Skip to content

Update Konflux references (release-v0.7) - #3514

Open
red-hat-konflux[bot] wants to merge 1 commit into
release-v0.7from
konflux/references/release-v0.7
Open

Update Konflux references (release-v0.7)#3514
red-hat-konflux[bot] wants to merge 1 commit into
release-v0.7from
konflux/references/release-v0.7

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Aug 22, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
quay.io/konflux-ci/tekton-catalog/task-apply-tags (source, changelog) tekton-bundle digest da0cff22dae3c4
quay.io/konflux-ci/tekton-catalog/task-build-image-index (source, changelog) tekton-bundle digest b00c9e6c2cda69
quay.io/konflux-ci/tekton-catalog/task-buildah-oci-ta (source, changelog) tekton-bundle patch 0.11.00.11.2
quay.io/konflux-ci/tekton-catalog/task-clair-scan (source, changelog) tekton-bundle minor 0.3.20.4.1
quay.io/konflux-ci/tekton-catalog/task-clamav-scan (source, changelog) tekton-bundle patch 0.3.10.3.2
quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks (source, changelog) tekton-bundle digest e438f31b961f8b
quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta (source, changelog) tekton-bundle patch 0.2.50.2.6
quay.io/konflux-ci/tekton-catalog/task-init (source, changelog) tekton-bundle digest 15d3d4a5f68715
quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta (source, changelog) tekton-bundle minor 0.7.10.10.1
quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta (source, changelog) tekton-bundle digest 350a144393b4d0
quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan (source, changelog) tekton-bundle patch 0.2.10.2.2
quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta (source, changelog) tekton-bundle digest d33d800c06bee8
quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta (source, changelog) tekton-bundle digest f4818f897231d2
quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta (source, changelog) tekton-bundle digest f31055c6a7fbfa
quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta (source, changelog) tekton-bundle digest 93f1df16bb2697

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-buildah-oci-ta)

v0.11.2

Fixed
  • Per-arch RPM filtering for the prefetch SBOM.
    • With buildah task versions >= 0.10.0, < 0.11.2, the final SBOM would always
      include the x86_64 RPMs (and no other arches) from the prefetch SBOM,
      even for images built on other arches.
    • Now, the SBOM will contain the RPMs for the corresponding arch.

v0.11.1

Version 0.11.1 only has relevant changes for the remote variants of this task.

konflux-ci/konflux-test-tasks (quay.io/konflux-ci/tekton-catalog/task-clair-scan)

v0.4.1

Changed

Allign script and task version.

v0.4

Changed

Allign script and task version.

konflux-ci/konflux-test-tasks (quay.io/konflux-ci/tekton-catalog/task-clamav-scan)

v0.3.2

Added
  • Skip extracting OCI layers that contain only unscannable model-weight files
    (.safetensors, .gguf, .ggml). Other layers are still extracted and
    scanned. If layer listing fails, the task falls back to extracting the
    full image.
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta)

v0.10.1

Changed
  • When input is empty, only run the skip-ta step and skip other steps
  • Use quay.io/konflux-ci/task-runner for the skip-ta step instead of ubi-minimal

v0.10.0

v0.9.0

Added
  • Added optional pip-index-url parameter to pass PIP_INDEX_URL to Hermeto for pip dependency prefetch.
    When set, this URL is used as a fallback package index when requirements.txt does not specify --index-url.
    To use this parameter, add pip-index-url (type: string, default: "") to your pipeline params
    and pass it to the prefetch-dependencies task.

v0.8.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 05:00 AM and 11:59 PM, only on Saturday (* 5-23 * * 6)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 22, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 6:40 AM UTC · Completed 6:47 AM UTC

Commit: 87c4a29 · View workflow run →

@codecov

codecov Bot commented Aug 22, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Flag Coverage Δ
generative 69.55% <ø> (ø)
integration 69.55% <ø> (ø)
unit 69.55% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 22, 2026

Copy link
Copy Markdown

Review

Findings

High

  • [scope-authorization-mismatch] .tekton/cli-v07-pull-request.yaml:329, .tekton/cli-v07-push.yaml:328 — The PR description (generated by Renovate/MintMaker) claims this is a minor version bump of task-clair-scan from 0.3.2 to 0.4.1. However, the actual diff replaces the clair-scan task entirely with a different scanning tool: task-roxctl-scan:0.1. This is not a version update — it is a tool substitution. The task name changes from clair-scan to roxctl-scan, the taskRef name changes, and the bundle reference switches from task-clair-scan to task-roxctl-scan. The roxctl-scan task is at version 0.1, indicating this is the initial release of a new tool being introduced into the CI pipeline. The same change occurs in both pipeline files.
    Remediation: A human reviewer must verify that the clair-scan to roxctl-scan migration is intentional and approved. If the Konflux platform has deprecated clair-scan in favor of roxctl-scan, the PR description should be updated to accurately describe the tool replacement rather than presenting it as a version bump.

Low

  • [stale-reference] benchmark/offliner/scans.go:90 — The benchmark code filters tasks by the name clair-scan. After the rename to roxctl-scan in v0.7 pipeline definitions, this filter will silently skip the scan task when run against v0.7 pipeline results, producing incomplete benchmark data with no error.
  • [stale-reference] hack/view-clair-reports.sh:39 — The helper script filters for task results where .name=="clair-scan". After the rename to roxctl-scan in v0.7 pipelines, this script will return no results when pointed at v0.7 pipeline runs.

Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR
Previous run

Looks good to me

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added the ready-for-merge All reviewers approved — ready to merge label Aug 22, 2026
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/references/release-v0.7 branch from fb0fb5b to efa77d2 Compare August 29, 2026 07:07
@github-actions github-actions Bot added size: M and removed size: S labels Aug 29, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Aug 29, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 7:08 AM UTC · Completed 7:23 AM UTC

Commit: 87c4a29 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $3.12

@fullsend-ai-review fullsend-ai-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See the review comment for full details.

values:
- "false"
- name: clair-scan
- name: roxctl-scan

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[high] scope-authorization-mismatch

The PR description (generated by Renovate/MintMaker) claims this is a minor version bump of task-clair-scan from 0.3.2 to 0.4.1. However, the actual diff replaces the clair-scan task entirely with a different scanning tool: task-roxctl-scan:0.1. This is not a version update — it is a tool substitution. The task name changes from clair-scan to roxctl-scan, the taskRef name changes, and the bundle reference switches from task-clair-scan to task-roxctl-scan. The roxctl-scan task is at version 0.1, indicating this is the initial release of a new tool being introduced into the CI pipeline. The same change occurs in .tekton/cli-v07-push.yaml.

Suggested fix: A human reviewer must verify that the clair-scan to roxctl-scan migration is intentional and approved. If the Konflux platform has deprecated clair-scan in favor of roxctl-scan, the PR description should be updated to accurately describe the tool replacement.

@fullsend-ai-review fullsend-ai-review Bot removed the ready-for-merge All reviewers approved — ready to merge label Aug 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants