Update docker.io/library/golang Docker tag to v1.26.8 (main) - #3372
Update docker.io/library/golang Docker tag to v1.26.8 (main)#3372red-hat-konflux[bot] wants to merge 1 commit into
Conversation
|
🤖 Finished Review · ✅ Success · Started 1:08 AM UTC · Completed 1:15 AM UTC |
ReviewFindingsHigh
Info
Next steps:
Previous runReviewFindingsHigh
Next steps:
Previous run (2)ReviewFindingsMedium
Previous run (3)ReviewFindingsHigh
Next steps:
Previous run (4)ReviewFindingsMedium
Previous run (5)ReviewFindingsHigh
Next steps:
Previous run (6)ReviewFindingsHigh
Next steps:
Previous run (7)ReviewFindingsHigh
Next steps:
Previous run (8)ReviewFindingsHigh
Next steps:
Previous run (9)ReviewFindingsHigh
Next steps:
Previous run (10)ReviewFindingsHigh
Next steps:
Previous run (11)ReviewFindingsHigh
Low
Next steps:
Previous run (12)ReviewFindingsHigh
Low
Next steps:
Previous run (13)ReviewFindingsHigh
Low
Next steps:
Previous run (14)ReviewFindingsHigh
Low
Next steps:
Previous run (15)ReviewFindingsMedium
Previous run (16)ReviewFindingsHigh
Next steps:
Previous run (17)ReviewFindingsHigh
Next steps:
Previous run (18)ReviewFindingsHigh
Next steps:
Previous run (19)ReviewFindingsHigh
Next steps:
Previous run (20)ReviewFindingsHigh
Next steps:
Previous run (21)ReviewFindingsHigh
Previous run (22)ReviewFindingsHigh
Previous run (23)Looks good to me — routine Golang base image patch bump (
Previous run (24)ReviewNo substantive findings. The Golang builder image bump from 1.26.3 to 1.26.5 with pinned digest is a routine dependency update.
Previous run (25)ReviewFindingsHigh
Previous run (26)ReviewFindingsHigh
Previous run (27)Looks good to me
Previous run (28)ReviewFindingsHigh
Previous run (29)Review — Approve ✅Patch version bump of the Go Docker base image ( SummaryThis is a mechanical, Renovate-generated dependency update that bumps the Go builder image by two patch versions. The change is a single-line tag swap with no behavioral, API, or architectural impact. Correctness: No logic, edge-case, or build risks introduced. The Security: No secrets, permissions, workflows, or auth-related files are modified. The mutable-tag pattern ( Intent & coherence: Automated patch maintenance by Renovate bot — authorization is implicit in the mechanical nature of the change and the project's configured auto-merge policy. Style & conventions: The new value follows the identical Documentation: No user-facing documentation references the specific Go builder image version. No staleness introduced. No findings above the severity threshold.
Previous run (30)Review — ✅ ApprovePR: #3372 — Update docker.io/library/golang Docker tag to v1.26.4 (main) SummaryRoutine patch version bump of the Go build base image in the Dockerfile from Analysis
FindingsNo findings.
Previous run (31)Review — ✅ ApproveScope: Automated patch version bump of Go Docker base image ( SummaryThis is a single-line, automated Renovate/MintMaker dependency update that bumps the Go compiler Docker image tag from Analysis
No findings above the severity threshold.
Previous run (32)Review — ✅ ApproveScope: Automated patch version bump of the Analysis
Notes
No findings. Safe to merge.
Previous run (33)Review of #3372 — Update docker.io/library/golang Docker tag to v1.26.5Verdict: ✅ Approve SummaryThis is an automated patch version bump of the Go Docker build image from Dimensions reviewed
Notes
Previous run (34)ReviewOutcome: Approve This PR is an automated Renovate/MintMaker dependency update that bumps the Go build image in Dimensions evaluated
No findings at or above the reporting threshold.
Previous run (35)ReviewOutcome: Approve SummaryMechanical patch-version bump of the Go build image from Findings
Dimensions evaluated
Labels: PR already has appropriate labels (dependencies, docker, renovate); adding go label since this is a Go compiler version bump. Previous run (36)Review of #3372 — Update docker.io/library/golang Docker tag to v1.26.4Verdict: Approve ✅ SummaryThis is a routine Renovate-automated patch version bump of the Go build image in Analysis
No findings.
Previous run (37)Review — #3372Verdict: ✅ Approve SummaryThis is a single-line, automated patch version bump of the Go build image in Dimension Results
Low-severity Observations
Previous run (38)ReviewFindingsHigh
Previous run (39)ReviewFindingsMedium
Labels: PR modifies the Dockerfile to bump a dependency version. |
93943cb to
48696b2
Compare
|
🤖 Finished Review · ✅ Success · Started 1:39 AM UTC · Completed 1:44 AM UTC |
9bcbd75 to
76d8bf9
Compare
|
🤖 Finished Review · ✅ Success · Started 1:49 AM UTC · Completed 1:54 AM UTC |
76d8bf9 to
275f5f9
Compare
|
🤖 Finished Review · ✅ Success · Started 1:39 AM UTC · Completed 1:42 AM UTC |
275f5f9 to
224bb6b
Compare
|
🤖 Finished Review · ✅ Success · Started 1:33 AM UTC · Completed 1:38 AM UTC |
|
🤖 Finished Review · ✅ Success · Started 2:58 AM UTC · Completed 3:07 AM UTC Commit: |
|
🤖 Finished Review · ✅ Success · Started 1:03 AM UTC · Completed 1:11 AM UTC Commit: |
|
🤖 Finished Review · ✅ Success · Started 2:51 AM UTC · Completed 2:58 AM UTC Commit: |
|
🤖 Finished Review · ✅ Success · Started 1:58 AM UTC · Completed 2:05 AM UTC Commit: |
|
🤖 Finished Review · ✅ Success · Started 2:03 AM UTC · Completed 2:10 AM UTC Commit: |
|
🤖 Finished Review · ✅ Success · Started 3:21 AM UTC · Completed 3:30 AM UTC Commit: |
|
🤖 Finished Review · ✅ Success · Started 1:06 AM UTC · Completed 1:13 AM UTC Commit: |
|
🤖 Finished Review · ✅ Success · Started 2:35 AM UTC · Completed 2:44 AM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.70 |
|
🤖 Finished Review · ✅ Success · Started 2:32 AM UTC · Completed 2:39 AM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.36 |
|
🤖 Finished Review · ✅ Success · Started 2:43 AM UTC · Completed 2:50 AM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.59 |
|
🤖 Finished Review · ✅ Success · Started 2:03 AM UTC · Completed 2:10 AM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.65 |
|
🤖 Review · Commit: |
|
🤖 Finished Review · ✅ Success · Started 2:17 AM UTC · Completed 2:27 AM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.68 |
|
Risk Assessment: low (1/5) DetailsTrivial automated Renovate patch bump of the golang base image (1.26.7 to 1.26.8) with re-pinned digest, touching only the FROM directive. Previous runRisk Assessment: moderate (2/5) DetailsBot-authored single-file Dockerfile update bumping the Go Docker tag. Minimal change size (1 file, 2 lines, small blast radius). Dockerfile is a protected path (score 3) and counts as CI workflow change (score 4), which elevate Tier 1 slightly. No security-sensitive files, no dependency file changes, no test files expected for config-only change. Git history shows moderate churn (4 commits/30d) and multiple authors (4/90d) on this file, with one recent fix commit. Composite: 0.62×1.63 + 0.38×1.67 = 1.64, rounds to 2 (moderate). |
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
|
🤖 Finished Review · ✅ Success · Started 3:55 AM UTC · Completed 4:01 AM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $2.04 |
| ## Build | ||
|
|
||
| FROM docker.io/library/golang:1.26.7@sha256:e30143be198ab04cf7ba25fba83ab3a692ca584c994aad0bf131fa0eb32dd8c1 AS build | ||
| FROM docker.io/library/golang:1.26.8@sha256:9d2f36f06329b2a141b9db99ffa32765cf695ee57b813ca29e245e8670bcbfff AS build |
There was a problem hiding this comment.
[high] protected-path
This PR modifies Dockerfile, which is on the repository's protected paths list (REVIEW_PROTECTED_PATHS). The change is a Renovate/MintMaker automated golang base-image patch bump (1.26.7 to 1.26.8) with the image digest re-pinned, but the PR has no linked issue explicitly authorizing modification of governance or infrastructure files. Per the protected-path policy, human approval is required.
Suggested fix: Link a tracking issue or repository policy document that authorizes automated Docker base-image bumps to modify Dockerfile, or defer to human maintainer review before merge.
This PR contains the following updates:
1.26.7→1.26.8Configuration
📅 Schedule: (UTC)
* 0-3 * * *)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.