-
Notifications
You must be signed in to change notification settings - Fork 60
Update docker.io/library/golang Docker tag to v1.26.6 (main) #3372
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. Weβll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -16,7 +16,7 @@ | |
|
|
||
| ## Build | ||
|
|
||
| FROM docker.io/library/golang:1.26.3@sha256:2d6c80227255c3112a4d08e67ba98e58efd3846daf15d9d7d4c389565d881b1a AS build | ||
| FROM docker.io/library/golang:1.26.6@sha256:0d1d3a794be25f809dd2cb3160d8c73276c4056a9f8242a138e908ddeee7b6b6 AS build | ||
|
|
||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. [low] metadata inconsistency The PR title says 'Update ... to v1.26.4' but the actual diff bumps the image from golang:1.26.3 to golang:1.26.5, skipping 1.26.4 entirely. The PR body mentions '1.26.3 to 1.26.4, Pending: 1.26.5', confirming the title is stale relative to the committed change. This is a cosmetic mismatch typical of Renovate bot rebases but could cause confusion when triaging or auditing dependency updates. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. [low] metadata inconsistency The PR title references v1.26.4, but the actual diff updates the golang image from 1.26.3 to 1.26.5. The PR body lists the change as 1.26.3 β 1.26.4 with 1.26.5 as pending, yet the committed code already uses 1.26.5. This is likely due to Renovate rebasing onto a newer version after the PR was initially created. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. [high] protected-path This PR modifies Dockerfile, which is a protected governance/infrastructure path. The PR has no linked issue providing authorization for the change. Human approval is required for all changes to protected paths. Suggested fix: Ensure a human reviewer approves changes to the Dockerfile. Consider linking to an issue that authorizes this infrastructure change. |
||
| ARG TARGETOS | ||
| ARG TARGETARCH | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
[high] protected-path
This PR modifies
Dockerfile, which is a protected path requiring human approval. The PR has no linked issue providing explicit authorization for modifying governance/infrastructure files. The change itself is a straightforward Renovate-managed Go base image patch bump (1.26.3 β 1.26.6) with a pinned digest, and the diff is mechanically correct. However, protected-path changes always require human review and approval regardless of the change's nature or author.Suggested fix: A human reviewer should verify the Go patch version bump is appropriate and approve the protected-path change.