Update docker.io/library/golang Docker tag to v1.26.4 (main) - #3372
Update docker.io/library/golang Docker tag to v1.26.4 (main)#3372red-hat-konflux[bot] wants to merge 1 commit into
Conversation
|
🤖 Finished Review · ✅ Success · Started 1:08 AM UTC · Completed 1:15 AM UTC |
ReviewFindingsHigh
Next steps:
Previous runReviewFindingsHigh
Next steps:
Previous run (2)ReviewFindingsHigh
Next steps:
Previous run (3)ReviewFindingsHigh
Next steps:
Previous run (4)ReviewFindingsHigh
Previous run (5)ReviewFindingsHigh
Previous run (6)Looks good to me — routine Golang base image patch bump (
Previous run (7)ReviewNo substantive findings. The Golang builder image bump from 1.26.3 to 1.26.5 with pinned digest is a routine dependency update.
Previous run (8)ReviewFindingsHigh
Previous run (9)ReviewFindingsHigh
Previous run (10)Looks good to me
Previous run (11)ReviewFindingsHigh
Previous run (12)Review — Approve ✅Patch version bump of the Go Docker base image ( SummaryThis is a mechanical, Renovate-generated dependency update that bumps the Go builder image by two patch versions. The change is a single-line tag swap with no behavioral, API, or architectural impact. Correctness: No logic, edge-case, or build risks introduced. The Security: No secrets, permissions, workflows, or auth-related files are modified. The mutable-tag pattern ( Intent & coherence: Automated patch maintenance by Renovate bot — authorization is implicit in the mechanical nature of the change and the project's configured auto-merge policy. Style & conventions: The new value follows the identical Documentation: No user-facing documentation references the specific Go builder image version. No staleness introduced. No findings above the severity threshold.
Previous run (13)Review — ✅ ApprovePR: #3372 — Update docker.io/library/golang Docker tag to v1.26.4 (main) SummaryRoutine patch version bump of the Go build base image in the Dockerfile from Analysis
FindingsNo findings.
Previous run (14)Review — ✅ ApproveScope: Automated patch version bump of Go Docker base image ( SummaryThis is a single-line, automated Renovate/MintMaker dependency update that bumps the Go compiler Docker image tag from Analysis
No findings above the severity threshold.
Previous run (15)Review — ✅ ApproveScope: Automated patch version bump of the Analysis
Notes
No findings. Safe to merge.
Previous run (16)Review of #3372 — Update docker.io/library/golang Docker tag to v1.26.5Verdict: ✅ Approve SummaryThis is an automated patch version bump of the Go Docker build image from Dimensions reviewed
Notes
Previous run (17)ReviewOutcome: Approve This PR is an automated Renovate/MintMaker dependency update that bumps the Go build image in Dimensions evaluated
No findings at or above the reporting threshold.
Previous run (18)ReviewOutcome: Approve SummaryMechanical patch-version bump of the Go build image from Findings
Dimensions evaluated
Labels: PR already has appropriate labels (dependencies, docker, renovate); adding go label since this is a Go compiler version bump. Previous run (19)Review of #3372 — Update docker.io/library/golang Docker tag to v1.26.4Verdict: Approve ✅ SummaryThis is a routine Renovate-automated patch version bump of the Go build image in Analysis
No findings.
Previous run (20)Review — #3372Verdict: ✅ Approve SummaryThis is a single-line, automated patch version bump of the Go build image in Dimension Results
Low-severity Observations
Previous run (21)ReviewFindingsHigh
Previous run (22)ReviewFindingsMedium
Labels: PR modifies the Dockerfile to bump a dependency version. |
93943cb to
48696b2
Compare
|
🤖 Finished Review · ✅ Success · Started 1:39 AM UTC · Completed 1:44 AM UTC |
9bcbd75 to
76d8bf9
Compare
|
🤖 Finished Review · ✅ Success · Started 1:49 AM UTC · Completed 1:54 AM UTC |
76d8bf9 to
275f5f9
Compare
|
🤖 Finished Review · ✅ Success · Started 1:39 AM UTC · Completed 1:42 AM UTC |
275f5f9 to
224bb6b
Compare
|
🤖 Finished Review · ✅ Success · Started 1:33 AM UTC · Completed 1:38 AM UTC |
|
🤖 Finished Review · ✅ Success · Started 1:45 AM UTC · Completed 1:52 AM UTC |
3f95df9 to
dda0e9e
Compare
|
🤖 Finished Review · ✅ Success · Started 1:39 AM UTC · Completed 1:46 AM UTC |
Superseded by updated review
dda0e9e to
bb10e0a
Compare
|
🤖 Finished Review · ✅ Success · Started 1:40 AM UTC · Completed 1:49 AM UTC |
bb10e0a to
d4dfe4d
Compare
|
🤖 Finished Review · ✅ Success · Started 1:55 AM UTC · Completed 2:02 AM UTC |
d4dfe4d to
cbc846e
Compare
|
🤖 Finished Review · ✅ Success · Started 1:57 AM UTC · Completed 2:05 AM UTC |
cbc846e to
0f14683
Compare
|
🤖 Finished Review · ✅ Success · Started 2:25 AM UTC · Completed 2:32 AM UTC |
0f14683 to
fdf9c83
Compare
|
🤖 Finished Review · ✅ Success · Started 2:12 AM UTC · Completed 2:19 AM UTC |
fdf9c83 to
a939765
Compare
|
🤖 Finished Review · ✅ Success · Started 1:52 AM UTC · Completed 2:00 AM UTC |
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
a939765 to
bafde14
Compare
|
🤖 Finished Review · ✅ Success · Started 1:56 AM UTC · Completed 2:05 AM UTC |
| ## Build | ||
|
|
||
| FROM docker.io/library/golang:1.26.3@sha256:2d6c80227255c3112a4d08e67ba98e58efd3846daf15d9d7d4c389565d881b1a AS build | ||
| FROM docker.io/library/golang:1.26.4@sha256:f96cc555eb8db430159a3aa6797cd5bae561945b7b0fe7d0e284c63a3b291609 AS build |
There was a problem hiding this comment.
[high] protected-path
Dockerfile is a protected governance/infrastructure file that requires human approval for all changes. This automated Renovate PR updates the Go builder image from 1.26.3 to 1.26.4 (patch bump with pinned digest), but no linked issue provides explicit authorization for modifying protected paths. The change itself is mechanically sound — the tag and digest are updated consistently and digest pinning is maintained.
Suggested fix: A maintainer must review and approve this Dockerfile change. No code-level changes are needed.
This PR contains the following updates:
1.26.3→1.26.41.26.5Warning
Some dependencies could not be looked up. Check the warning logs for more information.
Configuration
📅 Schedule: (UTC)
* 0-3 * * *)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.