Skip to content

chore(deps): bump docker/setup-buildx-action from 4.3.0 to 4.4.1 - #20

Open
dependabot[bot] wants to merge 63 commits into
mainfrom
dependabot/github_actions/docker/setup-buildx-action-4.4.1
Open

dependabot[bot] wants to merge 63 commits into
mainfrom
dependabot/github_actions/docker/setup-buildx-action-4.4.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026

Copy link
Copy Markdown
Contributor

Bumps docker/setup-buildx-action from 4.3.0 to 4.4.1.

Release notes

Sourced from docker/setup-buildx-action's releases.

v4.4.1

Full Changelog: docker/setup-buildx-action@v4.4.0...v4.4.1

v4.4.0

Full Changelog: docker/setup-buildx-action@v4.3.0...v4.4.0

Commits
  • f87e599 Merge pull request #624 from crazy-max/skip-pull-with-endpoint
  • e700274 chore: update generated content
  • 3061c91 skip BuildKit image pre-pulls for explicit endpoints
  • 594f3bf Merge pull request #609 from crazy-max/pull-buildkit-image-before-create
  • bd6e702 chore: update generated content
  • 6268c9d pull BuildKit image before builder creation
  • e823525 Merge pull request #621 from docker/dependabot/github_actions/codeql-actions-...
  • 533ed8e build(deps): bump the codeql-actions group with 2 updates
  • bedaf13 Merge pull request #620 from crazy-max/shared-error-helpers
  • d5079fb chore: update generated content
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

bjohns and others added 30 commits June 10, 2026 14:32
- Add git, unzip, make, gcc, gcc-c++ to builder stage (needed for
  tree-sitter native addon compilation and build script git calls)
- Set TINYCODE_CHANNEL=container to bypass git branch detection in
  build.ts when building without a .git directory
- Apply same fixes to ContainerFile (production) and ContainerFile.local

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Ollama running on the host is unreachable via localhost inside a
container. Default to host.containers.internal:11434 and allow
override via OLLAMA_HOST env var.

Config is written to config.json which tinycode merges with defaults
via mergeDeep (config.ts:484), so provider.ollama.options.baseURL
correctly overrides the hardcoded localhost URL.

For k8s: set OLLAMA_HOST to your cluster-accessible Ollama URL.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
- entrypoint.sh: use TINYCODE_OLLAMA_HOST env var (now native in tinycode)
  instead of config.json provider override; default to host.containers.internal
- entrypoint.sh: drop --port flag, rely on TINYCODE_PORT env var (issue #1 fix)
- deployment.yaml: switch probes from tcpSocket to httpGet /global/health
  (now unauthenticated, issue #2 fix); add TINYCODE_PORT=3000 env var

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…, update README

- entrypoint.sh: remove port override, tinycode now uses its default 4096
- ContainerFile: EXPOSE 4096
- k8s/: all port references updated from 3000 to 4096
- CONTAINER.md: authoritative interface contract linking tiny-container and tinycode-operator
- README.md: port corrected, Issues section removed (fixed upstream), Ecosystem section added

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…ction

entrypoint.sh: when TINYCODE_CLUSTER_ADMIN=true, downloads the static oc
binary to ~/.local/bin/ at startup (skipped if already present). Wraps
download in set+e so failure is non-fatal — container starts in degraded
mode with a clear warning. After download, auto-detects cluster type via
oc api-resources and exports TINYCODE_CLUSTER_TYPE=openshift|kubernetes.

ContainerFile / ContainerFile.local: add curl to runtime stage and add
~/.local/bin to PATH so the downloaded oc binary is immediately usable.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Rename the project from tiny-container to tinycode-container for consistency
with the tinycode ecosystem naming (tinycode, tinycode-operator). Consolidates
all image references to ghcr.io/bjohns/tinycode-container:latest. Also fixes
pre-existing bug in install.sh (wrong GitHub org in URL).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Align deployment manifests and CONTAINER.md with the quay.io registry
that the cluster actually uses. CI workflow still pushes to ghcr.io.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Copy 41 agent definitions and 5 skills into the config directory
during image build so they're available in the web UI on deployed
instances, not just local TUI sessions.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…PVC shadow

Root cause: PVC mounted at ~/.config/tinycode/ shadows files COPY'd into
the image at build time. The COPY'd agent/ and skills/ dirs were invisible
at runtime because the PVC mount hides the entire parent directory.

Fix: COPY to /opt/tinycode-defaults/ (not PVC-mounted), then entrypoint.sh
copies them into the PVC config dir on startup with cp -n (no-clobber so
user customizations survive).

Also adds config/agent/ and config/skills/ to the build context with all
44 agent files and 13 skill directories.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
tmux fails on OpenShift when SHELL=/sbin/nologin (the container user's
login shell). Set SHELL=/bin/sh in the ENV block. Also move agent/skill
COPY to /opt/tinycode-defaults/ so the PVC mount on ~/.config/tinycode/
doesn't shadow them — the entrypoint copies them into the PVC on startup.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Fix issue #3: Change github_token build secret from GITHUB_TOKEN to GH_PAT (Classic PAT with repo scope needed for private repo clones during build)
- Fix issue #5: Add Quay.io as primary registry with dual-push to both quay.io and ghcr.io
- Update install.sh to use quay.io/bjohns/tinycode-container as primary image source
- Update README.md to reference quay.io as primary registry with GHCR as mirror

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
bobbyjohnstx and others added 24 commits June 26, 2026 10:44
Added community files for open-source release readiness:
- CONTRIBUTING.md with container build/test workflow and environment variable contract reference
- SECURITY.md with vulnerability reporting process

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…security docs

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Enables building amd64 images on arm64 hosts:
  BUILD_PLATFORM=linux/amd64 IMAGE_TAG=quay.io/bjohns/tinycode-container:v13 ./build-local.sh

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…ts PVC, doc drift, dockerignore, pin refs

- Add git-core to ContainerFile runtime stage for GitOps mode
- Fix arm64 tmux RPM URLs using $(uname -m) architecture detection
- Add emptyDir mounts for readOnlyRootFilesystem compatibility
- Add /projects PVC (5Gi) for user workspace files
- Fix build-local.sh port references (3000 → 4096)
- Fix documentation drift: UBI9-minimal → UBI9, tmux v3.4 → v3.2a
- Add .dockerignore for faster builds
- Add ARG TINYCODE_REF/OMT_REF for pinnable git refs

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
… config generation

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- arm64 tmux RPM architecture detection
- Added git-core to CI runtime image (GitOps mode)
- readOnlyRootFilesystem emptyDir mounts for writable paths
- Added /projects PVC mount to k8s deployment
- build-local.sh port corrected to 4096
- Documentation drift (UBI9 not UBI9-minimal, RPM not compiled from source)
- .dockerignore for build context optimization
- Pinnable git clone refs (TINYCODE_REF, OMT_REF build args)
- bats test suite for entrypoint validation

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- actions/checkout: v4 → v7
- docker/setup-qemu-action: v3 → v4
- docker/setup-buildx-action: v3 → v4
- docker/login-action: v3 → v4
- docker/build-push-action: v6 → v7

All actions updated to SHA-pinned versions for security.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…le docs

- entrypoint.sh: use printf instead of echo to prevent newline bypass in VLLM_MODEL validation; add 255-char length check
- test/entrypoint.bats: replace hardcoded /private/tmp/tinycode-container/ paths with $BATS_TEST_DIRNAME/../ for CI portability
- CONTAINER.md: update VLLM_MODEL validation description to match actual regex (add _, :, @, space)
- CONTRIBUTING.md: fix stale TINYCODE_COMMAND example to use correct tinycode --version syntax
- k8s/overlays/ingress/kustomization.yaml: exclude OpenShift Route from vanilla Kubernetes ingress overlay via $patch: delete

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
GitHub Actions runners require sudo to install to /usr/local.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…useful

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Allows tagging container images with a semantic version (e.g. v1.17.0)
and building from a specific tinycode git ref instead of always main.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 4.1.0 to 4.3.0.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@d7f5e7f...37fe631)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Quay.io login and tags are now skipped when QUAY_USERNAME/QUAY_PASSWORD
secrets are not configured. GH_PAT falls back to GITHUB_TOKEN for
repo clones. This allows the build to succeed with just GHCR.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Quay.io login and tags are now skipped when QUAY_USERNAME/QUAY_PASSWORD
secrets are not configured. Uses env var check instead of secrets context
in conditionals. GH_PAT falls back to GITHUB_TOKEN for repo clones.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add plugins/ directory for pre-baking tinycode plugins into the image.
Install npm plugins into plugins/ with `npm install`, commit the
node_modules, and the entrypoint auto-discovers and registers them.

- ContainerFile COPYs plugins/ to /opt/tinycode-plugins/
- Entrypoint scans node_modules/tinycode-plugin-* and adds to config
- Works with zero plugins (empty directory is fine)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
oh-my-tiny is built into tinycode natively now, so the separate
clone/build stage and plugin registration are no longer needed.
This also removes the github_token secret requirement since
tinycode is a public repo.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…cker/setup-buildx-action-4.3.0

chore(deps): bump docker/setup-buildx-action from 4.1.0 to 4.3.0
GITHUB_TOKEN can only push to packages under the repo owner namespace.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 4.3.0 to 4.4.1.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@37fe631...f87e599)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant