Skip to content

Bump docker/setup-buildx-action from 3.11.1 to 4.3.0 - #110

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/docker/setup-buildx-action-4.3.0
Closed

Bump docker/setup-buildx-action from 3.11.1 to 4.3.0#110
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/docker/setup-buildx-action-4.3.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Bumps docker/setup-buildx-action from 3.11.1 to 4.3.0.

Release notes

Sourced from docker/setup-buildx-action's releases.

v4.3.0

Full Changelog: docker/setup-buildx-action@v4.2.0...v4.3.0

v4.2.0

Full Changelog: docker/setup-buildx-action@v4.1.0...v4.2.0

v4.1.0

Full Changelog: docker/setup-buildx-action@v4.0.0...v4.1.0

v4.0.0

... (truncated)

Commits
  • 37fe631 Merge pull request #595 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • b5c4f91 [dependabot skip] chore: update generated content
  • 3e93b63 build(deps): bump @​docker/actions-toolkit from 0.92.0 to 0.95.0
  • e527031 Merge pull request #600 from docker/dependabot/npm_and_yarn/brace-expansion-1...
  • c68814b [dependabot skip] chore: update generated content
  • 3f891b0 build(deps): bump brace-expansion from 1.1.13 to 1.1.18
  • 787db26 Merge pull request #585 from docker/dependabot/npm_and_yarn/js-yaml-5.2.1
  • f779368 [dependabot skip] chore: update generated content
  • 7d5e604 build(deps): bump js-yaml from 5.2.0 to 5.3.0
  • 292c2fb Merge pull request #590 from docker/dependabot/github_actions/actions/setup-n...
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 24, 2026
@dependabot
dependabot Bot requested a review from jeremydixon22 as a code owner August 24, 2026 00:29
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 24, 2026
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 3.11.1 to 4.3.0.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@e468171...37fe631)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/docker/setup-buildx-action-4.3.0 branch from 3c85e33 to 57ca214 Compare August 24, 2026 07:34
jeremydixon22 added a commit that referenced this pull request Aug 24, 2026
## Summary

- Refresh the Buildx action pin and the release-policy assertions that
protect it.
- Apply the pending AWS, Google, Azure Durable Functions, and Semantic
Kernel package updates.
- Regenerate every affected downstream NuGet lock graph so locked
restores remain complete for all target frameworks.

This consolidates and supersedes #110-#115. PR #113 duplicates the
Google.Apis.Core portion of #112.

PR #108 is intentionally excluded: the current CodeQL bundle (2.26.3) is
built with Go 1.26 and emits extraction errors against Go 1.27. Upstream
says Go 1.27 support will arrive in the next CodeQL release:
github/codeql#22394 (comment).
Retaining Go 1.26.6 preserves complete security analysis until that
lands.

## Verification

- [x] Relevant unit and conformance tests pass.
- [x] Public API, contract, and maturity documentation is updated when
applicable.
- [x] Provider-specific behavior has an opt-in live gate and does not
widen a portable claim.
- [x] No credentials, customer data, local paths, generated artifacts,
or deployment identities are included.
- [x] Release artifacts and public export were rehearsed when a package,
client, container, or workflow changed.

Local verification included locked restore, Release build, the
deterministic .NET suite, Go tests, NuGet vulnerability audit, policy
verifiers, and public-export rehearsal.

## Public information review

Does this change expose new public information? **No**

## Compatibility and operations

No application contract or deployment behavior changes. NuGet consumers
receive patch/minor dependency refreshes.

---------

Co-authored-by: jeremydixon22 <jeremydixon22@users.noreply.github.com>
@jeremydixon22

Copy link
Copy Markdown
Member

Superseded by #116, which applies this update together with the complete downstream lock-graph and policy-pin refreshes and passed the full repository gate set.

@dependabot @github

dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/docker/setup-buildx-action-4.3.0 branch August 24, 2026 07:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant