Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@

## Build

FROM docker.io/library/golang:1.26.3@sha256:2d6c80227255c3112a4d08e67ba98e58efd3846daf15d9d7d4c389565d881b1a AS build
FROM docker.io/library/golang:1.26.7@sha256:dc2521c2a906db43073b8b4d99f491b6341cf15610b6ebbab187c45153f9959e AS build

Check failure on line 19 in Dockerfile

View workflow job for this annotation

GitHub Actions / Test

Containerfile version incompatible, saw 1.26.7, running with version: 1.26.3

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[medium] protected-path

This PR modifies Dockerfile, which is a protected path requiring human approval. The change is a Renovate-managed patch bump of the Go build-stage base image (golang:1.26.3 to golang:1.26.7) with a pinned digest. The PR description and labels (renovate, dependencies) provide sufficient context for the change rationale. Human approval is always required for protected-path changes, regardless of context.


Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[low] metadata inconsistency

The PR title says 'Update ... to v1.26.4' but the actual diff bumps the image from golang:1.26.3 to golang:1.26.5, skipping 1.26.4 entirely. The PR body mentions '1.26.3 to 1.26.4, Pending: 1.26.5', confirming the title is stale relative to the committed change. This is a cosmetic mismatch typical of Renovate bot rebases but could cause confusion when triaging or auditing dependency updates.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[low] metadata inconsistency

The PR title references v1.26.4, but the actual diff updates the golang image from 1.26.3 to 1.26.5. The PR body lists the change as 1.26.3 β†’ 1.26.4 with 1.26.5 as pending, yet the committed code already uses 1.26.5. This is likely due to Renovate rebasing onto a newer version after the PR was initially created.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[high] protected-path

This PR modifies Dockerfile, which is a protected governance/infrastructure path. The PR has no linked issue providing authorization for the change. Human approval is required for all changes to protected paths.

Suggested fix: Ensure a human reviewer approves changes to the Dockerfile. Consider linking to an issue that authorizes this infrastructure change.

ARG TARGETOS
ARG TARGETARCH
Expand Down
Loading