Skip to content

NO-JIRA: Update registry.redhat.io/ubi9/ubi-minimal Docker digest to 7fbeae1 - #3214

Open
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/registry.redhat.io-ubi9-ubi-minimal
Open

NO-JIRA: Update registry.redhat.io/ubi9/ubi-minimal Docker digest to 7fbeae1#3214
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/registry.redhat.io-ubi9-ubi-minimal

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
registry.redhat.io/ubi9/ubi-minimal final digest 8eb28307fbeae1

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Aug 26, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@red-hat-konflux[bot]: This pull request explicitly references no jira issue.

Details

In response to this:

This PR contains the following updates:

Package Type Update Change
registry.redhat.io/ubi9/ubi-minimal final digest 8eb2830580752f

Configuration

📅 Schedule: (UTC)

  • Branch creation
  • At any time (no schedule defined)
  • Automerge
  • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai

coderabbitai Bot commented Aug 26, 2026

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 1602f5ff-990e-4942-b389-8bb282608109

📥 Commits

Reviewing files that changed from the base of the PR and between e0beea4 and d68c8b8.

📒 Files selected for processing (2)
  • release/operator/konflux.Dockerfile
  • release/operator/rpms.lock.yaml

Included review availability: Your plan provides up to 12 included reviews per hour; 0 remain after this review.


Walkthrough

The runtime stage uses an updated pinned UBI 9 minimal image digest. The RPM lockfile updates dbus-broker and gzip metadata for four architectures.

Changes

Runtime dependency updates

Layer / File(s) Summary
Pinned runtime image update
release/operator/konflux.Dockerfile
The runtime stage uses a new pinned UBI 9 minimal image digest. $TARGETPLATFORM selection remains unchanged.
Mult architecture RPM lock refresh
release/operator/rpms.lock.yaml
The lockfile updates binary and source entries for dbus-broker and gzip across aarch64, ppc64le, s390x, and x86_64.

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to d68c8

This PR updates the UBI minimal image digest; no actionable merge-blocking risk remains beyond normal checks and review.

Suggested reviewers: eggfoobar, jeff-roche, qjkee

🚥 Pre-merge checks | ✅ 15
✅ Passed checks (15 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the primary change: updating the pinned registry.redhat.io/ubi9/ubi-minimal Docker image digest. It is concise and specific.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed PASS: The pull request changes only release/operator/konflux.Dockerfile and release/operator/rpms.lock.yaml. The diff contains no Ginkgo test declarations or test title changes. Therefore, it intr…
Test Structure And Quality ✅ Passed PASS. The pull request changes only release/operator/konflux.Dockerfile and release/operator/rpms.lock.yaml. The diff contains no Go files, Ginkgo constructs, or test paths. Therefore, the Ginkgo …
Microshift Test Compatibility ✅ Passed PASS: The pull request changes only release/operator/konflux.Dockerfile and release/operator/rpms.lock.yaml. The diff contains a UBI image digest update and RPM metadata updates. It adds no Ginkgo…
Single Node Openshift (Sno) Test Compatibility ✅ Passed PASS: The pull request changes only release/operator/konflux.Dockerfile and release/operator/rpms.lock.yaml. The diff contains no Go test files and no added or modified Ginkgo declarations such as…
Topology-Aware Scheduling Compatibility ✅ Passed PASS: The pull request changes only the runtime image digest in release/operator/konflux.Dockerfile and package metadata in release/operator/rpms.lock.yaml. The diff adds no deployment manifests, …
Ote Binary Stdout Contract ✅ Passed PASS — The pull request changes only release/operator/konflux.Dockerfile and release/operator/rpms.lock.yaml. The Dockerfile changes the UBI image digest, while the lockfile changes RPM metadata f…
Ipv6 And Disconnected Network Test Compatibility ✅ Passed PASS — The pull request changes only release/operator/konflux.Dockerfile and release/operator/rpms.lock.yaml. The diff updates a UBI image digest and RPM metadata. It adds no Ginkgo e2e tests and …
No-Weak-Crypto ✅ Passed PASS. The commit changes only the UBI minimal image digest and RPM lock metadata for dbus-broker and gzip across four architectures. The added lines contain no MD5, SHA1, DES, RC4, 3DES, Blowfish,…
Container-Privileges ✅ Passed PASS. The PR changes only the UBI image digest and RPM lock metadata. No changed line adds privileged, host PID/network/IPC access, SYS_ADMIN, or allowPrivilegeEscalation: true. The runtime Dock…
No-Sensitive-Data-In-Logs ✅ Passed PASS. The pull request changes only the UBI image digest and RPM lockfile metadata for dbus-broker and gzip. The exact diff adds no logging statements, output commands, or sensitive-data values. P…
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (2 skipped: 2 unsupported.)

Full details: Stable And Deterministic Test Names

Explanation

PASS: The pull request changes only release/operator/konflux.Dockerfile and release/operator/rpms.lock.yaml. The diff contains no Ginkgo test declarations or test title changes. Therefore, it introduces no unstable or overly specific test name.

Full details: Test Structure And Quality

Explanation

PASS. The pull request changes only release/operator/konflux.Dockerfile and release/operator/rpms.lock.yaml. The diff contains no Go files, Ginkgo constructs, or test paths. Therefore, the Ginkgo test structure and quality requirements are not applicable.

Full details: Microshift Test Compatibility

Explanation

PASS: The pull request changes only release/operator/konflux.Dockerfile and release/operator/rpms.lock.yaml. The diff contains a UBI image digest update and RPM metadata updates. It adds no Ginkgo e2e tests, API references, namespaces, or unsupported MicroShift assumptions. The compatibility check is therefore not triggered.

Full details: Single Node Openshift (Sno) Test Compatibility

Explanation

PASS: The pull request changes only release/operator/konflux.Dockerfile and release/operator/rpms.lock.yaml. The diff contains no Go test files and no added or modified Ginkgo declarations such as It, Describe, Context, or When. Therefore, the SNO test compatibility check is not applicable.

Full details: Topology-Aware Scheduling Compatibility

Explanation

PASS: The pull request changes only the runtime image digest in release/operator/konflux.Dockerfile and package metadata in release/operator/rpms.lock.yaml. The diff adds no deployment manifests, operator/controller code, replicas, affinity, topology spread, node selectors, tolerations, or PDB settings. The topology-aware scheduling check is therefore not applicable.

Full details: Ote Binary Stdout Contract

Explanation

PASS — The pull request changes only release/operator/konflux.Dockerfile and release/operator/rpms.lock.yaml. The Dockerfile changes the UBI image digest, while the lockfile changes RPM metadata for dbus-broker and gzip. No Go source, main(), suite setup, or logging code changed. The build still uses the existing cmd/main.go, so this pull request introduces no process-level non-JSON stdout write covered by the check.

Full details: Ipv6 And Disconnected Network Test Compatibility

Explanation

PASS — The pull request changes only release/operator/konflux.Dockerfile and release/operator/rpms.lock.yaml. The diff updates a UBI image digest and RPM metadata. It adds no Ginkgo e2e tests and no test code with IPv4 assumptions or external connectivity requirements. The registry.redhat.io reference is build metadata, not a new test dependency.

Full details: No-Weak-Crypto

Explanation

PASS. The commit changes only the UBI minimal image digest and RPM lock metadata for dbus-broker and gzip across four architectures. The added lines contain no MD5, SHA1, DES, RC4, 3DES, Blowfish, or ECB usage, and no source or crypto implementation changed. The apparent ecb scan matches are substrings inside SHA-256 checksum values, not algorithm usage.

Full details: Container-Privileges

Explanation

PASS. The PR changes only the UBI image digest and RPM lock metadata. No changed line adds privileged, host PID/network/IPC access, SYS_ADMIN, or allowPrivilegeEscalation: true. The runtime Dockerfile still sets USER 65532:65532. Existing privileged SCC settings are unchanged and are not caused by this PR.

Full details: No-Sensitive-Data-In-Logs

Explanation

PASS. The pull request changes only the UBI image digest and RPM lockfile metadata for dbus-broker and gzip. The exact diff adds no logging statements, output commands, or sensitive-data values. Pattern checks across both changed files found no log or sensitive-data logging constructs.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch konflux/mintmaker/main/registry.redhat.io-ubi9-ubi-minimal

Comment @coderabbitai help to get the list of available commands.

@openshift-ci
openshift-ci Bot requested review from eggfoobar and jeff-roche August 26, 2026 07:24
@openshift-ci openshift-ci Bot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Aug 26, 2026
@openshift-ci

openshift-ci Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: red-hat-konflux[bot]
Once this PR has been reviewed and has the lgtm label, please assign eggfoobar for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

…7fbeae1

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/registry.redhat.io-ubi9-ubi-minimal branch from e0beea4 to d68c8b8 Compare September 1, 2026 01:06
@red-hat-konflux red-hat-konflux Bot changed the title NO-JIRA: Update registry.redhat.io/ubi9/ubi-minimal Docker digest to 580752f NO-JIRA: Update registry.redhat.io/ubi9/ubi-minimal Docker digest to 7fbeae1 Sep 1, 2026
@openshift-ci openshift-ci Bot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Sep 1, 2026
@openshift-ci

openshift-ci Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

@red-hat-konflux[bot]: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant