Skip to content

chore(deps): update konflux references - #262

Open
red-hat-konflux-kflux-prd-rh02[bot] wants to merge 1 commit into
release-0.2from
konflux/references/release-0.2
Open

red-hat-konflux-kflux-prd-rh02[bot] wants to merge 1 commit into
release-0.2from
konflux/references/release-0.2

Conversation

@red-hat-konflux-kflux-prd-rh02

@red-hat-konflux-kflux-prd-rh02 red-hat-konflux-kflux-prd-rh02 Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
quay.io/konflux-ci/tekton-catalog/task-build-image-index (source, changelog) tekton-bundle minor 0.3.1 → 0.4
quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta (source, changelog) tekton-bundle patch 0.12.1 → 0.12.3
quay.io/konflux-ci/tekton-catalog/task-clamav-scan (source, changelog) tekton-bundle patch 0.3.3 → 0.3.4
quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks (source, changelog) tekton-bundle digest fa53ef4 → 4390141
quay.io/konflux-ci/tekton-catalog/task-init (source, changelog) tekton-bundle digest c6c414a → 7854d7b
quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta (source, changelog) tekton-bundle digest 3e59d63 → 4c567d1
quay.io/konflux-ci/tekton-catalog/task-roxctl-scan (source, changelog) tekton-bundle digest 97e2b2c → 8286d4d
quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan tekton-bundle digest d9df5d3 → 12239e6
quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta (source, changelog) tekton-bundle patch 0.3.1 → 0.3.2

Release Notes

konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-build-image-index)

v0.4

Added
  • IMAGE_PLATFORM_MAP parameter: optional per-image platform mapping
    (imageRef=os/arch entries) passed to konflux-build-cli as
    --image-platform-map. This sets the platform on each index entry explicitly,
    which is required for OCI artifacts whose empty config carries no platform
    information (e.g. disk images), where the platform would otherwise be null.
    When empty (the default), behaviour is unchanged.
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta)

v0.12.3

Changed
  • All ssh and rsync invocations to the build VM now share a single ssh
    connection. The build step writes an ~/.ssh/config with ControlMaster auto,
    ControlPath and ControlPersist, so only the first invocation pays the cost
    of the TCP handshake, key exchange and authentication.

v0.12.2

Removed
  • Removed the SSH port forwarding from decommissioned JVM Build Service artifact cache
    (JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR) from the remote build. This is just cleanup of unused code.
konflux-ci/konflux-test-tasks (quay.io/konflux-ci/tekton-catalog/task-clamav-scan)

v0.3.4

Added
  • Pre-extract every nested archive into a loose file tree before scanning, so
    clamd scans each file directly instead of recursing through nested archive
    layers. This makes scanning of deeply nested archives faster. Extraction uses
    bsdtar, which detects archives (zip/jar/war/ear/tar
    and tar.gz/tar.bz2/tar.xz) by content rather than extension — important because
    the OCI dir: payload is an extension-less blob — and unpacks them
    unconditionally with no size/count/depth limits. It is defensive: a corrupt or
    partial archive is left in place for clamd rather than aborting the scan. No new
    parameters are introduced. Requires the clamav-db image to ship bsdtar
    (added in konflux-clamav).
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta)

v0.3.2

Fixed
  • Cargo prefetched dependencies are now included in the source image. They are
    vendored as unpacked source trees rather than archives, so previously they
    were missed by the archive-type filter and left out of the source image.

Configuration

📅 Schedule: (in timezone Etc/UTC)

  • Branch creation
    • Between 02:00 AM and 08:59 AM, only on Sunday (* 2-8 * * 0)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@codecov-commenter

codecov-commenter commented Sep 27, 2026 •

Copy link
Copy Markdown

❌ 3 Tests Failed:

Tests completed Failed Passed Skipped
380 3 377 12
View the full list of 3 ❄️ flaky test(s)
::policy 1

Flake rate in main: 100.00% (Passed 0 times, Failed 166 times)

Stack Traces | 0s run time
- test violation 1
- test violation 2
- test violation 3
::policy 4

Flake rate in main: 100.00% (Passed 0 times, Failed 166 times)

Stack Traces | 0s run time
- testing multiple alert violation messages 1
- testing multiple alert violation messages 2
- testing multiple alert violation messages 3
github.com/stackrox/stackrox-mcp/smoke::TestSmoke_RealCluster

Flake rate in main: 9.52% (Passed 38 times, Failed 4 times)

Stack Traces | 360s run time
Failed

To view more test analytics, go to the Test Analytics Dashboard
📋 Got 3 mins? Take this short survey to help us improve Test Analytics.

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

E2E Test Results

Commit: 53abd94
Workflow Run: View Details
Artifacts: Download test results & logs

=== Evaluation Summary ===

  ✓ cve-cluster-does-exist (assertions: 3/3)
  ✓ cve-cluster-list (assertions: 3/3)
  ✓ cve-clusters-general (assertions: 3/3)
  ✓ cve-nonexistent (assertions: 3/3)
  ✗ cve-cluster-does-not-exist (assertions: 3/3)
      one or more verification steps failed
  ✓ rhsa-not-supported (assertions: 2/2)
  ✓ cve-log4shell (assertions: 3/3)
  ✗ cve-multiple (assertions: 3/3)
      one or more verification steps failed
  ✓ list-clusters (assertions: 3/3)
  ✓ cve-detected-clusters (assertions: 3/3)
  ✓ cve-detected-workloads (assertions: 3/3)

Tasks:      9/11 passed (81.82%)
Assertions: 32/32 passed (100.00%)
Tokens:     ~52395 (estimate - excludes system prompt & cache)
MCP schemas: ~12562 (included in token total)
Agent used tokens:
  Input:  11814 tokens
  Output: 20613 tokens
Judge used tokens:
  Input:  79219 tokens
  Output: 60175 tokens

Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com>
@red-hat-konflux-kflux-prd-rh02
red-hat-konflux-kflux-prd-rh02 Bot force-pushed the konflux/references/release-0.2 branch from d9a3b50 to 53abd94 Compare October 4, 2026 04:07
@coderabbitai

coderabbitai Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository YAML (base), Central YAML (inherited), Organization UI (inherited)
  • Review profile: ASSERTIVE
  • Plan: Enterprise
  • Run ID: 9a6e0340-6a82-4996-a9a9-adb4ae4f154c
📥 Commits

Reviewing files that changed from the base of the PR and between a7c5a42 and 53abd94.

📒 Files selected for processing (1)
  • .tekton/basic-component-pipeline.yaml

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.


📝 Summary

Summary by CodeRabbit

  • Chores
    • Updated the versions of several components used in the build and release pipeline, including image-building and security-scanning steps.
    • No changes to user-facing features or behavior.

Walkthrough

The basic component pipeline updates pinned bundle digests for nine tasks. The build-container, build-image-index, and clamav-scan task versions also advance. The pipeline task graph, parameters, and conditions remain unchanged.

Changes

Pipeline bundle updates

Layer / File(s) Summary
Refresh pinned task bundles
.tekton/basic-component-pipeline.yaml
The pipeline updates pinned bundle digests for nine tasks. The build-container, build-image-index, and clamav-scan task versions advance.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Suggested reviewers: mtodor

Merge Risk: ⚪ Minimal · up to 53abd

No concrete issue requiring a change before merge is established by the supplied evidence.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies this as a dependency update for Konflux references, which matches the main changes.
Description check ✅ Passed The description details the updated Tekton bundles, version changes, release notes, and automation settings. It is directly related to the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant