Skip to content

Update Konflux references - #348

Open
red-hat-konflux-kflux-prd-rh02[bot] wants to merge 1 commit into
mainfrom
konflux/references/main
Open

Update Konflux references#348
red-hat-konflux-kflux-prd-rh02[bot] wants to merge 1 commit into
mainfrom
konflux/references/main

Conversation

@red-hat-konflux-kflux-prd-rh02

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
quay.io/konflux-ci/tekton-catalog/task-apply-tags (source, changelog) tekton-bundle digest f89a59d2dae3c4
quay.io/konflux-ci/tekton-catalog/task-build-image-index (source, changelog) tekton-bundle digest 714a86dc2cda69
quay.io/konflux-ci/tekton-catalog/task-buildah-oci-ta (source, changelog) tekton-bundle digest de5580ccf32941
quay.io/konflux-ci/tekton-catalog/task-clair-scan (source, changelog) tekton-bundle minor 0.3.20.4.0
quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta (source, changelog) tekton-bundle patch 0.2.50.2.6
quay.io/konflux-ci/tekton-catalog/task-init (source, changelog) tekton-bundle digest 4dbbfed5f68715
quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta (source, changelog) tekton-bundle minor 0.9.00.10.1
quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta (source, changelog) tekton-bundle digest ee041e2393b4d0
quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan (source, changelog) tekton-bundle digest cc51335538a853
quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta (source, changelog) tekton-bundle digest c7ecd1e6bb2697

Release Notes

konflux-ci/konflux-test-tasks (quay.io/konflux-ci/tekton-catalog/task-clair-scan)

v0.4

Changed

0.4 is a dummy version used to facilitate the migration from clair-scan 0.3 to roxctl-scan 0.1

konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta)

v0.10.1

Changed
  • When input is empty, only run the skip-ta step and skip other steps
  • Use quay.io/konflux-ci/task-runner for the skip-ta step instead of ubi-minimal

v0.10.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 05:00 AM and 11:59 PM, only on Saturday (* 5-23 * * 6)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com>
@openshift-ci
openshift-ci Bot requested review from Ruclo and mliptak0 August 22, 2026 08:03
@openshift-ci

openshift-ci Bot commented Aug 22, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign rh-amarin for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@coderabbitai

coderabbitai Bot commented Aug 22, 2026

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 50407645-7942-4c7d-86ab-6f95b79cb344

📥 Commits

Reviewing files that changed from the base of the PR and between 541f6b4 and 5d0b66c.

📒 Files selected for processing (4)
  • .tekton/hyperfleet-api-chart-push.yaml
  • .tekton/hyperfleet-api-chart-tag.yaml
  • .tekton/hyperfleet-api-push.yaml
  • .tekton/hyperfleet-api-tag.yaml
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • openshift-hyperfleet/architecture (manual)
  • openshift-hyperfleet/hyperfleet-api (manual)
  • openshift-hyperfleet/hyperfleet-sentinel (manual) → reviewed against open PR #251 konflux/references/main instead of the default branch
  • openshift-hyperfleet/hyperfleet-adapter (manual) → reviewed against open PR #281 konflux/references/main instead of the default branch
  • openshift-hyperfleet/hyperfleet-broker (manual)

Included review availability: Your plan provides up to 12 included reviews per hour; 10 remain after this review.


📝 Walkthrough

Summary by CodeRabbit

  • Chores
    • Updated the CI/CD pipeline task versions and image references.
    • Refreshed tasks for source retrieval, dependency preparation, image builds, tagging, publishing, and security scanning.
    • Pipeline behavior, configuration, and execution flow remain unchanged.

Walkthrough

The change updates pinned Tekton task bundle versions and image digests in four pipeline definitions. It updates initialization, repository cloning, dependency prefetching, image building, image indexing, source-image building, Clair scanning, tag application, Dockerfile pushing, and RPM signature scanning references. Task parameters, ordering, conditions, workspaces, and pipeline behavior remain unchanged.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: 🔵 Low · up to 5d0b6

This PR refreshes pinned Tekton task bundles used by build and tagging pipelines. The references have matching digests and valid task interfaces, but the six updated artifacts still need owner confirmation that they correspond to the intended upstream releases; the change is mergeable with that awareness.

Suggested reviewers: mliptak0, ruclo, ciaranroche

🚥 Pre-merge checks | ✅ 11
✅ Passed checks (11 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (4 skipped: 4 unsupported.)
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Sec-02: Secrets In Log Output ✅ Passed The PR diff changes only pinned Tekton bundle image references in four YAML files; it adds no slog, log, logr, zap, or fmt.Print statement with secret fields or interpolation.
No Hardcoded Secrets ✅ Passed The PR changes only pinned Tekton image versions and SHA-256 digests. Added lines contain no credential URLs, key markers, named secret literals, or non-digest base64 strings.
No Weak Cryptography ✅ Passed The HEAD diff only updates Tekton bundle references; all introduced digests are 64-hex SHA-256 values, with no MD5, DES, RC4, SHA-1, ECB, or comparison code.
No Injection Vectors ✅ Passed HEAD diff changes only 26 pinned OCI bundle values in four YAML files; no added SQL, exec.Command, template.HTML, or yaml.Unmarshal pattern (CWE-89/78/79/502).
No Privileged Containers ✅ Passed HEAD^..HEAD changes only pinned bundle references in four Tekton PipelineRun CI manifests; no privilege fields changed. Existing Dockerfile USER root is unchanged and limited to package installation.
No Pii Or Sensitive Data In Logs ✅ Passed The PR changes only 26 pinned Tekton bundle-reference lines in four YAML files; no slog, logr, zap, log, fmt.Print, PII, or request/response logging was added.
Title check ✅ Passed The title clearly identifies the main change: updating Konflux references.
Description check ✅ Passed The description directly documents the updated Konflux Tekton bundle references and version changes.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch konflux/references/main
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch konflux/references/main

Comment @coderabbitai help to get the list of available commands.

@hyperfleet-ci-bot

Copy link
Copy Markdown

Risk Score: 0 — risk/low

Signal Detail Points
PR size 52 lines +0
Sensitive paths none +0

Computed by hyperfleet-risk-scorer

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants