Skip to content

Update Konflux references (release-v0.8) (patch) - #3255

Open
red-hat-konflux[bot] wants to merge 1 commit into
release-v0.8from
konflux/references/release-v0.8
Open

Update Konflux references (release-v0.8) (patch)#3255
red-hat-konflux[bot] wants to merge 1 commit into
release-v0.8from
konflux/references/release-v0.8

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Apr 18, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
quay.io/konflux-ci/tekton-catalog/task-build-image-index (source, changelog) tekton-bundle patch 0.30.3.1
quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta (source, changelog) tekton-bundle minor 0.90.10.7
quay.io/konflux-ci/tekton-catalog/task-clair-scan (source, changelog) tekton-bundle patch 0.30.3.2
quay.io/konflux-ci/tekton-catalog/task-clamav-scan (source, changelog) tekton-bundle patch 0.30.3.1
quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check (source, changelog) tekton-bundle digest e78d0d30ccc688
quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks (source, changelog) tekton-bundle digest 2e5ebe027c9760
quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta (source, changelog) tekton-bundle minor 0.10.2.5
quay.io/konflux-ci/tekton-catalog/task-init (source, changelog) tekton-bundle patch 0.40.4.3
quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta (source, changelog) tekton-bundle patch 0.30.3.2
quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta (source, changelog) tekton-bundle patch 0.30.3.1
quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan (source, changelog) tekton-bundle patch 0.20.2.1
quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta (source, changelog) tekton-bundle digest f6a115e61b27e6
quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta (source, changelog) tekton-bundle minor 0.40.5
quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta (source, changelog) tekton-bundle digest 4961c44eb9d539
quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta (source, changelog) tekton-bundle digest 2dd5b3e6081c41

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

konflux-ci/build-pipeline-tasks (quay.io/konflux-ci/tekton-catalog/task-build-image-index)

v0.3.1

Fixed
  • Export SBOM_SKIP_VALIDATION into the step environment so the create-sbom step honors the parameter.
    The parameter did nothing before. Now it works as expected.
konflux-ci/konflux-test-tasks (quay.io/konflux-ci/tekton-catalog/task-clair-scan)

v0.3.2

Changed
  • Replaced quay.io/konflux-ci/oras:latest image with quay.io/konflux-ci/task-runner:1.5.0 in the oci-attach-report step.
Added
  • set docker-config-dir in clair-action report command

v0.3.1

Added
  • Declare DOCKER_CONFIG to get get credential to quay.io.
  • Increase retry to 5
konflux-ci/build-pipeline-tasks (quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta)

v0.3.2

  • Added enable-package-registry-proxy parameter to enable use of the package registry proxy when prefetching dependencies.
  • Added SERVICE_CA_TRUST_CONFIG_MAP_NAME and SERVICE_CA_TRUST_CONFIG_MAP_KEY parameters to mount the OpenShift service CA for verifying TLS connections to in-cluster services such as the package registry proxy.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 05:00 AM and 11:59 PM, only on Saturday (* 5-23 * * 6)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/release-v0.8 branch 4 times, most recently from ed94175 to 533c8b8 Compare April 24, 2026 18:52
@red-hat-konflux red-hat-konflux Bot changed the title Update Konflux references (release-v0.8) (minor) Update Konflux references (release-v0.8) Apr 24, 2026
@github-actions github-actions Bot added size: M and removed size: XS labels Apr 24, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/release-v0.8 branch from 533c8b8 to a5361fd Compare April 24, 2026 18:52
@codecov

codecov Bot commented Apr 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Flag Coverage Δ
acceptance 54.86% <ø> (ø)
generative 18.14% <ø> (ø)
integration 26.99% <ø> (ø)
unit 68.66% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/release-v0.8 branch 3 times, most recently from c5431ce to 21c6620 Compare May 2, 2026 07:39
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/release-v0.8 branch 5 times, most recently from 44badb2 to 0fee981 Compare May 16, 2026 07:29
@simonbaird
simonbaird enabled auto-merge May 20, 2026 21:42
@red-hat-konflux

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@simonbaird

Copy link
Copy Markdown
Member

I might force push to get rid of my deps updates, (which should be done in the base branch by now).

@simonbaird
simonbaird force-pushed the konflux/references/release-v0.8 branch from 2837694 to 0fee981 Compare July 31, 2026 13:51
@simonbaird

Copy link
Copy Markdown
Member

I'm still hoping @red-hat-konflux[bot] will redo this PR on a newer parent.

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 31, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 1:52 PM UTC · Completed 2:02 PM UTC
Commit: 87c4a29 · View workflow run →

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 31, 2026

Copy link
Copy Markdown

Review

Findings

Medium

  • [api-contract] .tekton/cli-v08-pull-request.yaml — The PR adds three new build parameters (SOURCE_DATE_EPOCH, REWRITE_TIMESTAMP, OMIT_HISTORY) and passes them to the build-container task in both pipeline files, but the buildah-remote-oci-ta task reference in pull-request.yaml remains at version 0.9 while push.yaml is updated to 0.10.7. These parameters were introduced in the 0.10.x line. With safe defaults ('', 'false', 'false'), existing behavior is preserved, but the reproducibility features will silently not take effect in PR builds if explicitly configured. The main-branch equivalent (cli-main-pull-request.yaml) already uses 0.10.5 with these parameters.
    Remediation: Update the buildah-remote-oci-ta task reference in cli-v08-pull-request.yaml to 0.10.7 to match push.yaml.
Previous run

Looks good to me

Previous run (2)

Looks good to me


Labels: PR modifies Tekton CI pipeline definitions under .tekton/

Previous run (3)

Review

Findings

Low

  • [security scanning scope] .tekton/cli-v08-pull-request.yaml:114 — The new pipeline parameter sast-target-dirs (default: .) is wired to the TARGET_DIRS param of sast-snyk-check, sast-shell-check, and sast-unicode-check tasks. While the default value . preserves full scan coverage, this parameter could theoretically be overridden at PipelineRun time to narrow SAST scan scope. Practical risk is low since pipeline parameters in Konflux are controlled by platform trigger configuration, not PR authors.

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added the ready-for-merge All reviewers approved — ready to merge label Jul 31, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/release-v0.8 branch from 0fee981 to 07b6ccb Compare July 31, 2026 14:04
@red-hat-konflux red-hat-konflux Bot changed the title Update Konflux references (release-v0.8) Update Konflux references (release-v0.8) (patch) Jul 31, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 31, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 2:05 PM UTC · Completed 2:11 PM UTC
Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/release-v0.8 branch from 07b6ccb to fdc191d Compare July 31, 2026 21:53
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 31, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 9:54 PM UTC · Completed 10:03 PM UTC
Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/release-v0.8 branch from fdc191d to a72993a Compare August 1, 2026 22:27
@fullsend-ai-review

fullsend-ai-review Bot commented Aug 1, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 10:28 PM UTC · Completed 10:40 PM UTC
Commit: 87c4a29 · View workflow run →

@fullsend-ai-review fullsend-ai-review Bot added requires-manual-review Review requires human judgment and removed ready-for-merge All reviewers approved — ready to merge labels Aug 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant