Skip to content

[18-stable] Update GitHub Actions Dependencies to v3 (18-stable)#429

Open
ospk8s-renovate[bot] wants to merge 1 commit into
18-stablefrom
renovate/18-stable-major-github-actions-dependencies
Open

[18-stable] Update GitHub Actions Dependencies to v3 (18-stable)#429
ospk8s-renovate[bot] wants to merge 1 commit into
18-stablefrom
renovate/18-stable-major-github-actions-dependencies

Conversation

@ospk8s-renovate

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
redhat-actions/buildah-build action major v2v3
redhat-actions/push-to-registry action major v2v3

Release Notes

redhat-actions/buildah-build (redhat-actions/buildah-build)

v3.0.1

Compare Source

Bug Fixes
  • Fix container mode storage permission error: The buildah-image feature hardcoded the rootful storage path /var/lib/containers/storage, which fails with permission denied on rootless runners. The action now detects the host's actual storage root via podman info at runtime, with a fallback to the previous path. #​175
CI & Infrastructure
  • Add unit test suite using vitest and a test job in CI. #​175

v3.0.0

Compare Source

Breaking Changes
  • Node.js 24 runtime: The action now runs on the Node.js 24 runtime (runs.using: node24). GitHub Actions runners must support this runtime. #​154
  • Squash defaults to true: The squash input now defaults to true, matching common usage. Set squash: false to preserve intermediate layers. #​161
New Features
  • Annotations input: Add OCI annotations to images using the new annotations input. Separate multiple annotations by newline. Only supported by OCI images. #​161
  • Container mode (buildah-image input): Run buildah from a container image instead of the host-installed version. Useful for getting a newer buildah than what the runner provides. For example, buildah-image: quay.io/buildah/stable. #​168
  • Podman fallback: When buildah is not installed on the runner, the action automatically falls back to using podman build for containerfile builds. Scratch builds still require buildah. #​169
  • Multiple ports: The port input now accepts multiple ports separated by newline. #​165
  • Parallel multi-arch builds: When building for multiple architectures, each architecture is now built in parallel for significantly faster builds. #​167
  • Architecture verification: After each multi-arch build, the action verifies the output image matches the expected architecture, catching misconfigured emulation early. #​166
  • Image digest output: The digest output now reliably returns the content digest of the built image. #​153, #​165
Bug Fixes
  • Fix empty entrypoint being set when the input is not provided. #​161
  • Fix containerfile path resolution to check both workspace and context directory. #​165
  • Fix digest retrieval using buildah images --format {{.Digest}} instead of buildah inspect which returned the wrong type. #​165
CI & Infrastructure
  • Modernize all CI workflows: upgrade to actions/checkout@v7, actions/setup-node@v7, ubuntu-24.04 runners. #​156
  • Add workflow permissions, concurrency groups, and path filters. #​156
  • Remove broken install_latest_buildah.sh script and simplify CI matrices. #​164
  • Remove defunct CRDA vulnerability scan workflow. #​170
  • Enable Dependabot for npm and GitHub Actions dependencies. #​156
  • Add CODEOWNERS, SECURITY.md. #​156
Dependency Updates
  • Upgrade TypeScript to 6.x. #​163
  • Upgrade ESLint to 10 with flat config. #​156
  • Upgrade @actions/core, @actions/exec, @actions/io to latest versions. #​150, #​156
  • Upgrade @types/node to v26. #​159
  • Upgrade redhat-actions/common to v2. #​158

v3

Compare Source

Bug Fixes
  • Fix container mode storage permission error: The buildah-image feature hardcoded the rootful storage path /var/lib/containers/storage, which fails with permission denied on rootless runners. The action now detects the host's actual storage root via podman info at runtime, with a fallback to the previous path. #​175
CI & Infrastructure
  • Add unit test suite using vitest and a test job in CI. #​175

v2.13

Compare Source

v2.12

Compare Source

  • Forcibly remove existing manifest before creating a new one. #​103

v2.11

Compare Source

v2.10

Compare Source

  • Make image and tag in lowercase, if found in uppercase. #​89
  • Add --tls-verify and extra-args input for buildah from command. #​92
  • Remove kubic packages from test workflows. #​93

v2.9

Compare Source

  • Add support for multiple archs and platforms.
  • Allow building image manifest if multi arch or platform is provided.

