Skip to content

OCM-00000 | ci: Update registry.access.redhat.com/ubi9/go-toolset Docker tag to v1.26.5-1784190466 - #3359

Merged
openshift-merge-bot[bot] merged 1 commit into
masterfrom
konflux/mintmaker/master/registry.access.redhat.com-ubi9-go-toolset-1.x
Jul 29, 2026
Merged

OCM-00000 | ci: Update registry.access.redhat.com/ubi9/go-toolset Docker tag to v1.26.5-1784190466#3359
openshift-merge-bot[bot] merged 1 commit into
masterfrom
konflux/mintmaker/master/registry.access.redhat.com-ubi9-go-toolset-1.x

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
registry.access.redhat.com/ubi9/go-toolset stage patch 1.26.5-17839315151.26.5-1784190466
registry.access.redhat.com/ubi9/go-toolset final patch 1.26.5-17839315151.26.5-1784190466

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux red-hat-konflux Bot added the ok-to-test Indicates a non-member PR verified by an org member that is safe to test. label Jul 9, 2026
@coderabbitai

coderabbitai Bot commented Jul 9, 2026

Copy link
Copy Markdown

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Updated UBI9 Go toolset image references from 1.26.4 to 1.26.5 in the main, e2e, and Konflux Dockerfiles. The e2e Dockerfile also updates the rosa-support builder and final runtime stages.

Suggested reviewers: davidleerh, robpblake

🚥 Pre-merge checks | ✅ 14 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description is Renovate-generated and misses the template sections for summary, issue context, testing, and verification. Rewrite the PR description to match the template, adding PR Summary, issue context, related links, change type, behavior, test steps, proof, and checklist items.
✅ Passed checks (14 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed The PR only bumps go-toolset tags in Dockerfiles; no Ginkgo test titles or test files were changed.
Test Structure And Quality ✅ Passed Only Dockerfiles changed; no Ginkgo test files or test code were modified, so this test-quality check is not applicable.
Microshift Test Compatibility ✅ Passed PR only bumps go-toolset images in Dockerfiles; no Ginkgo e2e tests were added or modified, so MicroShift compatibility isn’t implicated.
Single Node Openshift (Sno) Test Compatibility ✅ Passed Only Dockerfiles changed; no new Ginkgo tests or test logic were added, so the SNO compatibility check is not applicable.
Topology-Aware Scheduling Compatibility ✅ Passed Only Dockerfile base-image tags changed; no manifests, controllers, affinity, selectors, or replica logic were added.
Ote Binary Stdout Contract ✅ Passed PR only bumps go-toolset tags in Dockerfiles; no process-level code or stdout writes were changed.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed PASS: The PR only bumps Dockerfile base image tags; no Ginkgo e2e tests or network logic were added or changed.
No-Weak-Crypto ✅ Passed PR only bumps go-toolset image tags in Dockerfiles; no MD5/SHA1/DES/RC4/3DES/Blowfish, custom crypto, or secret-comparison code was added.
Container-Privileges ✅ Passed Diff only bumps go-toolset tags in 3 Dockerfiles; no privileged, hostPID/Network/IPC, SYS_ADMIN, or allowPrivilegeEscalation changes were introduced.
No-Sensitive-Data-In-Logs ✅ Passed PR only bumps go-toolset image tags in Dockerfiles; no new logging or secret/PII-bearing output was added.
Title check ✅ Passed The title clearly states the main change: bumping the ubi9/go-toolset Docker tag in CI images.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch konflux/mintmaker/master/registry.access.redhat.com-ubi9-go-toolset-1.x

Comment @coderabbitai help to get the list of available commands.

@openshift-ci
openshift-ci Bot requested review from davidleerh and robpblake July 9, 2026 21:55
@openshift-ci

openshift-ci Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

Hi @red-hat-konflux[bot]. Thanks for your PR.

I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@images/Dockerfile.e2e`:
- Around line 22-23: The E2E Dockerfile’s final stage currently uses the build
toolchain image and switches to root, so update the runtime stage to a minimal
supported base (such as UBI minimal or distroless) and copy only the required
artifacts from the builder stage. In the Dockerfile for the E2E image, remove
any build tools from the final image, switch to a non-root user like appuser
before runtime setup, and add a HEALTHCHECK for the running service. Use the
existing multi-stage structure and adjust the final-stage setup around the
Dockerfile’s runtime instructions rather than the build stage.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 5ddceca7-bfa6-4c90-be6a-18faf76ad471

📥 Commits

Reviewing files that changed from the base of the PR and between f89fbbc and fefe012.

📒 Files selected for processing (3)
  • Dockerfile
  • images/Dockerfile.e2e
  • images/Dockerfile.konflux

Comment thread images/Dockerfile.e2e Outdated
Comment on lines 22 to 23
FROM registry.access.redhat.com/ubi9/go-toolset:1.26.4-1783628461
USER root

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift

Use a minimal non-root runtime image for the E2E stage.

The final stage is based on ubi9/go-toolset and explicitly starts as root, retaining build tooling in the runtime image. Please use a supported minimal runtime base, copy only required artifacts, set USER appuser before runtime operations where possible, and add the required HEALTHCHECK.
As per path instructions: “Base image: UBI minimal or distroless,” “Multi-stage builds; no build tools in final image,” “USER non-root; never run as root,” and “HEALTHCHECK defined.”

Also applies to: 39-44

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@images/Dockerfile.e2e` around lines 22 - 23, The E2E Dockerfile’s final stage
currently uses the build toolchain image and switches to root, so update the
runtime stage to a minimal supported base (such as UBI minimal or distroless)
and copy only the required artifacts from the builder stage. In the Dockerfile
for the E2E image, remove any build tools from the final image, switch to a
non-root user like appuser before runtime setup, and add a HEALTHCHECK for the
running service. Use the existing multi-stage structure and adjust the
final-stage setup around the Dockerfile’s runtime instructions rather than the
build stage.

Source: Path instructions

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/master/registry.access.redhat.com-ubi9-go-toolset-1.x branch from fefe012 to fa73203 Compare July 13, 2026 11:43
@red-hat-konflux red-hat-konflux Bot changed the title OCM-00000 | ci: Update registry.access.redhat.com/ubi9/go-toolset Docker tag to v1.26.4-1783628461 OCM-00000 | ci: Update registry.access.redhat.com/ubi9/go-toolset Docker tag to v1.26.5-1783679445 Jul 13, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/master/registry.access.redhat.com-ubi9-go-toolset-1.x branch from fa73203 to b6817f5 Compare July 13, 2026 15:50
@red-hat-konflux red-hat-konflux Bot changed the title OCM-00000 | ci: Update registry.access.redhat.com/ubi9/go-toolset Docker tag to v1.26.5-1783679445 OCM-00000 | ci: Update registry.access.redhat.com/ubi9/go-toolset Docker tag to v1.26.5-1783931515 Jul 13, 2026
@amandahla

Copy link
Copy Markdown
Contributor

/hold

@openshift-ci openshift-ci Bot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Jul 13, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/master/registry.access.redhat.com-ubi9-go-toolset-1.x branch from b6817f5 to 9a2176a Compare July 14, 2026 19:36
@red-hat-konflux red-hat-konflux Bot changed the title OCM-00000 | ci: Update registry.access.redhat.com/ubi9/go-toolset Docker tag to v1.26.5-1783931515 OCM-00000 | ci: Update registry.access.redhat.com/ubi9/go-toolset Docker tag to v1.26.5-1784032128 Jul 14, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/master/registry.access.redhat.com-ubi9-go-toolset-1.x branch from 9a2176a to bdc9b07 Compare July 15, 2026 06:06
@red-hat-konflux red-hat-konflux Bot changed the title OCM-00000 | ci: Update registry.access.redhat.com/ubi9/go-toolset Docker tag to v1.26.5-1784032128 OCM-00000 | ci: Update registry.access.redhat.com/ubi9/go-toolset Docker tag to v1.26.5-1784090680 Jul 15, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/master/registry.access.redhat.com-ubi9-go-toolset-1.x branch from bdc9b07 to 44ed1b9 Compare July 15, 2026 18:28
@red-hat-konflux red-hat-konflux Bot changed the title OCM-00000 | ci: Update registry.access.redhat.com/ubi9/go-toolset Docker tag to v1.26.5-1784090680 OCM-00000 | ci: Update registry.access.redhat.com/ubi9/go-toolset Docker tag to v1.26.5-1784127026 Jul 15, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/master/registry.access.redhat.com-ubi9-go-toolset-1.x branch from 44ed1b9 to 28ef974 Compare July 16, 2026 16:08
@red-hat-konflux red-hat-konflux Bot changed the title OCM-00000 | ci: Update registry.access.redhat.com/ubi9/go-toolset Docker tag to v1.26.5-1784127026 OCM-00000 | ci: Update registry.access.redhat.com/ubi9/go-toolset Docker tag to v1.26.5-1784190466 Jul 16, 2026
@openshift-ci

openshift-ci Bot commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

@red-hat-konflux: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/govulncheck 28ef974 link false /test govulncheck
ci/prow/security 28ef974 link false /test security

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

…ker tag to v1.26.5-1784190466

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/master/registry.access.redhat.com-ubi9-go-toolset-1.x branch from 28ef974 to 3ca87d7 Compare July 16, 2026 20:07
@amandahla

Copy link
Copy Markdown
Contributor

/unhold
/approve
/lgtm

@openshift-ci openshift-ci Bot removed the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Jul 29, 2026
@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Jul 29, 2026
@openshift-ci

openshift-ci Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: amandahla, red-hat-konflux[bot]

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 29, 2026
@openshift-merge-bot
openshift-merge-bot Bot merged commit b82db51 into master Jul 29, 2026
12 of 14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. dco-signoff: yes lgtm Indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant