Skip to content

Update docker.io/library/golang Docker tag to v1.27.1 (main) - #3512

Open
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main-main/docker.io-library-golang-1.x
Open

red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main-main/docker.io-library-golang-1.x

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
docker.io/library/golang stage minor 1.26.71.27.1

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 20, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 2:45 AM UTC · Completed 2:52 AM UTC

Commit: 87c4a29 · View workflow run →

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 20, 2026

Copy link
Copy Markdown

Review

Findings

Medium

  • [protected-path] Dockerfile — This PR is a Renovate-managed golang base image tag bump (1.26.71.27.1) touching Dockerfile, which is on the protected-paths list. The change itself is mechanical and well-formed (valid sha256: digest, format matches surrounding context, trusted automated author red-hat-konflux[bot] acting through the renovate.json policy). Regardless of authorization context, human approval is always required for protected-path changes.
    Remediation: Human reviewer confirms the golang 1.27.1 bump is acceptable. Related manifests (go.mod, .tool-versions, Dockerfile.dist) remain on 1.26.7 and will be updated by separate Renovate PRs on their own cadence — the inconsistency with those files is expected Renovate behavior, not a defect of this PR.

No correctness, security, style, or documentation findings above the configured severity threshold.

Previous run

Review

Findings

Info

  • [protected-path] Dockerfile — This PR modifies a protected path (Dockerfile). Human approval is always required for protected-path changes, regardless of context. Note: intent-coherence identifies this as a mechanical Renovate bot dependency bump (golang 1.26.7 → 1.27.1), and the repo's renovate.json authorizes automated dependency bumps.
  • [scope-authorization-implicit] N/A — Authorization inferred from mechanical nature of change (Docker base image version/digest bump by Renovate bot). No architectural review required.
  • [provenance-warning] N/A — Prior review context discarded: provenance validation failed (unverifiable-wrong-app). This review treats all findings as first-time assessments; severity anchoring was skipped for this run.
Previous run (2)

Review

Reason: stale-head

The review agent reviewed commit a65a109ba5e1605c4e42ed419edcee2d14f33b90 but the PR HEAD is now 64d307409d15bab965337b0e0d6cae151b152e10. This review was discarded to avoid approving unreviewed code.

Previous run (3)

Review

Findings

Medium

  • [protected-path] Dockerfile — This PR modifies Dockerfile, which is on the repository's protected-paths list. Human approval is always required for changes to governance and infrastructure files, regardless of context. The change is a Renovate/MintMaker automated base image bump (docker.io/library/golang:1.26.71.27.1) with a matching pinned sha256 digest, and the repository's renovate.json authorizes this bot's dependency-update pattern; that authorization does not remove the human-approval requirement for protected paths.

Info

  • [provenance-warning] — Prior review context discarded: provenance validation failed (PRIOR_REVIEW_PROVENANCE=unverifiable-wrong-app). This review treats all findings as first-time assessments and severity anchoring was skipped for this run.
Previous run (4)

Review

Mechanical Renovate-bot Docker tag bump: docker.io/library/golang:1.26.7
1.27.1 (build stage only), with an updated pinned SHA256 digest. No
functional bugs, security issues, style problems, or intent/coherence
concerns identified. The multi-stage runtime image
(registry.access.redhat.com/ubi9/ubi-minimal) is unchanged.

Not approving because Dockerfile is a governance-protected path — human
review is required by policy regardless of how mechanical the change is.

Findings

Info

  • [protected-path] Dockerfile — This PR modifies a governance-protected
    path (Dockerfile is in REVIEW_PROTECTED_PATHS). No issue is linked, so
    under the strict rule this would be raised as high severity, but the
    intent-coherence finding cites the mechanical value-only nature of the
    change as implicit authorization, and the repository's renovate.json
    extends the org-wide Renovate config that authorizes exactly this class
    of dependency update. Severity downgraded to info via orchestrator
    reconciliation. Human approval is still required for protected-path
    changes — this note exists so reviewers understand what is being
    changed and why.
  • [scope-authorization-implicit] Authorization inferred from the
    mechanical nature of the change (value-only / digest bump). No
    architectural review required.
  • [sub-agent-failure] The challenger sub-agent returned an empty
    adjudicated_findings array (it argued the single info finding was a
    non-actionable meta-note). Per the orchestrator's guard against empty
    challenger results, the pre-challenger finding set was preserved.
  • [provenance-warning] Prior review context was discarded because
    provenance validation failed (PRIOR_REVIEW_PROVENANCE=unverifiable-wrong-app
    — the prior comment was created by a different app than expected). This
    review treats all findings as first-time assessments; severity anchoring
    was skipped for this run.
Previous run (5)

Review

Findings

Medium

  • [protected-path] Dockerfile — This PR modifies Dockerfile, which is listed in this repository's REVIEW_PROTECTED_PATHS (governance / infrastructure). The PR body and this repo's renovate.json (extending github>conforma/.github//config/renovate/renovate.json) supply sufficient context: this is a value-only Renovate base-image bump. Human approval is nevertheless required for any protected-path change, regardless of context.
    Remediation: A human reviewer must approve. Before merge, confirm the new digest sha256:512690a5660563b57d37ecc31129e7f136e831db2aed24a1dbeb8ad7380dc0fa corresponds to docker.io/library/golang:1.27.1 on Docker Hub (Renovate is authoritative for the tag→digest pair; the pin remains the source of trust for the build).

Info

  • [scope-authorization-implicit] — Authorization inferred from the mechanical nature of the change (value-only dependency version bump by the Renovate bot). No architectural review required.
  • [provenance-warning] — Prior review context was discarded: provenance validation returned unverifiable-wrong-app (a prior review comment exists but was created by a different app than expected). This review treats all findings as first-time assessments; severity anchoring was skipped for this run.
Previous run (6)

Review

Findings

High

  • [protected-path] Dockerfile:19 — This PR modifies Dockerfile, which is under protected paths. The PR has no linked issue providing explicit authorization for this change. While this appears to be a routine renovate bot dependency update (golang 1.26.3 → 1.27.0 with pinned digest), human approval is always required for changes to protected governance and infrastructure files.
    Remediation: Obtain human reviewer approval for this protected-path change.

Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR
Previous run (7)

Review

Findings

High

  • [protected-path] Dockerfile:19 — This PR modifies Dockerfile, which is under a protected path requiring human approval. The PR has no linked issue providing authorization for the change. While the Renovate bot description explains this is a golang base image update from 1.26.3 to 1.27.0, protected-path changes require explicit issue-based authorization.
    Remediation: Link an issue authorizing the Dockerfile change, or obtain explicit human approval for this dependency update.

Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR
Previous run (8)

Review

Findings

High

  • [protected-path] Dockerfile — This PR modifies Dockerfile, which is a protected governance/infrastructure file requiring human approval. The PR has no linked issue providing authorization or justification for the change. While this is an automated Renovate dependency update (golang 1.26.3 → 1.27.0), protected-path changes always require explicit human review regardless of the change mechanism.
    Remediation: A human maintainer must review and approve changes to protected files. No automated approval is permitted for governance/infrastructure paths.

Labels: PR modifies Dockerfile with a dependency version update


Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added docker Pull requests that update Docker code dependencies Pull requests that update a dependency file labels Aug 20, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/docker.io-library-golang-1.x branch from 4f499f8 to b635f4b Compare August 20, 2026 02:55
@fullsend-ai-review

fullsend-ai-review Bot commented Aug 20, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 2:56 AM UTC · Completed 3:04 AM UTC

Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/docker.io-library-golang-1.x branch from b635f4b to 29a4b90 Compare August 26, 2026 03:04
@fullsend-ai-review

fullsend-ai-review Bot commented Aug 26, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:05 AM UTC · Completed 3:15 AM UTC

Commit: 87c4a29 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $2.14

fullsend-ai-review[bot]

This comment was marked as outdated.

@red-hat-konflux red-hat-konflux Bot changed the title Update docker.io/library/golang Docker tag to v1.27.0 (main) Update docker.io/library/golang Docker tag to v1.27.1 (main) Sep 6, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/docker.io-library-golang-1.x branch from 29a4b90 to 395f0ee Compare September 6, 2026 02:24
@red-hat-konflux
red-hat-konflux Bot requested a review from a team as a code owner September 6, 2026 02:24
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 6, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 2:26 AM UTC · Completed 2:33 AM UTC

Commit: cd01138 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $2.65

@fullsend-ai-review
fullsend-ai-review Bot dismissed stale reviews from themself September 6, 2026 02:33

Superseded by updated review

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added the requires-manual-review Review requires human judgment label Sep 6, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/docker.io-library-golang-1.x branch from 395f0ee to e4be4e3 Compare September 6, 2026 03:01
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 6, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:02 AM UTC · Completed 3:10 AM UTC

Commit: cd01138 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $3.38

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/docker.io-library-golang-1.x branch from e4be4e3 to aa70c41 Compare September 11, 2026 02:45
@coderabbitai

coderabbitai Bot commented Sep 11, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 179cd254-077f-4cf3-8c67-978f13bebbe5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 11, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 2:47 AM UTC · Completed 2:51 AM UTC

Commit: cd01138 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $1.29

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/docker.io-library-golang-1.x branch from aa70c41 to a65a109 Compare September 11, 2026 02:54
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 11, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 2:56 AM UTC · Completed 3:01 AM UTC

Commit: cd01138 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $2.01

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/docker.io-library-golang-1.x branch from a65a109 to 64d3074 Compare September 11, 2026 03:01
@fullsend-ai-review fullsend-ai-review Bot added the risk/moderate PR risk: moderate label Sep 11, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 11, 2026

Copy link
Copy Markdown

Risk Assessment: moderate (2/5)

Details

Routine Renovate bot Go toolset minor-version bump in a well-trodden pattern; protected-path status and minor API-compatibility risk across a Go minor version elevate from low to moderate.

Previous run

Risk Assessment: moderate (2/5)

Details

Small bot-authored Go version bump to a protected but low-blast Dockerfile with modestly active recent history yields a moderate composite score.

Previous run (2)

Risk Assessment: moderate (2/5)

Details

Routine Renovate-bot Go builder image bump (1.26.7 to 1.27.1) pinned by digest in a single protected file (Dockerfile); small blast radius but a major Go minor-version jump warrants moderate rather than low risk.

@fullsend-ai-review

Copy link
Copy Markdown

/fs-review

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 11, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:02 AM UTC · Completed 3:09 AM UTC

Commit: cd01138 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $2.50

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/docker.io-library-golang-1.x branch from 64d3074 to 40971b5 Compare September 20, 2026 01:49

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file docker Pull requests that update Docker code main renovate requires-manual-review Review requires human judgment risk/moderate PR risk: moderate size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants