Repository navigation
Update Konflux references - #15098
Open
red-hat-konflux-kflux-prd-rh02[bot] wants to merge 1 commit into
Open
red-hat-konflux-kflux-prd-rh02[bot] wants to merge 1 commit into
red-hat-konflux-kflux-prd-rh02[bot] wants to merge 1 commit into
Conversation
|
Hi @red-hat-konflux-kflux-prd-rh02[bot]. Thanks for your PR. I'm waiting for a ComplianceAsCode member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
red-hat-konflux-kflux-prd-rh02
Bot
force-pushed
the
konflux/references/master
branch
from
September 12, 2026 08:06
bb5a64d to
c89bb0e
Compare
red-hat-konflux-kflux-prd-rh02
Bot
force-pushed
the
konflux/references/master
branch
from
September 19, 2026 00:03
c89bb0e to
dcd9f2f
Compare
red-hat-konflux-kflux-prd-rh02
Bot
force-pushed
the
konflux/references/master
branch
from
September 26, 2026 00:04
dcd9f2f to
b8fdf2e
Compare
red-hat-konflux-kflux-prd-rh02
Bot
force-pushed
the
konflux/references/master
branch
2 times, most recently
from
October 10, 2026 00:05
4e442f5 to
bfe00b3
Compare
Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com>
red-hat-konflux-kflux-prd-rh02
Bot
force-pushed
the
konflux/references/master
branch
from
October 10, 2026 20:06
bfe00b3 to
3da29d7
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.3→0.3.20.3.1→0.40.12.0→0.13.00.3.2→0.3.40ccc688→81b7cadb961f8b→43901413bcd4c3→a3678915f68715→7854d7b0.10.1→0.10.3393b4d0→4c567d176ed85a→e398b9df110c53→f72e0ba0.1→0.1.10.5→0.5.10.4→0.4.10.3→0.3.2Release Notes
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-apply-tags)
v0.3.2Added
ADDITIONAL_TAGS_FROM_LABELparameter to specify image label to read additional tags from.For now set previously hardcoded value
konflux.additional-tagsby default to avoid changing the task behavior.v0.3.1Changed
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-build-image-index)
v0.4Added
IMAGE_PLATFORM_MAPparameter: optional per-image platform mapping(
imageRef=os/archentries) passed tokonflux-build-clias--image-platform-map. This sets the platform on each index entry explicitly,which is required for OCI artifacts whose empty config carries no platform
information (e.g. disk images), where the platform would otherwise be null.
When empty (the default), behaviour is unchanged.
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta)
v0.13.0Changed
The
BUILD_ARGS_FILEparameter was renamed toBUILD_ARGS_FILESand allowspassing multiple build arguments files as buildah itself does.
v0.12.3Changed
sshandrsyncinvocations to the build VM now share a single sshconnection. The build step writes an
~/.ssh/configwithControlMaster auto,ControlPathandControlPersist, so only the first invocation pays the costof the TCP handshake, key exchange and authentication.
v0.12.2Removed
(
JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR) from the remote build. This is just cleanup of unused code.v0.12.1Changed
prepare-sbomsstep memory from 256Mi to 512Mi (requests = limits) to prevent OOM kills on large container images (GPU/ML, bootc, driver-toolkit).prepare-sbomsCPU limit (was 100m) to allow burst CPU and prevent throttling. CPU requests remain at 100m.konflux-ci/konflux-test-tasks (quay.io/konflux-ci/tekton-catalog/task-clamav-scan)
v0.3.4Added
clamd scans each file directly instead of recursing through nested archive
layers. This makes scanning of deeply nested archives faster. Extraction uses
bsdtar, which detects archives (zip/jar/war/ear/tarand tar.gz/tar.bz2/tar.xz) by content rather than extension — important because
the OCI
dir:payload is an extension-less blob — and unpacks themunconditionally with no size/count/depth limits. It is defensive: a corrupt or
partial archive is left in place for clamd rather than aborting the scan. No new
parameters are introduced. Requires the
clamav-dbimage to shipbsdtar(added in konflux-clamav).
v0.3.3Changed
model-weight files (
.safetensors,.gguf,.ggml,.pt,.pth,.onnx,.onnx_data/.onnx_data_*), usingorg.opencontainers.image.titleandolot.layer.content.inlayerpath. Any other annotated layer is skipped whenthe OCI descriptor
sizeis at least 2000MiB (slightly under ClamAV's ~2GiBMaxFileSize), regardless of extension. Layers without those annotations are
still listed with
--dry-runas in 0.3.2. The--dry-runskip uses thesame name list.
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta)
v0.10.3v0.10.2konflux-ci/konflux-sast-tasks (quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta)
v0.1.1Fixed
CACHI2_ARTIFACTparameterfrom user pipelines. The parameter was dropped from the task definition in an
earlier release, but pipelines kept passing it.
konflux-ci/konflux-sast-tasks (quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta)
v0.5.1Fixed
CACHI2_ARTIFACTparameterfrom user pipelines. The parameter was dropped from the task definition in an
earlier release, but pipelines kept passing it.
konflux-ci/konflux-sast-tasks (quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta)
v0.4.1Fixed
CACHI2_ARTIFACTparameterfrom user pipelines. The parameter was dropped from the task definition in an
earlier release, but pipelines kept passing it.
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta)
v0.3.2Fixed
vendored as unpacked source trees rather than archives, so previously they
were missed by the archive-type filter and left out of the source image.
v0.3.1Changed
Configuration
📅 Schedule: (UTC)
* * * * 6)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.