Update docker image updates to v9.8-1784190466#257
Update docker image updates to v9.8-1784190466#257red-hat-konflux-kflux-prd-rh02[bot] wants to merge 1 commit into
Conversation
Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com>
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
📝 WalkthroughWalkthroughThe Dockerfile builder stage image tag changed from Estimated code review effort: 1 (Trivial) | ~2 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 11✅ Passed checks (11 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
✨ Simplify code
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@Dockerfile`:
- Line 3: Update the Dockerfile builder image reference in the FROM instruction
to include the exact immutable manifest digest for
registry.access.redhat.com/ubi9/go-toolset:9.8-1784190466, preserving the
existing builder stage.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Central YAML (base), Organization UI (inherited)
Review profile: CHILL
Plan: Enterprise
Run ID: 77e7ca0c-b5e0-47b5-ac92-2ed9351b5c5b
📒 Files selected for processing (1)
Dockerfile
🔗 Linked repositories identified
CodeRabbit considers these linked repositories for cross-repo context during reviews:
openshift-hyperfleet/architecture(manual)openshift-hyperfleet/hyperfleet-api(manual)openshift-hyperfleet/hyperfleet-sentinel(manual)openshift-hyperfleet/hyperfleet-adapter(manual)openshift-hyperfleet/hyperfleet-broker(manual)
| ARG BASE_IMAGE=registry.access.redhat.com/ubi9-micro:latest | ||
|
|
||
| FROM registry.access.redhat.com/ubi9/go-toolset:9.8-1783931515 AS builder | ||
| FROM registry.access.redhat.com/ubi9/go-toolset:9.8-1784190466 AS builder |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
image='registry.access.redhat.com/ubi9/go-toolset:9.8-1784190466'
digest="$(skopeo inspect --format '{{.Digest}}' "docker://${image}")"
test -n "${digest}"
printf '%s\n' "${digest}"Repository: openshift-hyperfleet/hyperfleet-adapter
Length of output: 221
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo '--- Dockerfile ---'
cat -n Dockerfile | sed -n '1,40p'
echo
echo '--- digest pins in Dockerfile ---'
rg -n '`@sha256`:|FROM .*:' Dockerfile || trueRepository: openshift-hyperfleet/hyperfleet-adapter
Length of output: 1811
🏁 Script executed (no clone):
#!/bin/bash
set -euo pipefail
image='registry.access.redhat.com/ubi9/go-toolset:9.8-1784190466'
# Try the registry v2 manifest endpoint and print only the Docker-Content-Digest header.
# This is read-only and avoids depending on skopeo.
tmp_headers="$(mktemp)"
trap 'rm -f "$tmp_headers"' EXIT
curl -fsSI \
-H 'Accept: application/vnd.docker.distribution.manifest.list.v2+json, application/vnd.oci.image.index.v1+json, application/vnd.docker.distribution.manifest.v2+json, application/vnd.oci.image.manifest.v1+json' \
"https://${image%%:*}/v2/${image#*/}/manifests/${image##*:}" \
-D "$tmp_headers" >/dev/null || true
sed -n '/^Docker-Content-Digest:/p;/^HTTP\//p;/^WWW-Authenticate:/p' "$tmp_headers"
Length of output: 215
🏁 Script executed:
#!/bin/bash
set -euo pipefail
# Search for any other FROM lines or image pinning patterns in the repository.
rg -n 'FROM\s+.*(`@sha256`:|:[^[:space:]]+)' -g 'Dockerfile*' -g 'Containerfile*' . || trueRepository: openshift-hyperfleet/hyperfleet-adapter
Length of output: 351
Pin the builder image by digest Dockerfile:3 — registry.access.redhat.com/ubi9/go-toolset:9.8-1784190466 is still mutable. Use the manifest digest instead to avoid supply-chain drift (CWE-494).
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@Dockerfile` at line 3, Update the Dockerfile builder image reference in the
FROM instruction to include the exact immutable manifest digest for
registry.access.redhat.com/ubi9/go-toolset:9.8-1784190466, preserving the
existing builder stage.
Source: Path instructions
Risk Score: 0 —
|
| Signal | Detail | Points |
|---|---|---|
| PR size | 2 lines | +0 |
| Sensitive paths | none | +0 |
Computed by hyperfleet-risk-scorer
This PR contains the following updates:
9.8-1783931515→9.8-1784190466Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.