Skip to content

chore(deps): update integration#3531

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/integration
Open

chore(deps): update integration#3531
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/integration

Conversation

@renovate

@renovate renovate Bot commented May 18, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
quay.io/konflux-ci/konflux-test tekton-step-image patch v1.5.1v1.5.4
quay.io/konflux-ci/tekton-catalog/task-clair-scan digest 8fad4c2f5b4415
quay.io/konflux-ci/tekton-catalog/task-clair-scan digest 627d01dc94302c
quay.io/konflux-ci/tekton-catalog/task-clair-scan-min digest e8d451f59b513e
quay.io/konflux-ci/tekton-catalog/task-clamav-scan digest 567cb6653a0232
quay.io/konflux-ci/tekton-catalog/task-clamav-scan-min digest 908e3569f7f5ca
quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check digest e78d0d30ccc688
quay.io/konflux-ci/tekton-catalog/task-fbc-fips-check digest 8e99503c5fef24
quay.io/konflux-ci/tekton-catalog/task-fbc-fips-check-matrix-based-oci-ta digest 5d84b5e93f38a4
quay.io/konflux-ci/tekton-catalog/task-fbc-fips-check-oci-ta digest e957d03935adb6
quay.io/konflux-ci/tekton-catalog/task-fbc-fips-prepare-oci-ta digest 38cb62fe1b0970
quay.io/konflux-ci/tekton-catalog/task-fips-operator-bundle-check digest 3d51604134ca98
quay.io/konflux-ci/tekton-catalog/task-fips-operator-bundle-check-oci-ta digest 31446fe1d8d734
quay.io/konflux-ci/tekton-catalog/task-run-opm-command-oci-ta digest 7d11704a4865bd
quay.io/konflux-ci/tekton-catalog/task-sast-shell-check digest 2cd09c9b3df8ca
quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta digest c4ef47e5e4586b
quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta-min digest ecfae106b4248a
quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check digest a7ea29573ddc5e
quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check digest 566753c0dd8560
quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta digest bdd187ceba24f5
quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta digest 8f3ecbe8d794f3
quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check digest c162d9dcc79a84
quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta digest 90efa58eb9d539
quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta-min digest 96badf080bf85a
quay.io/konflux-ci/tekton-catalog/task-tpa-scan digest 8375c9e6a204ce
quay.io/konflux-ci/tekton-catalog/task-validate-fbc digest 1775e82855ac0d

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner May 18, 2026 23:55
@renovate
renovate Bot force-pushed the renovate/integration branch 7 times, most recently from 3f762b2 to b11f0c1 Compare May 25, 2026 01:56
@renovate
renovate Bot force-pushed the renovate/integration branch from b11f0c1 to 3de44b2 Compare May 26, 2026 08:47
@renovate
renovate Bot requested a review from sfowl as a code owner May 26, 2026 08:47
@renovate
renovate Bot force-pushed the renovate/integration branch 5 times, most recently from 138784f to a688d96 Compare June 2, 2026 09:56
@renovate renovate Bot changed the title chore(deps): update integration Update integration Jun 2, 2026
@renovate
renovate Bot force-pushed the renovate/integration branch 5 times, most recently from 02fd954 to 6e4472e Compare June 8, 2026 12:00
@renovate
renovate Bot force-pushed the renovate/integration branch from 6e4472e to 78e277a Compare June 16, 2026 01:54
@fullsend-ai-review

fullsend-ai-review Bot commented Jun 16, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 1:55 AM UTC · Completed 2:01 AM UTC
Commit: ffde3b2 · View workflow run →

@fullsend-ai-review

fullsend-ai-review Bot commented Jun 16, 2026

Copy link
Copy Markdown

Looks good to me

Previous run

Looks good to me

Previous run (2)

Looks good to me

Previous run (3)

Looks good to me

Previous run (4)

Looks good to me

Previous run (5)

Review of #3531 — chore(deps): update integration

Verdict: approve

Summary

This is a standard Renovate bot dependency update that bumps container image digest pins across 26 files in the external-task/ and stepactions/ directories. All images are sourced from the project's own registry (quay.io/konflux-ci/).

