Skip to content

Update docker.io/library/golang Docker tag to v1.27.0 (main) - #3555

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/main-docker.io-library-golang-1.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/main-docker.io-library-golang-1.x

Conversation

@renovate

@renovate renovate Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Pending
docker.io/library/golang (source) stage minor 1.26.71.27.0 1.27.1

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@coderabbitai

coderabbitai Bot commented Sep 10, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: b07ed2f2-13b6-4780-823e-236e57ccfc54

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 10, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:04 AM UTC · Completed 3:10 AM UTC

Commit: cd01138 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $1.71

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 10, 2026

Copy link
Copy Markdown

Review

Findings

Medium

  • [protected-path] Dockerfile — This PR modifies Dockerfile, which is on the protected-paths list; changes to it always require human approval regardless of context. The rationale is clear (Renovate bumping the golang builder image from 1.26.7 to 1.27.0 with a matching SHA256 digest, generated by renovate[bot]), and the repository's renovate.json extends the shared conforma/.github//config/renovate/renovate.json preset, which authorizes the automated dependency-update pattern. A human reviewer must still explicitly confirm the base-image change before merge.
Previous run

Review

Findings

Medium

  • [protected-path] Dockerfile — This PR modifies Dockerfile, a governance/infrastructure file listed in the protected paths policy. The Renovate PR body explains the change (docker.io/library/golang 1.26.71.27.1, minor stage bump; both tag and digest are pinned), and the repository has renovate.json at root authorizing automated dependency updates. Human approval is always required for protected-path changes regardless of context.
    Remediation: A human reviewer confirms the Go 1.27.1 base image bump is acceptable and merges manually (Automerge is disabled by config for this repo).
Previous run (2)

Review

Findings

Low

  • [protected-path] Dockerfile — Modifies Dockerfile, which is in the repository's protected-paths list (REVIEW_PROTECTED_PATHS). The repository has a renovate.json extending github>conforma/.github//config/renovate/renovate.json and this PR is authored by the Renovate bot, so an automated Docker base-image tag/digest bump is within an established policy pattern. Human approval is still required for all protected-path changes regardless of context.
Previous run (3)

Review

Findings

Medium

  • [protected-path] Dockerfile — This PR modifies Dockerfile, which the review agent treats as a governance/infrastructure protected path (via REVIEW_PROTECTED_PATHS). The change is a routine Renovate-generated Docker tag bump (docker.io/library/golang 1.26.71.27.1) authorized in principle by the repo's renovate.json (which extends github>conforma/.github//config/renovate/renovate.json), and the requires-manual-review label is already applied. Human approval is required for any protected-path change regardless of context — the review agent will not auto-approve.

Info

  • [provenance-warning] Prior review context was discarded: PRIOR_REVIEW_PROVENANCE=unverifiable-wrong-app. A prior review comment exists on this PR but was authored by a different app than the one performing this review, so its authorship cannot be reliably attributed. This run treats all findings as first-time assessments; severity anchoring was skipped.
  • [risk-assessment] Composite risk score: 2/5 (moderate). Renovate bot bumps golang base image tag in a single protected file with a tiny diff and clean history; the modest Dockerfile churn nudges it slightly above low.
Previous run (4)

Review

Findings

Medium

  • [protected-path] Dockerfile — This PR modifies Dockerfile, which is on the repository's protected-paths list (governance/build infrastructure). The change is a Renovate-bot minor version bump of the golang builder base image (1.26.71.27.0, digest-pinned). The repository's renovate.json (extending github>conforma/.github//config/renovate/renovate.json) configures automated dependency updates, providing implicit repo-wide authorization for this class of change. Human approval is nonetheless required for all protected-path modifications, regardless of automated tooling context. Correctness, security, and style-conventions sub-agents produced no findings; the diff is limited to the single build-stage FROM line with the digest properly pinned.
    Remediation: A human reviewer should confirm the new base image and digest (sha256:4013ae0f9e7994f8535c58c811f8f863fbed38b72e0d51e6592156f758d66146) before merge.

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added the requires-manual-review Review requires human judgment label Sep 10, 2026
@renovate
renovate Bot force-pushed the renovate/main-docker.io-library-golang-1.x branch from d436ea5 to 1732811 Compare September 15, 2026 02:06
@renovate renovate Bot changed the title Update docker.io/library/golang Docker tag to v1.27.0 (main) Update docker.io/library/golang Docker tag to v1.27.1 (main) Sep 15, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 15, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 2:07 AM UTC · Completed 2:14 AM UTC

Commit: cd01138 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $2.43

@fullsend-ai-review fullsend-ai-review Bot added the risk/moderate PR risk: moderate label Sep 15, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 15, 2026

Copy link
Copy Markdown

Risk Assessment: moderate (2/5)

Details

Two-line Dockerfile change bumping the golang builder from 1.26.7 to 1.27.0 with a pinned digest, authored by renovate[bot]. Tier 1 is pulled above baseline by the protected-path flag on Dockerfile and CI-relevance, but offset by minimal change size (1 file, 2 lines), zero security-sensitive hits, and bot authorship. Tier 2 shows the file is high-churn but exclusively via routine automated updates with an established golang-bump cadence and no history of breakage. Aligns with the existing risk/moderate label.

Previous run

Risk Assessment: moderate (2/5)

Details

Routine bot-authored Go base-image bump in Dockerfile (1.26.7 -> 1.27.1), minimal size and no security-sensitive changes, modestly elevated by a protected-path flag, with an active but clean commit history on the file.

Previous run (2)

Risk Assessment: moderate (2/5)

Details

Renovate bot bumps golang base image tag in a single protected file with tiny diff and clean history; CI-touching signal and modest Dockerfile churn nudge it slightly above low.

fullsend-ai-review[bot]

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/main-docker.io-library-golang-1.x branch from 1732811 to 16a4faa Compare September 15, 2026 15:48
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 15, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:50 PM UTC · Completed 3:57 PM UTC

Commit: e8f0a9f · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $2.44

@fullsend-ai-review fullsend-ai-review Bot removed the risk/moderate PR risk: moderate label Sep 15, 2026
fullsend-ai-review[bot]

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/main-docker.io-library-golang-1.x branch from 16a4faa to 03b18a3 Compare September 17, 2026 17:34
@fullsend-ai-review fullsend-ai-review Bot added the risk/moderate PR risk: moderate label Sep 17, 2026
@renovate
renovate Bot force-pushed the renovate/main-docker.io-library-golang-1.x branch from 03b18a3 to afba9c8 Compare September 19, 2026 11:01
@renovate renovate Bot changed the title Update docker.io/library/golang Docker tag to v1.27.1 (main) Update docker.io/library/golang Docker tag to v1.27.0 (main) Sep 19, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

main renovate requires-manual-review Review requires human judgment risk/moderate PR risk: moderate size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants