Skip to content

github: retry release metadata fetches - #1276

Merged
crazy-max merged 1 commit into
docker:mainfrom
crazy-max:github-release-retry
Aug 17, 2026
Merged

github: retry release metadata fetches#1276
crazy-max merged 1 commit into
docker:mainfrom
crazy-max:github-release-retry

Conversation

@crazy-max

Copy link
Copy Markdown
Member

Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
@crazy-max
crazy-max requested review from thaJeztah and vvoland August 17, 2026 11:24
@crazy-max
crazy-max marked this pull request as ready for review August 17, 2026 11:24

@thaJeztah thaJeztah left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@crazy-max
crazy-max merged commit 7f83b17 into docker:main Aug 17, 2026
117 checks passed
@crazy-max
crazy-max deleted the github-release-retry branch August 17, 2026 11:29
nickpell pushed a commit to cloudx-io/openauction that referenced this pull request Aug 24, 2026
Weekly `ratchet` refresh of the SHA-pinned GitHub Actions under
`.github/`. Two refs moved, both to the newest release inside their
existing `# ratchet:` constraint. No constraint comment was rewritten
and no workflow logic changed.

## Refs that moved

| Action | File | Constraint | Version | SHA |
|---|---|---|---|---|
| `aws-actions/amazon-ecr-login` | `.github/workflows/docker.yml` |
`@v2` (unchanged) | v2.1.6 → v2.1.7 |
`d539f0932e70871a027e9d5a9d8fc38589180a64` →
`03f1aad4c6c7ffd436567f42f9384779290529bd` |
| `docker/setup-buildx-action` | `.github/workflows/docker.yml` | `@v4`
(unchanged) | v4.2.0 → v4.3.0 |
`bb05f3f5519dd87d3ba754cc423b652a5edd6d2c` →
`37fe631027851001ddb9b187196cc803df7f5f0e` |

## Upstream changelog

**[aws-actions/amazon-ecr-login
v2.1.7](https://github.com/aws-actions/amazon-ecr-login/releases/tag/v2.1.7)**
(published 2026-08-19). The changelog entry contains a single
*Dependency Updates* section — no features, fixes, or breaking-change
entries.

- `@aws-sdk/client-ecr`, `@aws-sdk/client-ecr-public`,
`@aws-sdk/credential-providers`: 3.1065.0 → 3.1111.0
- `undici` (transitive): 6.24.0 → 6.28.0
- Development-only: `eslint`, `globals`, `@vercel/ncc`, plus upstream's
own CI action pins
- `action.yml` is byte-identical between v2.1.6 and v2.1.7, so inputs,
outputs, and the action runtime are unchanged

**[docker/setup-buildx-action
v4.3.0](https://github.com/docker/setup-buildx-action/releases/tag/v4.3.0)**
(published 2026-08-19). The release notes list only dependency bumps.

- `@docker/actions-toolkit`: 0.92.0 → 0.95.0
- `js-yaml` 5.2.0 → 5.3.0; `brace-expansion` 1.1.13 → 1.1.18, `postcss`
8.5.10 → 8.5.25, `undici` 6.27.0 → 6.28.0 (transitive)
- `action.yml` is byte-identical between v4.2.0 and v4.3.0
- The behaviour-relevant content in the toolkit range is: retries added
around GitHub release-metadata fetches
([actions-toolkit#1276](docker/actions-toolkit#1276),
confined to `src/github/github.ts`), an **opt-in** Rekor v2 path for
cosign signing
([actions-toolkit#1176](docker/actions-toolkit#1176)),
an `undock` helper update, and `@actions/cache` 6.1.0 → 6.2.0

Neither release is labelled breaking, and neither carries a
breaking-change section. Both are patch/minor releases within the major
this repository already pins.

## Risk assessment

Low. The diff is two SHA values in one workflow file.

- **No contract change.** Each action's `action.yml` is unchanged across
the bump, so the inputs this repository passes — `platforms:` for the
buildx setup step, and no inputs for the ECR login step — resolve
exactly as before.
- **No major held back.** After this update every ratchet-managed ref
under `.github/` sits at the tip of its declared constraint, and no
action has a newer major tag upstream than the one currently pinned.
Nothing needed `ratchet upgrade`, so no `# ratchet:` constraint comment
was rewritten.
- **PR CI does not exercise these two steps.** Both changed refs live in
`.github/workflows/docker.yml`, which is triggered by `workflow_run`
after the Go workflow completes and by `workflow_dispatch`; it does not
run on pull requests. PR CI therefore confirms the refs are pinned and
that pinning is idempotent, but the two updated actions are first
exercised by Docker Build after this merges to `main`. That is covered
in the post-merge section below.
- **Most likely observable effect** is the buildx toolkit's new retry on
release-metadata fetches, which makes buildx setup more tolerant of
transient GitHub API failures. The Rekor v2 addition is opt-in and this
workflow does not enable it.
- For the ECR login step, the AWS SDK bump is a routine cumulative range
and the step's behaviour — authenticating the local Docker client
against the account registry — is unchanged.
- No open upstream issues report regressions against either version.

## Pre-merge checklist

- [x] `mise run //:ratchet:update` applied; re-running it produces no
further diff
- [x] `mise run //:ratchet:lint` passes — every external ref is still
pinned
- [x] `mise run //:ratchet:pin` is idempotent — `git diff --exit-code`
is clean afterwards
- [x] Diff limited to two SHA pins in `.github/workflows/docker.yml`; no
constraint comment changed and no unrelated workflow edits
- [x] Upstream release notes reviewed for both bumps; neither is
labelled breaking
- [ ] PR CI green, including `Ratchet Lint`

## Post-merge verification

- [ ] Workflows on `main` reference the new pins
- [ ] The first Docker Build run on `main` after merge succeeds. This is
where both updated actions are first exercised, since `docker.yml` does
not run on pull requests: the buildx setup step on every run, and the
ECR login step on a publishing run.

<div><a
href="https://cursor.com/agents/bc-5a0208aa-ff1b-4944-bb4b-f90b8d2aa38c?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/automations/65e8572f-8209-11f1-a7d1-d6b4613131ce"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/view-automation-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/view-automation-light.png"><img
alt="View Automation" width="141" height="28"
src="https://cursor.com/assets/images/view-automation-dark.png"></picture></a>&nbsp;</div>

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants