Update docker image updates to v9.8-1782717933#217
Update docker image updates to v9.8-1782717933#217red-hat-konflux-kflux-prd-rh02[bot] wants to merge 1 commit into
Conversation
Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com>
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Hi @red-hat-konflux-kflux-prd-rh02[bot]. Thanks for your PR. I'm waiting for a openshift-hyperfleet member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
📝 WalkthroughWalkthroughThe Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Supply chain note (CWE-829, CWE-494): Tag-pinned images are not digest-pinned. 🚥 Pre-merge checks | ✅ 11✅ Passed checks (11 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
✨ Simplify code
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@Dockerfile`:
- Line 3: The builder image reference in the Dockerfile is still tag-based and
should be pinned by digest. Update the FROM instruction for the builder stage to
use a digest-pinned image reference instead of
registry.access.redhat.com/ubi9/go-toolset:9.8-1782717933, so the build uses a
fixed immutable image and remains reproducible.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Central YAML (base), Organization UI (inherited)
Review profile: CHILL
Plan: Enterprise
Run ID: 3be6476c-e698-494a-892e-c443af7259fd
📒 Files selected for processing (1)
Dockerfile
🔗 Linked repositories identified
CodeRabbit considers these linked repositories for cross-repo context during reviews:
openshift-hyperfleet/architecture(manual)openshift-hyperfleet/hyperfleet-api(manual) → reviewed against open PR#258konflux/mintmaker/main/docker-image-updatesinstead of the default branchopenshift-hyperfleet/hyperfleet-sentinel(manual) → reviewed against open PR#203konflux/mintmaker/main/docker-image-updatesinstead of the default branchopenshift-hyperfleet/hyperfleet-adapter(manual)openshift-hyperfleet/hyperfleet-broker(manual)
| ARG BASE_IMAGE=registry.access.redhat.com/ubi9-micro:latest | ||
|
|
||
| FROM registry.access.redhat.com/ubi9/go-toolset:9.8-1781757851 AS builder | ||
| FROM registry.access.redhat.com/ubi9/go-toolset:9.8-1782717933 AS builder |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf '\n== Dockerfile ==\n'
cat -n Dockerfile | sed -n '1,40p'
printf '\n== FROM lines ==\n'
rg -n '^FROM\s' Dockerfile
printf '\n== digest references in repo ==\n'
rg -n '`@sha256`:|go-toolset:' -S . || trueRepository: openshift-hyperfleet/hyperfleet-adapter
Length of output: 2022
Dockerfile:3 — Pin the builder image by digest. registry.access.redhat.com/ubi9/go-toolset:9.8-1782717933 is still a mutable tag; use a digest-pinned reference to prevent supply-chain drift and keep the build reproducible (CWE-494, CWE-345).
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@Dockerfile` at line 3, The builder image reference in the Dockerfile is still
tag-based and should be pinned by digest. Update the FROM instruction for the
builder stage to use a digest-pinned image reference instead of
registry.access.redhat.com/ubi9/go-toolset:9.8-1782717933, so the build uses a
fixed immutable image and remains reproducible.
Source: Path instructions
This PR contains the following updates:
9.8-1781757851→9.8-1782717933Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.