v2.8

Compare Source

v2.7

Compare Source

  • Add output image-with-tag which provides image name and its corresponding first tag present.
  • Replace input dockerfiles with containerfiles. Input dockerfiles will be present as alias of containerfiles.
  • Add matrix to install latest buildah. (Internal)
redhat-actions/push-to-registry (redhat-actions/push-to-registry)

v3.0.0

Compare Source

Breaking Changes
  • Upgrade action runtime from Node 20 to Node 24. #​113
  • Tags are no longer lowercased. Per the OCI distribution spec, only image names and registries are normalized to lowercase; tag case is now preserved. #​112, #​121
Features
  • Add Sigstore signing support via sigstore-private-key and sign-passphrase inputs. #​120
  • Add podman-args input for global podman flags (e.g. --storage-driver=vfs) that apply to all podman invocations, not just push. #​102, #​121
  • Add remote input for podman remote mode (--remote). When enabled, Docker image storage checks are skipped. #​95, #​122
Bug Fixes
  • Prefix unqualified source images with localhost/ when pushing to prevent podman from resolving to remote registries. #​66, #​121
  • Fix default tag fallback when tags input is empty. #​109
  • Fix registry input not being lowercased for OCI compliance. #​110
  • Fix deprecated fs.rmdir usage, replace with fs.rm. #​113
  • Fix typo in createDockerPodmanImageStorage function name. #​113
Dependency Updates
  • Upgrade @actions/core from 1.x to 3.x. #​113
  • Upgrade @actions/exec from 1.x to 3.x. #​113
  • Upgrade @actions/io from 1.x to 3.x. #​113
  • Upgrade TypeScript from 5.3 to 6.0. #​113
  • Migrate ESLint from v8 to v10 with flat config. #​113
  • Bump ini from 5.0.0 to 7.0.0. #​118
CI & Infrastructure
  • Modernize all CI workflows: update to ubuntu-24.04, latest action versions, add permissions and concurrency groups. #​114
  • Enable secret scanning and push protection. #​114
  • Add Dependabot configuration for npm and GitHub Actions. #​114
  • Add CODEOWNERS and SECURITY.md. #​114
Documentation
  • Add Required Permissions section to README. #​107, #​121
  • Document multi-line tag support using YAML pipe syntax. #​101, #​121
  • Add qemu version guidance for multi-arch manifest builds. #​85, #​121
  • Document podman remote mode usage. #​122

v3

Compare Source

Breaking Changes
  • Upgrade action runtime from Node 20 to Node 24. #​113
  • Tags are no longer lowercased. Per the OCI distribution spec, only image names and registries are normalized to lowercase; tag case is now preserved. #​112, #​121
Features
  • Add Sigstore signing support via sigstore-private-key and sign-passphrase inputs. #​120
  • Add podman-args input for global podman flags (e.g. --storage-driver=vfs) that apply to all podman invocations, not just push. #​102, #​121
  • Add remote input for podman remote mode (--remote). When enabled, Docker image storage checks are skipped. #​95, #​122
Bug Fixes
  • Prefix unqualified source images with localhost/ when pushing to prevent podman from resolving to remote registries. #​66, #​121
  • Fix default tag fallback when tags input is empty. #​109
  • Fix registry input not being lowercased for OCI compliance. #​110
  • Fix deprecated fs.rmdir usage, replace with fs.rm. #​113
  • Fix typo in createDockerPodmanImageStorage function name. #​113
Dependency Updates
  • Upgrade @actions/core from 1.x to 3.x. #​113
  • Upgrade @actions/exec from 1.x to 3.x. #​113
  • Upgrade @actions/io from 1.x to 3.x. #​113
  • Upgrade TypeScript from 5.3 to 6.0. #​113
  • Migrate ESLint from v8 to v10 with flat config. #​113
  • Bump ini from 5.0.0 to 7.0.0. #​118
CI & Infrastructure
  • Modernize all CI workflows: update to ubuntu-24.04, latest action versions, add permissions and concurrency groups. #​114
  • Enable secret scanning and push protection. #​114
  • Add Dependabot configuration for npm and GitHub Actions. #​114
  • Add CODEOWNERS and SECURITY.md. #​114
Documentation
  • Add Required Permissions section to README. #​107, #​121
  • Document multi-line tag support using YAML pipe syntax. #​101, #​121
  • Add qemu version guidance for multi-arch manifest builds. #​85, #​121
  • Document podman remote mode usage. #​122

v2.8

Compare Source


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • "every weekend"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@openshift-ci
openshift-ci Bot requested review from steveb and stuggi July 25, 2026 07:09
@openshift-ci

openshift-ci Bot commented Jul 25, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: ospk8s-renovate[bot]
Once this PR has been reviewed and has the lgtm label, please assign steveb for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci

openshift-ci Bot commented Jul 25, 2026

Copy link
Copy Markdown
Contributor

Hi @ospk8s-renovate[bot]. Thanks for your PR.

I'm waiting for a openstack-k8s-operators member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants