chore: bump outdated tool versions and pinned Actions - #3
Merged
Merged
Conversation
- Bump traefik feature default image from v3.3 to v3.7 — v3.3 is several minor releases behind and misses security fixes backported to the 3.6/3.7 lines (CVE-2026-54763, CVE-2026-54764, CVE-2026-54765, fixed in v3.6.22/v3.7.6). Bumped feature version 1.3.1 -> 1.3.2 per this repo's per-feature semver convention. - Bump actions/checkout v4 -> v7 across all workflows. v4 runs on the deprecated Node 20 runtime and predates the fix for the "pwn request" fork-checkout issue; v7 requires no runtime changes for our simple checkout usage. - Bump docker/login-action v3 -> v4, docker/metadata-action v5 -> v6, docker/setup-buildx-action v3 -> v4, docker/build-push-action v6 -> v7 in publish.yml to pick up Node 24 runtime support and current dependency/security patches.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Audited every
src/*/devcontainer-feature.json+install.sh, the rootDockerfile, and.github/workflows/*.ymlfor outdated or vulnerable pinned versions.Most CLI tool features (
claude-code,gemini-cli,openai-codex,opencode,stripe-cli,supabase-cli,tinybird-cli,uv) install vianpm install -g <pkg>or a vendorcurl | shscript with no version pin — they always resolve to latest at install time, so there was nothing to bump there.bun's feature already defaults itsversionoption to"latest". The base imagemcr.microsoft.com/devcontainers/base:bookwormis current stable Debian 12, not EOL.Found and fixed:
src/traefik/install.sh(generateddocker-compose.yml)traefik:v3.3→traefik:v3.7v3.3never received these backports.src/traefik/devcontainer-feature.jsonversion1.3.1→1.3.2.github/workflows/claude-code-review.yml,claude.yml,publish-features.yml,publish.ymlactions/checkout@v4→@v7pull_request_target/workflow_run, so this is a no-op behavior change for us..github/workflows/publish.ymldocker/login-action@v3→@v4.github/workflows/publish.ymldocker/metadata-action@v5→@v6.github/workflows/publish.ymldocker/setup-buildx-action@v3→@v4.github/workflows/publish.ymldocker/build-push-action@v6→@v7Left unchanged:
anthropics/claude-code-action@v1anddevcontainers/action@v1— both are moving major-version tags already pointing at the latestv1.xrelease, so no pin bump was needed.Test plan
claude-code-review.yml,claude.ymltriggers)publish.ymlandpublish-features.ymlmanually (workflow_dispatch) to confirm the bumped Docker/build actions still build & push successfullydevcontainer features test -f traefik .to confirm the bumped Traefik image starts cleanly with the existing static/dynamic config generation🤖 Generated with Claude Code
https://claude.ai/code/session_01LuHU3xhHJxcnxt2nzgUjMn
Generated by Claude Code