Skip to content

Update Konflux references#1586

Open
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/references/main
Open

Update Konflux references#1586
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/references/main

Conversation

@red-hat-konflux
Copy link
Copy Markdown
Contributor

@red-hat-konflux red-hat-konflux Bot commented May 2, 2026

This PR contains the following updates:

Package Change
quay.io/konflux-ci/tekton-catalog/task-build-image-index (source, changelog) 550afdeb33bfa8
quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta (source, changelog) f667d117700725
quay.io/konflux-ci/tekton-catalog/task-clair-scan (source, changelog) cd49cde8fad4c2
quay.io/konflux-ci/tekton-catalog/task-clamav-scan (source, changelog) 171eca5567cb66
quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check (source, changelog) 5ff16b7e78d0d3
quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks (source, changelog) 2468c0188f4fd6
quay.io/konflux-ci/tekton-catalog/task-fbc-fips-check-oci-ta (source, changelog) 54bcb4823c6e30
quay.io/konflux-ci/tekton-catalog/task-fbc-target-index-pruning-check (source, changelog) fcc6f1ba7696d9
quay.io/konflux-ci/tekton-catalog/task-fips-operator-bundle-check-oci-ta (source, changelog) 8970351761ad19
quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta (source, changelog) 13d49dfd30f13d
quay.io/konflux-ci/tekton-catalog/task-init (source, changelog) b797dd45a42324
quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta (source, changelog) 1b209c03dc78af
quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan (source, changelog) ce4bace237c54b
quay.io/konflux-ci/tekton-catalog/task-run-opm-command-oci-ta (source, changelog) c79858b6a7c758
quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta (source, changelog) c4ef47e3cbb353
quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta (source, changelog) 8f3ecbe0ebf28a
quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta (source, changelog) 0854d922238120
quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta (source, changelog) 0917cfc8567bb7
quay.io/konflux-ci/tekton-catalog/task-validate-fbc (source, changelog) 291cbcc1775e82

Configuration

📅 Schedule: Branch creation - Between 05:00 AM and 11:59 PM, only on Saturday ( * 5-23 * * 6 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux red-hat-konflux Bot added approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged. labels May 2, 2026
@openshift-ci openshift-ci Bot requested review from joshuawilson and xrajesh May 2, 2026 08:26
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/references/main branch from a8f78a6 to 01fcaf0 Compare May 2, 2026 16:17
@openshift-ci openshift-ci Bot removed the lgtm Indicates that a PR is ready to be merged. label May 2, 2026
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/references/main branch 2 times, most recently from c2be42e to d28d07d Compare May 16, 2026 08:25
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update konflux references Update Konflux references May 16, 2026
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/references/main branch from d28d07d to 26a58a0 Compare May 23, 2026 08:26
@raptorsun
Copy link
Copy Markdown
Contributor

/lgtm
/retest

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label May 26, 2026
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/references/main branch from 26a58a0 to 940c4b5 Compare May 30, 2026 08:19
@openshift-ci openshift-ci Bot removed the lgtm Indicates that a PR is ready to be merged. label May 30, 2026
@openshift-ci
Copy link
Copy Markdown

openshift-ci Bot commented May 30, 2026

New changes are detected. LGTM label has been removed.

@coderabbitai
Copy link
Copy Markdown

coderabbitai Bot commented May 30, 2026

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 4a6d4f8d-e0a7-4e45-a359-6cd0db2423e6

📥 Commits

Reviewing files that changed from the base of the PR and between 940c4b5 and bc967af.

📒 Files selected for processing (18)
  • .tekton/fbc-v4-16-pull-request.yaml
  • .tekton/fbc-v4-16-push.yaml
  • .tekton/fbc-v4-17-pull-request.yaml
  • .tekton/fbc-v4-17-push.yaml
  • .tekton/fbc-v4-18-pull-request.yaml
  • .tekton/fbc-v4-18-push.yaml
  • .tekton/fbc-v4-19-pull-request.yaml
  • .tekton/fbc-v4-19-push.yaml
  • .tekton/fbc-v4-20-pull-request.yaml
  • .tekton/fbc-v4-20-push.yaml
  • .tekton/fbc-v4-21-pull-request.yaml
  • .tekton/fbc-v4-21-push.yaml
  • .tekton/fbc-v4-22-pull-request.yaml
  • .tekton/fbc-v4-22-push.yaml
  • .tekton/lightspeed-operator-pull-request.yaml
  • .tekton/lightspeed-operator-push.yaml
  • .tekton/ols-bundle-pull-request.yaml
  • .tekton/ols-bundle-push.yaml
✅ Files skipped from review due to trivial changes (1)
  • .tekton/fbc-v4-22-push.yaml
🚧 Files skipped from review as they are similar to previous changes (17)
  • .tekton/fbc-v4-22-pull-request.yaml
  • .tekton/fbc-v4-21-push.yaml
  • .tekton/fbc-v4-20-push.yaml
  • .tekton/fbc-v4-19-pull-request.yaml
  • .tekton/fbc-v4-20-pull-request.yaml
  • .tekton/fbc-v4-19-push.yaml
  • .tekton/fbc-v4-21-pull-request.yaml
  • .tekton/fbc-v4-16-push.yaml
  • .tekton/fbc-v4-18-pull-request.yaml
  • .tekton/fbc-v4-17-pull-request.yaml
  • .tekton/lightspeed-operator-pull-request.yaml
  • .tekton/fbc-v4-17-push.yaml
  • .tekton/ols-bundle-push.yaml
  • .tekton/fbc-v4-16-pull-request.yaml
  • .tekton/fbc-v4-18-push.yaml
  • .tekton/ols-bundle-pull-request.yaml
  • .tekton/lightspeed-operator-push.yaml

📝 Walkthrough

Walkthrough

Adds a new PipelineRun parameter sast-target-dirs (string, default ".") to multiple Tekton manifests, wires it into SAST tasks as TARGET_DIRS, and refreshes pinned taskRef bundle digests across many pipeline tasks. No other task wiring or conditional logic changed.

Changes

Tekton Pipeline SAST Configuration and Task Updates

Layer / File(s) Summary
Pipeline parameter, SAST wiring, and bundle digest refresh
.tekton/*-v4-16-{push,pull-request}.yaml, .tekton/*-v4-17-{push,pull-request}.yaml, .tekton/*-v4-18-{push,pull-request}.yaml, .tekton/*-v4-19-{push,pull-request}.yaml, .tekton/*-v4-20-{push,pull-request}.yaml, .tekton/*-v4-21-{push,pull-request}.yaml, .tekton/*-v4-22-{push,pull-request}.yaml, .tekton/lightspeed-operator-{push,pull-request}.yaml, .tekton/ols-bundle-{push,pull-request}.yaml
Defines sast-target-dirs (string, default .) in multiple PipelineRuns, wires TARGET_DIRS into SAST tasks (sast-shell-check, sast-unicode-check, sast-snyk-check where present), and updates pinned taskRef bundle SHA digests across initialization, git clone, prefetch, build/index/source-build, scanning, and validation tasks.

🎯 2 (Simple) | ⏱️ ~12 minutes

Suggested reviewers

  • joshuawilson
  • xrajesh
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'Update Konflux references' accurately reflects the main change: updating Tekton task bundle references across multiple pipeline files.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch konflux/references/main

Comment @coderabbitai help to get the list of available commands and usage tips.

@openshift-ci
Copy link
Copy Markdown

openshift-ci Bot commented May 30, 2026

[APPROVALNOTIFIER] This PR is APPROVED

Approval requirements bypassed by manually added approval.

This pull-request has been approved by:

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/references/main branch from 940c4b5 to bc967af Compare May 30, 2026 13:07
@openshift-ci
Copy link
Copy Markdown

openshift-ci Bot commented May 30, 2026

@red-hat-konflux[bot]: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant