Push images to Vercel Container Registry from GitHub Actions

Vercel adds a GitHub Action that logs into Vercel Container Registry using OIDC, letting workflows push images without long-lived credentials. The action exchanges the workflow token for a short-lived VCR token, logs out and revokes it after the job, and supports Docker, Podman, or Buildah. Developers can now integrate secure image pushes directly in CI pipelines.

Vercel released a GitHub Action called vercel/vcr-action/login that lets a workflow authenticate to VCR using GitHub OIDC. The action swaps the workflow’s OIDC token for a short‑lived VCR access token, logs in to vcr.vercel.com, and revokes the token when the job finishes. It works with Docker by default and can be directed to use Podman or Buildah instead. By removing the need for long‑lived registry credentials, the new action reduces the attack surface for supply‑chain attacks. Teams can store only the Vercel team ID as a repository variable and grant the workflow id-token: write permission, keeping secret handling simple. The short‑lived token is automatically logged out and revoked, providing a more secure CI pipeline for pushing images such as linux/amd64 builds. It is not yet clear how the action will behave with alternative platforms beyond the documented Docker, Podman, and Buildah options. Vercel has not published performance benchmarks for the token exchange or the impact on build times. The long‑term support policy for the action’s versions, such as v1, remains unspecified.