to 0.39.0

Release notes

Sourced from hoverkraft-tech/ci-github-container/.github/workflows/docker-build-images.yml's releases.

0.39.0

Release Summary

Docker adds image build-provenance attestations, pins the installed Docker version, updates BuildKit and Buildx, and supports pull-request image-tag cleanup for user-owned packages.

Helm adds a dedicated chart-signing action and configurable test namespaces, while fixing dependency vulnerabilities in documentation generation.

Internal maintenance refreshes dependencies, development tooling, and documentation, and fixes CI linting and Helm fixture security failures.

Breaking changes

docker-build-images now requires attestations: write, and build-secret GitHub App tokens are restricted to contents: read on the calling repository by default; configure build-secret-github-app-repositories for additional repositories and supply separately scoped credentials through build-secrets for broader permissions.

helm/release-chart now signs charts by default: callers must grant id-token: write or explicitly set sign: "false".

What's Changed

... (truncated)

Commits
  • 5ffc3c8 chore(deps): bump the devcontainers-dependencies group with 3 updates
  • 6981397 chore(deps): bump prettier
  • aa754a8 docs: update actions and workflows documentation
  • 2bb5633 fix(ci): pass keyless flags in helm sign-chart test
  • a326cd2 feat(helm): add sign-chart action
  • 2b1e7fc docs: update actions and workflows documentation
  • fa8235e docs: update Helm chart documentation for charts
  • ad60282 fix(docker-build-images)!: restrict build-secret GitHub App tokens
  • 7120ed3 fix(ci): resolve lint and Helm fixture security failures
  • 448f911 chore(deps): bump prettier
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…ws/docker-build-images.yml

Bumps the github-actions-dependencies group with 1 update in the / directory: [hoverkraft-tech/ci-github-container/.github/workflows/docker-build-images.yml](https://github.com/hoverkraft-tech/ci-github-container).


Updates `hoverkraft-tech/ci-github-container/.github/workflows/docker-build-images.yml` from 0.38.0 to 0.39.0
- [Release notes](https://github.com/hoverkraft-tech/ci-github-container/releases)
- [Commits](hoverkraft-tech/ci-github-container@f8255a6...5ffc3c8)

---
updated-dependencies:
- dependency-name: hoverkraft-tech/ci-github-container/.github/workflows/docker-build-images.yml
  dependency-version: 0.39.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 9, 2026
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Hi, thank you for creating your PR, we will check it out very soon

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants