-
Notifications
You must be signed in to change notification settings - Fork 60
Update docker.io/library/golang Docker tag to v1.26.5 (main) #3372
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. Weβll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -16,7 +16,7 @@ | |
|
|
||
| ## Build | ||
|
|
||
| FROM docker.io/library/golang:1.26.3@sha256:2d6c80227255c3112a4d08e67ba98e58efd3846daf15d9d7d4c389565d881b1a AS build | ||
| FROM docker.io/library/golang:1.26.5@sha256:3aff6657219a4d9c14e27fb1d8976c49c29fddb70ba835014f477e1c70636647 AS build | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. [high] protected-path This PR modifies Dockerfile, which is a protected infrastructure file requiring human approval. The PR has no linked issue providing explicit authorization for this change. While the PR description indicates this is an automated Renovate dependency update (golang 1.26.3 β 1.26.5 with updated digest pin), protected-path changes require issue-level authorization regardless of the change's nature. Suggested fix: A human reviewer should explicitly approve this Dockerfile change. Consider linking a tracking issue that authorizes automated Dockerfile updates via Renovate. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. [high] protected-path Dockerfile is a protected infrastructure path that requires human approval for any modifications. This PR modifies the golang builder image tag and digest (1.26.3 β 1.26.5) but has no linked issue providing explicit authorization for this change. While the change is an automated Renovate dependency update from red-hat-konflux[bot], human review and approval is always required for protected-path changes. Suggested fix: A maintainer should review and approve this Dockerfile change. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. [high] protected-path Dockerfile is a protected path requiring human approval. This PR has no linked issue justifying the modification of governance/infrastructure files. While the change is a mechanical golang version bump (1.26.3 β 1.26.5) managed by Renovate/MintMaker, protected-path changes always require explicit human review regardless of the change nature. Suggested fix: A maintainer should review and approve this Dockerfile change. Consider linking a tracking issue or policy document that authorizes automated Dockerfile updates via Renovate. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. [high] protected-path Dockerfile is a protected governance/infrastructure file that always requires human approval. This PR modifies it but has no linked issue providing authorization for the change. The change is a routine Renovate patch bump of the Go build image (golang:1.26.3 β golang:1.26.5 with pinned sha256 digest), which is low-risk, but protected-path policy requires explicit human sign-off regardless of change nature. Suggested fix: A human maintainer should review and approve this Dockerfile change. Consider linking a tracking issue or policy that authorizes automated Dockerfile updates to streamline future Renovate PRs. |
||
|
|
||
| ARG TARGETOS | ||
| ARG TARGETARCH | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
[high] protected-path
This PR modifies Dockerfile, which is a protected path requiring human approval. The PR has no linked issue providing explicit authorization for changes to governance/infrastructure files. While the change is an automated Renovate dependency bump (golang 1.26.3 β 1.26.5 with pinned digest), human approval is always required for protected-path modifications.
Suggested fix: A human reviewer should approve this change directly. If this is a routine dependency update authorized by the repository's renovate.json configuration, a maintainer can approve without a linked issue.