Changes reviewed

Category Count Details
External task digest updates 25 SHA256 digest-only changes to task_bundle: references
Step action version + digest 1 konflux-test image bumped v1.5.1v1.5.4 with new digest

Analysis

Correctness — All changes are mechanical digest/version pin updates. Version tags (0.1–0.5) are preserved across the update; only the @sha256: portion changes. The konflux-test image receives a patch version bump (v1.5.1 → v1.5.4). All 52 SHA256 digests in the diff (26 old, 26 new) are well-formed 64-character hex strings.

Security — Digest pinning (@sha256:) is a supply chain security best practice — it prevents tag mutation attacks. All images originate from quay.io/konflux-ci/, the project's own container registry. No new image sources or registries are introduced.

Intent & scope — The PR matches the Renovate groupName=integration configuration in CODEOWNERS. All modified paths fall under @konflux-ci/integration-service-maintainers, @konflux-ci/operator-foundry, or @sfowl ownership. The scope is appropriate for a grouped dependency update.

Style/conventions — File format is consistent: each external-task/ YAML contains a single task_bundle: line. The stepaction YAML follows standard Tekton StepAction spec. No structural changes.

Documentation — No documentation updates needed for digest pin changes.

Cross-repo contracts — No API, schema, or interface changes. These are pinned image references consumed internally by Tekton pipelines.

No findings.

Previous run (6)

Review of #3531 — chore(deps): update integration

Verdict: ✅ Approve

Summary

This is an automated dependency update from Renovate that bumps container image digest pins across 26 files. All changes are mechanical — no logic, behavior, or API changes.

Changes:

  • 25 external-task YAML files: SHA256 digest updates for tekton-catalog task bundles (clair-scan, clamav-scan, fbc-fips-check, fips-operator-bundle-check, run-opm-command, sast-shell-check, sast-snyk-check, sast-unicode-check, tpa-scan, validate-fbc — across multiple versions and variants)
  • 1 stepaction YAML (fips-operator-check-step-action): konflux-test image patch bump v1.5.1v1.5.4 with updated SHA256 digest

Analysis

Dimension Assessment
Correctness ✅ Each file changes exactly one image reference line. Tag versions remain consistent with directory paths. No behavioral changes.
Security ✅ All images remain pinned to SHA256 digests from the project's own registry (quay.io/konflux-ci/). Supply chain integrity preserved.
Intent & coherence ✅ Standard Renovate dependency update, well-scoped. Per project rules, automated digest bumps do not require version bumps or changelog entries.
Style & conventions ✅ Follows existing file format conventions throughout.
Documentation ✅ No documentation impacts for digest-only updates.
Cross-repo contracts ✅ No API or schema changes. Task bundle references are consumed internally.

No findings.

Previous run (7)

Review — approve

PR: #3531 — chore(deps): update integration
Author: renovate[bot]
Scope: 26 files — container image digest/version updates only

Summary

This is an automated Renovate dependency update PR that bumps container image references for Tekton task bundles and one step action image. All changes are mechanically identical: updating @sha256: digests (and one minor version tag bump).

Changes breakdown:

  • 25 external-task YAML files: Each updates a single task_bundle: line with a new SHA256 digest. All images are from quay.io/konflux-ci/tekton-catalog/. Tags remain unchanged; only digests rotate.
  • 1 stepaction file (stepactions/fips-operator-check-step-action/0.1/fips-operator-check-step-action.yaml): Updates quay.io/konflux-ci/konflux-test from v1.5.1 to v1.5.4 with a new SHA256 digest. No changes to the step action's script, parameters, results, or security context.

