Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@

## Build

FROM docker.io/library/golang:1.26.3@sha256:2d6c80227255c3112a4d08e67ba98e58efd3846daf15d9d7d4c389565d881b1a AS build
FROM docker.io/library/golang:1.26.5@sha256:3aff6657219a4d9c14e27fb1d8976c49c29fddb70ba835014f477e1c70636647 AS build

Check failure on line 19 in Dockerfile

View workflow job for this annotation

GitHub Actions / Test

Containerfile version incompatible, saw 1.26.5, running with version: 1.26.3

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[high] protected-path

This PR modifies Dockerfile, which is a protected path requiring human approval. The PR has no linked issue providing explicit authorization for changes to governance/infrastructure files. While the change is an automated Renovate dependency bump (golang 1.26.3 β†’ 1.26.5 with pinned digest), human approval is always required for protected-path modifications.

Suggested fix: A human reviewer should approve this change directly. If this is a routine dependency update authorized by the repository's renovate.json configuration, a maintainer can approve without a linked issue.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[high] protected-path

This PR modifies Dockerfile, which is a protected infrastructure file requiring human approval. The PR has no linked issue providing explicit authorization for this change. While the PR description indicates this is an automated Renovate dependency update (golang 1.26.3 β†’ 1.26.5 with updated digest pin), protected-path changes require issue-level authorization regardless of the change's nature.

Suggested fix: A human reviewer should explicitly approve this Dockerfile change. Consider linking a tracking issue that authorizes automated Dockerfile updates via Renovate.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[high] protected-path

Dockerfile is a protected infrastructure path that requires human approval for any modifications. This PR modifies the golang builder image tag and digest (1.26.3 β†’ 1.26.5) but has no linked issue providing explicit authorization for this change. While the change is an automated Renovate dependency update from red-hat-konflux[bot], human review and approval is always required for protected-path changes.

Suggested fix: A maintainer should review and approve this Dockerfile change.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[high] protected-path

Dockerfile is a protected path requiring human approval. This PR has no linked issue justifying the modification of governance/infrastructure files. While the change is a mechanical golang version bump (1.26.3 β†’ 1.26.5) managed by Renovate/MintMaker, protected-path changes always require explicit human review regardless of the change nature.

Suggested fix: A maintainer should review and approve this Dockerfile change. Consider linking a tracking issue or policy document that authorizes automated Dockerfile updates via Renovate.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[high] protected-path

Dockerfile is a protected governance/infrastructure file that always requires human approval. This PR modifies it but has no linked issue providing authorization for the change. The change is a routine Renovate patch bump of the Go build image (golang:1.26.3 β†’ golang:1.26.5 with pinned sha256 digest), which is low-risk, but protected-path policy requires explicit human sign-off regardless of change nature.

Suggested fix: A human maintainer should review and approve this Dockerfile change. Consider linking a tracking issue or policy that authorizes automated Dockerfile updates to streamline future Renovate PRs.


ARG TARGETOS
ARG TARGETARCH
Expand Down
Loading