Skip to content

ci: add dependency update workflow - #4000

Draft
crazy-max wants to merge 1 commit into
docker:masterfrom
crazy-max:update-deps
Draft

crazy-max wants to merge 1 commit into
docker:masterfrom
crazy-max:update-deps

Conversation

@crazy-max

@crazy-max crazy-max commented Aug 5, 2026 •

Copy link
Copy Markdown
Member

This adds an update-deps workflow that opens dependency update pull requests for the Dockerfile versions used by the test image.

The workflow resolves the latest release tags for Docker, registry, BuildKit, Compose, Scout and Undock, updates the matching Dockerfile arguments, and creates a signed pull request for each dependency. The BuildKit update also refreshes the test-integration matrix so it keeps testing master, latest, buildx-stable-1, and the latest three stable minor BuildKit release tags.

@crazy-max
crazy-max force-pushed the update-deps branch 2 times, most recently from e0ebe45 to aa6e841 Compare August 5, 2026 16:07
@crazy-max
crazy-max requested a review from vvoland August 6, 2026 13:34
@crazy-max
crazy-max marked this pull request as ready for review August 6, 2026 13:34
Comment thread .github/workflows/update-deps.yml Outdated
Comment thread .github/workflows/update-deps.yml
Comment thread .github/workflows/update-deps.yml Outdated
@crazy-max

Copy link
Copy Markdown
Member Author

Also added pull_request event to verify the changes: https://github.com/docker/buildx/actions/runs/31488665508/job/93769785673?pr=4000#step:5:11

@crazy-max
crazy-max requested a review from tonistiigi August 11, 2026 13:16
@crazy-max crazy-max added this to the v0.38.0 milestone Sep 16, 2026
@crazy-max crazy-max modified the milestones: v0.38.0, v0.39.0 Sep 30, 2026
@crazy-max
crazy-max requested a review from a team October 8, 2026 08:06
@thaJeztah

Copy link
Copy Markdown
Member

Silly question; could this be done with (forking-)renovate?

@crazy-max
crazy-max force-pushed the update-deps branch 2 times, most recently from 92211a4 to ebee25e Compare October 8, 2026 08:21
@crazy-max

Copy link
Copy Markdown
Member Author

Silly question; could this be done with (forking-)renovate?

I'm not sure tbh, just wanted smth similar to what we already do on other repos:

Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
@vvoland

vvoland commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

FYI, you can do something like moby/moby#53698 with renovate

Comment on lines +21 to +23
push:
branches:
- 'master'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we really want to trigger the whole update logic on every push to master?

@crazy-max

Copy link
Copy Markdown
Member Author

FYI, you can do something like moby/moby#53698 with renovate

Can be tricky with the buildkit matrix one and not sure if Renovate is allowed in our org atm

@thaJeztah

Copy link
Copy Markdown
Member

not sure if Renovate is allowed in our org atm

Forking renovate (what we use in moby) opens PRs from a fork, which means it doesn't need any access to the repository (so, probably more secure than (eg) dependabot)

branch: 'deps/scout-version',
owner: 'docker',
repo: 'scout-cli',
path: '.github/workflows/build.yml',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh, IIRC the default GITHUB_TOKEN will be able to push a branch that modifies the workflows

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah good call out, without a GitHub App it will not be able to update workflow files.

I will take a look

@crazy-max
crazy-max marked this pull request as draft October 8, 2026 09:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants