Skip to content

chore(deps): update konflux references - #3968

Merged
red-hat-konflux[bot] merged 1 commit into
masterfrom
konflux/references/master
Oct 7, 2026
Merged

red-hat-konflux[bot] merged 1 commit into
masterfrom
konflux/references/master

Conversation

@red-hat-konflux

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
quay.io/konflux-ci/tekton-catalog/task-clair-scan (source, changelog) tekton-bundle digest 94b31a5 → 4aaf7b8
quay.io/konflux-ci/tekton-catalog/task-clamav-scan (source, changelog) tekton-bundle digest da31caf → 6fe7e04
quay.io/konflux-ci/tekton-catalog/task-roxctl-scan (source, changelog) tekton-bundle digest 4c40ba4 → e398b9d

Configuration

📅 Schedule: (in timezone Etc/UTC)

  • Branch creation
    • Between 12:00 AM and 07:59 AM (* 0-7 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot requested a review from rhacs-bot as a code owner October 7, 2026 05:07
@red-hat-konflux
red-hat-konflux Bot requested review from a team as code owners October 7, 2026 05:07
@red-hat-konflux
red-hat-konflux Bot enabled auto-merge (squash) October 7, 2026 05:07

@rhacs-bot rhacs-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by automation.

@rhacs-bot rhacs-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by automation.

@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Central YAML (base), Organization UI (inherited)
  • Review profile: CHILL
  • Plan: Enterprise
  • Run ID: 585d79df-b75d-4c02-84a1-1c61667fe27c
📥 Commits

Reviewing files that changed from the base of the PR and between 2a3ca72 and 9267c6b.

📒 Files selected for processing (1)
  • .tekton/scanner-component-pipeline.yaml

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 9 remain after this review.


📝 Summary

Summary by CodeRabbit

  • Chores
    • Updated the components used for automated security scans. The available scan tasks and their behavior remain unchanged.

Walkthrough

The Tekton scanner component pipeline now uses updated pinned bundle digests for roxctl-scan, clair-scan, and clamav-scan. Task names, versions, parameters, and execution conditions are unchanged.

Changes

Scanner task bundle pins

Layer / File(s) Summary
Update scanner task bundle digests
.tekton/scanner-component-pipeline.yaml
The roxctl-scan, clair-scan, and clamav-scan tasks reference new pinned bundle digests. Their versions and configurations are unchanged.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Suggested reviewers: msugakov

Merge Risk: ⚪ Minimal · up to 9267c

The pipeline changes only the pinned scanner bundle digests; no actionable regression is established from the supplied change context, so it is mergeable subject to normal checks.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the dependency update by identifying the Konflux references as the target.
Description check ✅ Passed The description lists the three Tekton bundle digest updates and their old and new values, which match the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@red-hat-konflux
red-hat-konflux Bot merged commit 9c46dea into master Oct 7, 2026
39 of 41 checks passed
@red-hat-konflux
red-hat-konflux Bot deleted the konflux/references/master branch October 7, 2026 05:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant