Update registry.access.redhat.com/ubi9/go-toolset Docker tag to v1.26.5 (release-v0.7) - #3462
Conversation
|
🤖 Finished Review · ✅ Success · Started 2:24 AM UTC · Completed 2:31 AM UTC |
ReviewFindingsHigh
Next steps:
Previous runReviewFindingsHigh
Labels: PR modifies a Dockerfile and updates a dependency version Next steps:
Previous run (2)ReviewFindingsHigh
Next steps:
|
6a3a95f to
4652eb7
Compare
|
🤖 Finished Review · ✅ Success · Started 10:53 AM UTC · Completed 11:00 AM UTC Commit: |
4652eb7 to
7cc001b
Compare
|
🤖 Finished Review · ✅ Success · Started 3:23 PM UTC · Completed 3:31 PM UTC Commit: |
| ## Build | ||
|
|
||
| FROM registry.access.redhat.com/ubi9/go-toolset:1.26.4@sha256:9748bb0b8e3376e9b155a4db3fbdfbfd20057b449ea9b3aed367b2f967cdfe1b AS build | ||
| FROM registry.access.redhat.com/ubi9/go-toolset:1.26.5@sha256:0b471eb04868f3d9d90bf3c668f9c6c7a22cef07474ac9fec067909dfd7dec7c AS build |
There was a problem hiding this comment.
[high] protected-path
This PR modifies Dockerfile.dist, which matches the Dockerfile protected path pattern (governance/infrastructure). The PR has no linked issue authorizing changes to protected paths, and the description is an auto-generated Renovate template rather than a human-authored justification. Human approval is always required for protected-path changes.
Suggested fix: A human reviewer must explicitly approve this infrastructure change. The change itself (patch version bump of go-toolset from 1.26.4 to 1.26.5 with pinned digest) is straightforward, but protected-path policy requires human sign-off.
This PR contains the following updates:
1.26.4→1.26.5Configuration
📅 Schedule: (UTC)
* 0-3 * * *)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.