Skip to content

Update Konflux references (main) (minor) - #3254

Merged
simonbaird merged 1 commit into
mainfrom
konflux/references/main
Jul 31, 2026
Merged

Update Konflux references (main) (minor)#3254
simonbaird merged 1 commit into
mainfrom
konflux/references/main

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Apr 18, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
quay.io/konflux-ci/tekton-catalog/task-build-image-index (source, changelog) tekton-bundle minor 0.20.3.1
quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta (source, changelog) tekton-bundle minor 0.90.10.5
quay.io/konflux-ci/tekton-catalog/task-clair-scan (source, changelog) tekton-bundle patch 0.30.3.2
quay.io/konflux-ci/tekton-catalog/task-clamav-scan (source, changelog) tekton-bundle patch 0.30.3.1
quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check (source, changelog) tekton-bundle digest e78d0d30ccc688
quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks (source, changelog) tekton-bundle digest 2e5ebe027c9760
quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta (source, changelog) tekton-bundle minor 0.10.2.5
quay.io/konflux-ci/tekton-catalog/task-init (source, changelog) tekton-bundle patch 0.40.4.3
quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta (source, changelog) tekton-bundle patch 0.30.3.2
quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta (source, changelog) tekton-bundle patch 0.30.3.1
quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan (source, changelog) tekton-bundle patch 0.20.2.1
quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta (source, changelog) tekton-bundle digest f6a115e5e4586b
quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta (source, changelog) tekton-bundle minor 0.40.5
quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta (source, changelog) tekton-bundle digest 4961c44eb9d539

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

konflux-ci/build-pipeline-tasks (quay.io/konflux-ci/tekton-catalog/task-build-image-index)

v0.3.1

Fixed
  • Export SBOM_SKIP_VALIDATION into the step environment so the create-sbom step honors the parameter.
    The parameter did nothing before. Now it works as expected.

v0.3

Fixed
  • Export SBOM_SKIP_VALIDATION into the step environment so the create-sbom step honors the parameter.
    The parameter did nothing before. Now it works as expected.
konflux-ci/build-definitions (quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta)

v0.10.5

Added
  • Added a new parameter RHSM_MOUNT_CA_CERTS to allow setting [konflux-build-cli]'s
    --rhsm-mount-ca-certs option.

v0.10

Added
  • Added a new parameter RHSM_MOUNT_CA_CERTS to allow setting [konflux-build-cli]'s
    --rhsm-mount-ca-certs option.
konflux-ci/konflux-test-tasks (quay.io/konflux-ci/tekton-catalog/task-clair-scan)

v0.3.2

Changed
  • Replaced quay.io/konflux-ci/oras:latest image with quay.io/konflux-ci/task-runner:1.5.0 in the oci-attach-report step.
Added
  • set docker-config-dir in clair-action report command

v0.3.1

Added
  • Declare DOCKER_CONFIG to get get credential to quay.io.
  • Increase retry to 5
konflux-ci/build-pipeline-tasks (quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta)

v0.3.2

  • Added enable-package-registry-proxy parameter to enable use of the package registry proxy when prefetching dependencies.
  • Added SERVICE_CA_TRUST_CONFIG_MAP_NAME and SERVICE_CA_TRUST_CONFIG_MAP_KEY parameters to mount the OpenShift service CA for verifying TLS connections to in-cluster services such as the package registry proxy.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 05:00 AM and 11:59 PM, only on Saturday (* 5-23 * * 6)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/main branch 3 times, most recently from 0f18e82 to 1564d22 Compare April 18, 2026 07:35
@codecov

codecov Bot commented Apr 18, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Flag Coverage Δ
acceptance 54.26% <ø> (ø)
generative 16.80% <ø> (ø)
integration 27.97% <ø> (ø)
unit 71.75% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/main branch from 1564d22 to a9ff53d Compare April 24, 2026 18:51
@red-hat-konflux red-hat-konflux Bot changed the title Update Konflux references (main) (minor) Update Konflux references (main) Apr 24, 2026
@github-actions github-actions Bot added size: M and removed size: XS labels Apr 24, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/main branch 3 times, most recently from 65de3e8 to 8ce9f41 Compare May 2, 2026 07:37
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/main branch from 8ce9f41 to a500f9f Compare May 9, 2026 07:45
@red-hat-konflux red-hat-konflux Bot changed the title Update Konflux references (main) Update Konflux references (main) (minor) May 9, 2026
@github-actions github-actions Bot added size: XS and removed size: M labels May 9, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/main branch 4 times, most recently from fbf7ddf to 1c40ad0 Compare May 20, 2026 23:09
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/main branch 2 times, most recently from 1df25d0 to 401a56a Compare May 30, 2026 06:51
@github-actions github-actions Bot added size: S and removed size: XS labels May 30, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/main branch from 401a56a to 3737ca2 Compare June 20, 2026 05:22
@fullsend-ai-review

fullsend-ai-review Bot commented Jun 20, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 5:24 AM UTC · Completed 5:30 AM UTC
Commit: 47d3320 · View workflow run →

@fullsend-ai-review

fullsend-ai-review Bot commented Jun 20, 2026

Copy link
Copy Markdown

Looks good to me

Previous run

Review — ✅ Approve

Scope: Automated Tekton task reference updates in CI pipeline definitions (MintMaker/Renovate).

Changes verified

Task Version change Notes
task-git-clone-oci-ta 0.10.2 Minor bump with digest pin
task-b... 0.90.10 Minor bump with digest pin
task-build-image-index 0.20.3 Minor bump; COMMIT_SHA and IMAGE_EXPIRES_AFTER params correctly removed (dropped upstream)
task-s... 0.40.5 Minor bump with digest pin
task-rpms-signature-scan 0.2 (digest only) Digest update, same version tag

Review dimensions

  • Correctness: All five task reference updates are consistently applied to both cli-main-pull-request.yaml and cli-main-push.yaml. The removal of COMMIT_SHA and IMAGE_EXPIRES_AFTER parameters from build-image-index aligns with the upstream v0.3 migration notes which document these parameters as removed. No other parameters or task wiring are affected.
  • Security: All image references remain pinned to full sha256 digests. No new credentials, secrets, RBAC changes, or privilege escalation vectors introduced. All references are sourced from the trusted quay.io/konflux-ci/tekton-catalog/ registry.
  • Intent & coherence: Changes are a well-scoped automated dependency update matching the PR description and Renovate/MintMaker pattern. No unrelated changes included.
  • Style/conventions: YAML formatting is consistent with existing pipeline structure. No structural deviations.
  • Documentation: No documentation updates required for CI configuration reference bumps.
  • Cross-repo contracts: The removed parameters were unused by the task implementation per upstream release notes. No downstream contract breakage.

No findings. This is a clean, well-formed automated dependency update.


Labels: Automated CI/Tekton pipeline dependency update

Previous run (2)

Review

Outcome: approve

Summary

Automated Tekton task bundle dependency update from MintMaker/Renovate (red-hat-konflux[bot]). Updates five task references across both CI pipeline files (.tekton/cli-main-pull-request.yaml and .tekton/cli-main-push.yaml):

Task Version change Notes
task-git-clone-oci-ta 0.1 → 0.2 SSH symlink fix
task-b... 0.9 → 0.10 New RHSM_MOUNT_CA_CERTS param (not used here)
task-build-image-index 0.2 → 0.3 Removes unused COMMIT_SHA & IMAGE_EXPIRES_AFTER params
task-s... 0.4 → 0.5 Migration required
task-rpms-signature-scan 0.2 → 0.2 Digest-only update

Analysis

Correctness — Changes are symmetrically applied to both pipeline files. The removal of COMMIT_SHA and IMAGE_EXPIRES_AFTER parameters from the build-image-index task invocation is correct: the upstream v0.3 changelog confirms these parameters were removed because they were "not used by the task implementation." All remaining parameters (IMAGE, ALWAYS_BUILD_INDEX, IMAGES) are retained. No logic errors or missing parameter adjustments detected.

Security — All bundle references use pinned SHA256 digests (@sha256:...), preventing tag mutability attacks. Images are sourced from the expected quay.io/konflux-ci/tekton-catalog/ registry. No new privileges, permissions, or secret references are introduced.

Intent & coherence — PR is authored by the known red-hat-konflux[bot] automation. Changes are well-scoped to CI pipeline dependency updates. Migration links are provided in the PR body for breaking version changes. The PR body content is informational and contains no instruction injection.

Style & conventions — YAML formatting is consistent with the existing file structure. Bundle reference format follows the established <registry>/<image>:<version>@sha256:<digest> pattern.

Documentation — No documentation updates are required for CI pipeline configuration changes.

No blocking findings.


Labels: PR updates CI pipeline task references

Previous run (3)

Review

Verdict: approve

Summary

This is an automated dependency update PR from the Renovate/MintMaker bot (red-hat-konflux[bot]) that bumps Tekton task bundle references in the two CI pipeline configuration files (.tekton/cli-main-pull-request.yaml and .tekton/cli-main-push.yaml).

Changes analyzed

Version bumps (with migration guides):

  • task-git-clone-oci-ta: 0.1 → 0.2
  • task-b...: 0.9 → 0.10
  • task-build-image-index: 0.2 → 0.3
  • task-s...: 0.4 → 0.5

Digest-only updates (same version):

  • task-apply-tags (0.3), task-clair-scan (0.3), task-clamav-scan (0.3), task-e... (0.2), task-p... (0.3), task-rpms-signature-scan (0.2), task-s... (0.1), task-s... (0.4), task-source-build-oci-ta (0.3)

Parameter removals:
The COMMIT_SHA and IMAGE_EXPIRES_AFTER parameters are removed from the build-image-index task step in both pipeline files. This is correct — the task-build-image-index v0.3 changelog explicitly states these parameters were removed because they were not used by the task implementation.

Review dimensions

Dimension Assessment
Correctness ✅ All task reference updates are consistent across both pipeline files (pull-request and push). The parameter removals align with the upstream task v0.3 migration guide. Both files have identical changes (13 additions, 17 deletions each).
Security ✅ All bundle references use SHA256 digest pinning (@sha256:...), ensuring immutable image references. All images are from the trusted quay.io/konflux-ci/tekton-catalog/ registry.
Intent & coherence ✅ Standard automated CI dependency update. The change is appropriately scoped to pipeline configuration only, with no application code changes.
Style/conventions ✅ YAML formatting is consistent with existing patterns.
Documentation ✅ No documentation changes needed — these are CI configuration updates.

Labels: PR updates CI pipeline task references

Previous run (4)

Looks good to me

Previous run (5)

Looks good to me


Labels: Automated Renovate dependency update to CI pipeline Tekton task references.

Previous run (6)

Looks good to me

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added the ready-for-merge All reviewers approved — ready to merge label Jun 20, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/main branch from 3737ca2 to 16ac154 Compare June 27, 2026 05:34
fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added ready-for-merge All reviewers approved — ready to merge and removed ready-for-merge All reviewers approved — ready to merge labels Jul 11, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/main branch from d10e0e7 to 4605e8d Compare July 18, 2026 06:13
@red-hat-konflux red-hat-konflux Bot changed the title Update Konflux references (main) Update Konflux references (main) (minor) Jul 18, 2026
@github-actions github-actions Bot added size: XS and removed size: S labels Jul 18, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 18, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 6:13 AM UTC · Completed 6:17 AM UTC
Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added ready-for-merge All reviewers approved — ready to merge and removed ready-for-merge All reviewers approved — ready to merge labels Jul 18, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/main branch from 4605e8d to 95f337a Compare July 18, 2026 21:22
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 18, 2026

Copy link
Copy Markdown

🤖 Review · ⚠️ Cancelled · Started 9:22 PM UTC · Ended 9:24 PM UTC
Commit: 87c4a29 · View workflow run →

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/main branch from 95f337a to 1169c26 Compare July 18, 2026 21:23
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 18, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 9:24 PM UTC · Completed 9:28 PM UTC
Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added ready-for-merge All reviewers approved — ready to merge and removed ready-for-merge All reviewers approved — ready to merge labels Jul 18, 2026
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/main branch from 1169c26 to ca22463 Compare July 25, 2026 05:19
@github-actions github-actions Bot added size: M and removed size: XS labels Jul 25, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 25, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 5:20 AM UTC · Completed 5:30 AM UTC
Commit: 87c4a29 · View workflow run →

@simonbaird

Copy link
Copy Markdown
Member

It's been a while, but this is green and looks fine to me. Thanks for your patience @red-hat-konflux.

I did confirm that the three digit tags really exist in acceptable bundles.

@simonbaird
simonbaird merged commit cbfef82 into main Jul 31, 2026
22 checks passed
@simonbaird
simonbaird deleted the konflux/references/main branch July 31, 2026 13:44
@fullsend-ai-retro

fullsend-ai-retro Bot commented Jul 31, 2026

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 1:45 PM UTC · Completed 1:53 PM UTC
Commit: 87c4a29 · View workflow run →

@fullsend-ai-retro

Copy link
Copy Markdown

Retro: PR #3254 — Update Konflux references (main) (minor)

This automated dependency-update PR from red-hat-konflux[bot] (MintMaker/Renovate) updated 14 Tekton task bundle references across two .tekton/ pipeline YAML files. It was open for 104 days (2026-04-18 to 2026-07-31).

Timeline

  1. Apr 18 — PR created by MintMaker bot. Weekly Saturday rebases begin.
  2. Jun 1–3fullsend.yaml shim installed in the repo.
  3. Jun 20 → Jul 25 — Review agent dispatched 8 times (7 successful, 1 cancelled) via pull_request_target: synchronize events triggered by the bot's weekly force-push rebases. Each run produced the same verdict: "Looks good to me."
  4. Jul 31 — Human reviewer simonbaird approved and merged, noting they verified externally that "the three digit tags really exist in acceptable bundles."

Key observations

  • Token waste from repeated reviews: 7 identical approval reviews on effectively the same diff. Each weekly rebase by MintMaker triggers a synchronize event → review dispatch, even though the semantic diff hasn't changed.
  • Human review added real value: The human verified external registry state (that three-digit version tags exist in acceptable bundles) — something the review agent's static analysis cannot replicate.
  • No triage/code/fix agents involved: This was a bot-generated PR with no agent-generated code.

No new proposals — existing issues cover all findings

All improvement areas identified are already well-covered by open issues:

Workflow quality

The review agent's analysis was thorough — it correctly evaluated correctness, security (SHA-pinned image references), intent, style, and cross-repo contracts. The approval verdict was appropriate each time. The problem is purely one of redundant dispatching, not review quality.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci dependencies Pull requests that update a dependency file ready-for-merge All reviewers approved — ready to merge size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant