Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@

## Build

FROM docker.io/library/golang:1.26.3@sha256:2d6c80227255c3112a4d08e67ba98e58efd3846daf15d9d7d4c389565d881b1a AS build
FROM docker.io/library/golang:1.26.5@sha256:2005724102f45917a63e9d092fc0e4ea56ea575048ce147caad5f5f61502c365 AS build

Check failure on line 19 in Dockerfile

View workflow job for this annotation

GitHub Actions / Test

Containerfile version incompatible, saw 1.26.5, running with version: 1.26.3

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[high] protected-path

This PR modifies Dockerfile, which is a protected infrastructure file requiring human approval. The PR has no linked issue authorizing the change. While this is a Renovate-generated Go base image bump (1.26.3 β†’ 1.26.5) with a pinned digest, protected-path changes always require explicit human verification.

Suggested fix: A human maintainer should verify this Renovate-generated Dockerfile change is expected and approve it. Consider linking to the Renovate configuration or an issue that authorizes Dockerfile modifications to streamline future reviews.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[high] protected-path

This PR modifies Dockerfile, a protected infrastructure file. No linked issue provides authorization for changes to protected paths. The change updates the Go build-stage base image from golang:1.26.3 to golang:1.26.5 (patch-level version bump with pinned digest). Human approval is always required for protected-path changes, regardless of change nature.

Suggested fix: A human reviewer must explicitly approve this Dockerfile change.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[high] protected-path

This PR modifies Dockerfile, which is a protected infrastructure file requiring human approval. The PR has no linked issue providing explicit authorization for this change. The change itself is a routine automated Renovate dependency update (golang 1.26.3 β†’ 1.26.5) with a pinned digest, and renovate.json in the repository root configures Renovate for this repository, confirming the update is within the bots configured scope. However, human review and approval is always required for protected-path changes regardless of the changes nature.

Suggested fix: A repository maintainer should review and approve this protected-path change. No code changes are needed β€” this is a governance gate, not a code defect.


ARG TARGETOS
ARG TARGETARCH
Expand Down
Loading