Analysis

Dimension Assessment
Correctness ✅ All changes are syntactically valid image reference updates. Format is consistent (image:tag@sha256:hash). No logic changes.
Security ✅ All images sourced from the organization's own registry (quay.io/konflux-ci/). All pinned by SHA256 digest — the most secure referencing method. No privilege escalations, no new capabilities, no RBAC changes.
Intent & coherence ✅ Standard automated dependency update matching the PR title. Appropriately scoped to image reference updates only. Consistent with the project's Tekton rules which state "Automated image digest bumps do not necessarily require a version bump or changelog entry."
Style/conventions ✅ Follows existing patterns. External-task files maintain single-line task_bundle: format. Step action file maintains existing YAML structure.
Documentation ✅ No documentation updates needed per project convention for automated digest bumps.
Cross-repo contracts ✅ No API, schema, or interface changes. Task parameters and results are unchanged.

No findings at severity low or above.


Labels: Automated dependency digest/version bump for Tekton task bundles

Previous run (8)

Review

Automated dependency update — approve

This is a Renovate-generated PR that updates container image references across 26 files. All changes are mechanical digest/version bumps with no logic, API, or behavioral changes.

Changes reviewed

Category Count Details
Task bundle digest updates 25 files external-task/ — sha256 digest rotations for clair-scan, clamav-scan, fbc-fips-check, fips-operator-bundle-check, run-opm-command, sast-shell-check, sast-snyk-check, sast-unicode-check, tpa-scan, validate-fbc
Step action image bump 1 file stepactions/fips-operator-check-step-action/0.1/konflux-test v1.5.1 → v1.5.3 with updated digest

Verification

  • Image provenance: All images sourced from quay.io/konflux-ci/ (organization-owned registry) ✅
  • Digest pinning: Every image reference uses @sha256: pinning, preventing tag mutation ✅
  • Tag consistency: Tag versions preserved alongside digests where applicable ✅
  • Version bump scope: The only version change (v1.5.1v1.5.3) is a patch-level bump ✅
  • No code/logic changes: Pure reference updates, no functional impact ✅
  • Scope: All changes are within external-task/ and stepactions/ — no pipeline definitions, policies, or test files modified ✅

No findings.

Previous run (9)

Review — ✅ Approve

Summary

This is an automated Renovate dependency update PR (groupName: integration) that updates container image digest references across 26 files. All changes are mechanical and well-formed.

Changes analyzed

Category Count Detail
External task bundle digest updates 25 external-task/*/.../*.yaml — digest-only changes to quay.io/konflux-ci/tekton-catalog/task-* images
Step action image update 1 stepactions/fips-operator-check-step-action/0.1/konflux-test bumped v1.5.1v1.5.3 with new digest

Verification

  • Digest integrity: All 26 new sha256: digests are valid 64-character hex strings
  • Version tag preservation: All task bundle version tags (0.1–0.5) are unchanged between old and new references — only digests rotated
  • Image provenance: All images originate from quay.io/konflux-ci/ (organization's own registry)
  • Renovate config alignment: All changed paths match the integration group in renovate.json
  • Format consistency: Each file's single-line task_bundle: format is preserved; the step action YAML structure is unchanged
  • No logic changes: No code, scripts, parameters, or security contexts were modified
  • Digest pinning maintained: All image references continue to use @sha256: pinning (security best practice)

Dimensions

  • Correctness: No logic to evaluate — pure data substitution. The v1.5.1v1.5.3 patch bump in konflux-test is a minor version update with no structural changes to the step action definition.
  • Security: No new permissions, security contexts, or exposed surfaces. Digest pinning prevents tag-mutability attacks.
  • Intent & coherence: PR title "Update integration" matches the Renovate integration group. Scope is appropriate — one grouped dependency update.
  • Style/conventions: File format and naming conventions are preserved.
  • Documentation: No documentation impact — these are machine-managed reference files.

No findings.


Labels: Automated digest update PR with minimal review effort

Previous run (10)

Review — ✅ Approve

Scope: Automated dependency update (Renovate) — 26 files updating Tekton task bundle digests and one patch version bump.

Summary

This PR updates container image references across 26 files in external-task/ and stepactions/:

  • 25 external-task files: Digest-only updates (@sha256:...) for various Tekton catalog tasks (clair-scan, clamav-scan, fbc-fips-check variants, fips-operator-bundle-check variants, sast-shell-check variants, sast-snyk-check variants, sast-unicode-check variants, tpa-scan, validate-fbc, run-opm-command-oci-ta)
  • 1 stepaction file: fips-operator-check-step-action updates quay.io/konflux-ci/konflux-test from v1.5.1 to v1.5.3 with a new digest

Analysis

Dimension Assessment
Correctness ✅ Mechanical digest swaps only — no logic or behavioral changes
Security ✅ All images from quay.io/konflux-ci/ (org-owned registry); all references use digest pinning for immutable integrity
Intent & coherence ✅ Standard Renovate dependency update, appropriately scoped
Style & conventions ✅ Follows existing single-line task_bundle: pattern for external tasks
Documentation ✅ No documentation impact from digest updates
Cross-repo contracts ✅ Consumption-side updates only; no API or interface changes

No findings. Safe to merge.

Previous run (11)

Looks good to me

Previous run (12)

Looks good to me

Previous run (13)

Looks good to me

Previous run (14)

Looks good to me


Labels: Renovate bot dependency digest/tag updates

Previous run (15)

Looks good to me

Previous run (16)

Looks good to me.

Routine Renovate bot dependency update: 23 external-task bundle digest updates and one stepaction image bump (konflux-test v1.5.1 to v1.5.2). All images are pinned by sha256 digest from the project's own registry (quay.io/konflux-ci/).

Low

  • [naming-convention] external-task/roxctl-scan/0.1/roxctl-scan.yaml:1 — Pre-existing issue (not introduced by this PR): the task_bundle reference contains a duplicated sha256: prefix (@sha256:sha256:...), inconsistent with all other external-task files which use @sha256:<digest>. This malformed reference may cause container runtime resolution failures.
    Remediation: Remove the duplicated sha256: prefix so the line reads ...@sha256:8ffdef72... instead of ...@sha256:sha256:8ffdef72....

Labels: Renovate bot automated dependency digest updates

Previous run (17)

Review

Findings

Info

  • [scope-authorization] renovate.json:75 — No linked issue found for this PR. Scope authorization is inferred from the mechanical nature of the change. This is a Renovate bot automated update affecting the 'integration' group as defined in renovate.json (lines 75-108), which explicitly authorizes updates to the 28 affected file paths. All changes are container image digest/version swaps with no logic modifications.
Previous run (18)

Looks good to me

Previous run (19)

Looks good to me

Previous run (20)

Looks good to me

Previous run (21)

Looks good to me

Previous run (22)

Looks good to me

Previous run (23)

Looks good to me

Previous run (24)

Looks good to me

Previous run (25)

Looks good to me

Previous run (26)

Review

Findings

No findings.

All 20 changed files contain only container image digest and version bumps in Tekton task YAML definitions. No logic, script, permission, or test assertion changes. Images remain properly digest-pinned following the existing image:tag@sha256:digest pattern.

Previous run (27)

Review

Findings

No findings.

Previous run (28)

Review

Findings

No findings.

Previous run (29)

Review

Findings

No findings.

Previous run (30)

Review

Findings

Low

  • [incomplete update] .tekton/tasks/ec-checks.yaml:25 — References quay.io/konflux-ci/task-runner:1.7.0 without digest pinning, while this PR updates task-runner to 1.8.1 elsewhere. However, other .tekton/tasks/ files also reference older task-runner versions (e.g., 1.6.0) and were equally not updated, confirming that .tekton/ files are managed outside this Renovate configuration's scope. No action required for this PR.

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added the ready-for-merge All reviewers approved — ready to merge label Jun 16, 2026
@renovate
renovate Bot force-pushed the renovate/integration branch from 78e277a to 04b22b3 Compare June 16, 2026 09:14
@fullsend-ai-review

fullsend-ai-review Bot commented Jun 16, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 9:16 AM UTC · Completed 9:23 AM UTC
Commit: ffde3b2 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot removed the ready-for-merge All reviewers approved — ready to merge label Jun 16, 2026
fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 3, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 1:28 PM UTC · Completed 1:32 PM UTC
Commit: ec21706 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 7, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 5:48 AM UTC · Completed 5:51 AM UTC
Commit: 14477fe · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

kasemAlem
kasemAlem previously approved these changes Jul 7, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 8, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 1:43 AM UTC · Completed 1:47 AM UTC
Commit: 14477fe · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

kasemAlem
kasemAlem previously approved these changes Jul 8, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 8, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 9:45 AM UTC · Completed 9:48 AM UTC
Commit: 14477fe · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 14, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:52 PM UTC · Completed 3:55 PM UTC
Commit: 14477fe · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 15, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 4:25 PM UTC · Completed 4:29 PM UTC
Commit: 14477fe · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 16, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 5:38 PM UTC · Completed 5:41 PM UTC
Commit: 14477fe · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 20, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:45 PM UTC · Completed 3:52 PM UTC
Commit: 37b10e4 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 21, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 4:36 AM UTC · Completed 4:45 AM UTC
Commit: 37b10e4 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 22, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:32 AM UTC · Completed 3:40 AM UTC
Commit: 37b10e4 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@konflux-ci-qe-bot

Copy link
Copy Markdown

**Scenario: **
@renovate[bot]: The following test has Failed, say /retest to rerun failed tests.

PipelineRun Name Status Rerun command Build Log Test Log
build-definitions-pull-request-pnn7j Failed /retest View Pipeline Log View Test Logs

Inspecting Test Artifacts

To inspect your test artifacts, follow these steps:

  1. Install ORAS (see the ORAS installation guide).
  2. Download artifacts with the following commands:
mkdir -p oras-artifacts
cd oras-artifacts
oras pull quay.io/konflux-test-storage/konflux-team/build-definitions:9e9a977bda7a2efba2b51ce80268d85eabe9dc6b

Test results analysis

🚨 Error occurred while running the E2E tests, list of failed Spec(s):

➡️ [failed] [It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-docker (docker-build) should eventually finish successfully for component with Git source URL https://github.com/konflux-qe-bd/devfile-sample-python-basic-clone and Pipeline docker-build [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]

Click to view logs

Expected success, but got an error:
    <*errors.errorString | 0xc003b5bcb0>: 
    CouldntGetTask: Pipeline build-templates-e2e/test-comp-zpdw-on-pull-request-jgk2d can't be Run; it contains Tasks that don't exist: Couldn't retrieve Task "resolver type bundles\nname = buildah\n": error requesting remote resource: error getting "bundleresolver" "build-templates-e2e/bundles-69257c5e54e771aac5db49ff2681d230": cannot retrieve the oci image: GET https://quay.io/v2/konflux-ci/pull-request-builds/manifests/sha256:9d6f96baefbe19cc6848d5c8612ea41a0f2d8ac52bdb4a686707db15d255ec3d: MANIFEST_UNKNOWN: manifest unknown; map[]
    {
        s: "CouldntGetTask: Pipeline build-templates-e2e/test-comp-zpdw-on-pull-request-jgk2d can't be Run; it contains Tasks that don't exist: Couldn't retrieve Task \"resolver type bundles\\nname = buildah\\n\": error requesting remote resource: error getting \"bundleresolver\" \"build-templates-e2e/bundles-69257c5e54e771aac5db49ff2681d230\": cannot retrieve the oci image: GET https://quay.io/v2/konflux-ci/pull-request-builds/manifests/sha256:9d6f96baefbe19cc6848d5c8612ea41a0f2d8ac52bdb4a686707db15d255ec3d: MANIFEST_UNKNOWN: manifest unknown; map[]",
    }

OCI Artifact Browser URL

<not enabled>

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 22, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 4:51 AM UTC · Completed 4:59 AM UTC
Commit: 37b10e4 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 22, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 11:44 AM UTC · Completed 11:54 AM UTC
Commit: 37b10e4 · View workflow run →

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ready-for-merge All reviewers approved — ready to merge Review effort 2/5

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants