Skip to content

Update Konflux references - #251

Merged
openshift-merge-bot[bot] merged 1 commit into
mainfrom
konflux/references/main
Aug 24, 2026
Merged

Update Konflux references#251
openshift-merge-bot[bot] merged 1 commit into
mainfrom
konflux/references/main

Conversation

@red-hat-konflux-kflux-prd-rh02

@red-hat-konflux-kflux-prd-rh02 red-hat-konflux-kflux-prd-rh02 Bot commented Aug 22, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
quay.io/konflux-ci/tekton-catalog/task-apply-tags (source, changelog) tekton-bundle digest f89a59d2dae3c4
quay.io/konflux-ci/tekton-catalog/task-build-image-index (source, changelog) tekton-bundle digest 714a86dc2cda69
quay.io/konflux-ci/tekton-catalog/task-buildah-oci-ta (source, changelog) tekton-bundle digest de5580ccf32941
quay.io/konflux-ci/tekton-catalog/task-clair-scan (source, changelog) tekton-bundle minor 0.3.20.4.0
quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta (source, changelog) tekton-bundle patch 0.2.50.2.6
quay.io/konflux-ci/tekton-catalog/task-init (source, changelog) tekton-bundle digest 4dbbfed5f68715
quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta (source, changelog) tekton-bundle minor 0.9.00.10.1
quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta (source, changelog) tekton-bundle digest ee041e2393b4d0
quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan (source, changelog) tekton-bundle digest cc51335538a853
quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta (source, changelog) tekton-bundle digest c7ecd1e6bb2697

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

konflux-ci/konflux-test-tasks (quay.io/konflux-ci/tekton-catalog/task-clair-scan)

v0.4

Changed

0.4 is a dummy version used to facilitate the migration from clair-scan 0.3 to roxctl-scan 0.1

konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta)

v0.10.1

Changed
  • When input is empty, only run the skip-ta step and skip other steps
  • Use quay.io/konflux-ci/task-runner for the skip-ta step instead of ubi-minimal

v0.10.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 05:00 AM and 11:59 PM, only on Saturday (* 5-23 * * 6)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com>
@openshift-ci
openshift-ci Bot requested review from Mischulee and jsell-rh August 22, 2026 08:03
@coderabbitai

coderabbitai Bot commented Aug 22, 2026

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 0c10d6d7-5faf-4d3e-b726-3398f8adb39c

📥 Commits

Reviewing files that changed from the base of the PR and between dbb4ec9 and 3197803.

📒 Files selected for processing (4)
  • .tekton/hyperfleet-sentinel-chart-push.yaml
  • .tekton/hyperfleet-sentinel-chart-tag.yaml
  • .tekton/hyperfleet-sentinel-push.yaml
  • .tekton/hyperfleet-sentinel-tag.yaml
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • openshift-hyperfleet/architecture (manual)
  • openshift-hyperfleet/hyperfleet-api (manual) → reviewed against open PR #348 konflux/references/main instead of the default branch
  • openshift-hyperfleet/hyperfleet-sentinel (manual)
  • openshift-hyperfleet/hyperfleet-adapter (manual) → reviewed against open PR #281 konflux/references/main instead of the default branch
  • openshift-hyperfleet/hyperfleet-broker (manual)

Included review availability: Your plan provides up to 12 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Summary by CodeRabbit

  • Chores
    • Updated pinned build and release task components to newer revisions.
    • Upgraded repository cloning and dependency prefetching tasks.
    • Refreshed task references across chart push, image push, and tagging workflows.
    • Existing task parameters, conditions, and execution flow remain unchanged.

Walkthrough

Updated pinned Tekton task bundle references in four pipeline definitions. The changes update bundle digests and upgrade git-clone-oci-ta, prefetch-dependencies-oci-ta, and task-clair-scan. Task wiring, parameters, conditions, and execution flow remain unchanged.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to 31978

This change updates pinned Tekton task references without any demonstrated correctness, security, or availability issue; no actionable merge-blocking risk remains after normal verification.

Suggested reviewers: jsell-rh, mischulee, ciaranroche

🚥 Pre-merge checks | ✅ 11
✅ Passed checks (11 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (4 skipped: 4 unsupported.)
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Sec-02: Secrets In Log Output ✅ Passed HEAD^..HEAD changes only four Tekton YAML files; all 26 added lines are bundle references, with no slog, log, logr, zap, fmt.Print*, or secret-bearing log interpolation.
No Hardcoded Secrets ✅ Passed The diff only replaces OCI bundle tags and 64-character SHA-256 hex digests; no added credential names, embedded URL credentials, private keys, or base64 strings were found.
No Weak Cryptography ✅ Passed The commit changes only four Tekton YAML files; all added bundle pins use SHA-256 digests, and scans found no banned primitive or non-constant-time comparison usage.
No Injection Vectors ✅ Passed The diff adds only hardcoded, sha256-pinned Tekton bundle references. It adds no CWE-78 exec.Command, CWE-89 SQL, CWE-79 template.HTML, or CWE-502 yaml.Unmarshal pattern.
No Privileged Containers ✅ Passed The diff only changes pinned Tekton bundle digests in four build PipelineRun CI manifests; it adds no listed privileged setting, and the pre-existing Dockerfile USER root is documented as temporary.
No Pii Or Sensitive Data In Logs ✅ Passed The diff adds only pinned quay.io task bundle references. It adds no logging calls or raw request/response logging, so no stated PII exposure condition is introduced.
Title check ✅ Passed The title clearly identifies the main change: updating Konflux references.
Description check ✅ Passed The description directly documents the Konflux Tekton bundle updates and related version changes.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch konflux/references/main
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch konflux/references/main

Comment @coderabbitai help to get the list of available commands.

@hyperfleet-ci-bot

Copy link
Copy Markdown

Risk Score: 0 — risk/low

Signal Detail Points
PR size 52 lines +0
Sensitive paths none +0

Computed by hyperfleet-risk-scorer

@rafabene

Copy link
Copy Markdown
Member

/lgtm

@openshift-ci

openshift-ci Bot commented Aug 24, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: rafabene

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit 1f87fe2 into main Aug 24, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant