Skip to content

Update Konflux references#256

Open
red-hat-konflux-kflux-prd-rh02[bot] wants to merge 1 commit into
mainfrom
konflux/references/main
Open

Update Konflux references#256
red-hat-konflux-kflux-prd-rh02[bot] wants to merge 1 commit into
mainfrom
konflux/references/main

Conversation

@red-hat-konflux-kflux-prd-rh02

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change
quay.io/konflux-ci/tekton-catalog/task-apply-tags (source, changelog) 3ab84416387614
quay.io/konflux-ci/tekton-catalog/task-build-helm-chart-oci-ta (source, changelog) dcc40cc1de9b1c
quay.io/konflux-ci/tekton-catalog/task-buildah-oci-ta (source, changelog) 62de839daa9a28
quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan (source, changelog) 9ad20a02e79e47
quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta (source, changelog) 7c5575a2dd5b3e

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 05:00 AM and 11:59 PM, only on Saturday (* 5-23 * * 6)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com>
@openshift-ci
openshift-ci Bot requested review from rafabene and sherine-k July 18, 2026 08:02
@openshift-ci

openshift-ci Bot commented Jul 18, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign rafabene for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@coderabbitai

coderabbitai Bot commented Jul 18, 2026

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

Updated pinned Tekton task bundle digests in the chart-push, push, and tag PipelineRuns. The changes cover chart building, container building, source image building, tag application, and RPM signature scanning. Pipeline parameters, task wiring, conditions, and workspace configuration remain unchanged.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Suggested reviewers: ciaranroche

🚥 Pre-merge checks | ✅ 11
✅ Passed checks (11 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Sec-02: Secrets In Log Output ✅ Passed PASS: Diff only updates Tekton bundle digests in YAML; no new slog/logr/zap/fmt.Print* calls or token/password/credential/secret fields in touched files (CWE-532).
No Hardcoded Secrets ✅ Passed PASS: Added lines are only Tekton OCI bundle digest pins; no API key/token/password literals, embedded credentials, or suspicious base64 were added (CWE-798).
No Weak Cryptography ✅ Passed Only Tekton bundle digests changed; no banned primitives, custom crypto, or weak secret/HMAC comparisons in the touched files. CWE-327/CWE-328 not triggered.
No Injection Vectors ✅ Passed Only Tekton bundle digest pins changed; no new SQL, exec.Command, template.HTML, or yaml.Unmarshal sinks were introduced (CWE-89/78/79/502).
No Privileged Containers ✅ Passed PASS: The diff only updates Tekton bundle digests; no privileged:true, host* flags, allowPrivilegeEscalation, SYS_ADMIN, or runAsUser:0 appear in the changed manifests.
No Pii Or Sensitive Data In Logs ✅ Passed No new logging statements; only Tekton bundle digest pins changed, so no CWE-532 log exposure path was introduced.
Title check ✅ Passed The title accurately reflects the change: updating Konflux/Tekton references.
Description check ✅ Passed The description matches the changeset and lists the updated Tekton task references.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch konflux/references/main
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch konflux/references/main

Comment @coderabbitai help to get the list of available commands.

@hyperfleet-ci-bot

Copy link
Copy Markdown

Risk Score: 0 — risk/low

Signal Detail Points
PR size 18 lines +0
Sensitive paths none +0

Computed by hyperfleet-risk-scorer

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants