Skip to content

Update Konflux references - #15098

Open
red-hat-konflux-kflux-prd-rh02[bot] wants to merge 1 commit into
masterfrom
konflux/references/master
Open

red-hat-konflux-kflux-prd-rh02[bot] wants to merge 1 commit into
masterfrom
konflux/references/master

Conversation

@red-hat-konflux-kflux-prd-rh02

@red-hat-konflux-kflux-prd-rh02 red-hat-konflux-kflux-prd-rh02 Bot commented Sep 5, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
quay.io/konflux-ci/tekton-catalog/task-apply-tags (source, changelog) tekton-bundle patch 0.3 → 0.3.2
quay.io/konflux-ci/tekton-catalog/task-build-image-index (source, changelog) tekton-bundle minor 0.3.1 → 0.4
quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta (source, changelog) tekton-bundle minor 0.12.0 → 0.13.0
quay.io/konflux-ci/tekton-catalog/task-clamav-scan (source, changelog) tekton-bundle patch 0.3.2 → 0.3.4
quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check (source, changelog) tekton-bundle digest 0ccc688 → 81b7cad
quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks (source, changelog) tekton-bundle digest b961f8b → 4390141
quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta (source, changelog) tekton-bundle digest 3bcd4c3 → a367891
quay.io/konflux-ci/tekton-catalog/task-init (source, changelog) tekton-bundle digest 5f68715 → 7854d7b
quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta (source, changelog) tekton-bundle patch 0.10.1 → 0.10.3
quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta (source, changelog) tekton-bundle digest 393b4d0 → 4c567d1
quay.io/konflux-ci/tekton-catalog/task-roxctl-scan (source, changelog) tekton-bundle digest 76ed85a → e398b9d
quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan (source, changelog) tekton-bundle digest f110c53 → f72e0ba
quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta (source, changelog) tekton-bundle patch 0.1 → 0.1.1
quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta (source, changelog) tekton-bundle patch 0.5 → 0.5.1
quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta (source, changelog) tekton-bundle patch 0.4 → 0.4.1
quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta (source, changelog) tekton-bundle patch 0.3 → 0.3.2

Release Notes

konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-apply-tags)

v0.3.2

Added
  • ADDITIONAL_TAGS_FROM_LABEL parameter to specify image label to read additional tags from.
    For now set previously hardcoded value konflux.additional-tags by default to avoid changing the task behavior.

v0.3.1

Changed
  • Nothing. Started using semver specification for version labels.
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-build-image-index)

v0.4

Added
  • IMAGE_PLATFORM_MAP parameter: optional per-image platform mapping
    (imageRef=os/arch entries) passed to konflux-build-cli as
    --image-platform-map. This sets the platform on each index entry explicitly,
    which is required for OCI artifacts whose empty config carries no platform
    information (e.g. disk images), where the platform would otherwise be null.
    When empty (the default), behaviour is unchanged.
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta)

v0.13.0

Changed

The BUILD_ARGS_FILE parameter was renamed to BUILD_ARGS_FILES and allows
passing multiple build arguments files as buildah itself does.

v0.12.3

Changed
  • All ssh and rsync invocations to the build VM now share a single ssh
    connection. The build step writes an ~/.ssh/config with ControlMaster auto,
    ControlPath and ControlPersist, so only the first invocation pays the cost
    of the TCP handshake, key exchange and authentication.

v0.12.2

Removed
  • Removed the SSH port forwarding from decommissioned JVM Build Service artifact cache
    (JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR) from the remote build. This is just cleanup of unused code.

v0.12.1

Changed
  • Bump prepare-sboms step memory from 256Mi to 512Mi (requests = limits) to prevent OOM kills on large container images (GPU/ML, bootc, driver-toolkit).
  • Remove prepare-sboms CPU limit (was 100m) to allow burst CPU and prevent throttling. CPU requests remain at 100m.
konflux-ci/konflux-test-tasks (quay.io/konflux-ci/tekton-catalog/task-clamav-scan)

v0.3.4

Added
  • Pre-extract every nested archive into a loose file tree before scanning, so
    clamd scans each file directly instead of recursing through nested archive
    layers. This makes scanning of deeply nested archives faster. Extraction uses
    bsdtar, which detects archives (zip/jar/war/ear/tar
    and tar.gz/tar.bz2/tar.xz) by content rather than extension — important because
    the OCI dir: payload is an extension-less blob — and unpacks them
    unconditionally with no size/count/depth limits. It is defensive: a corrupt or
    partial archive is left in place for clamd rather than aborting the scan. No new
    parameters are introduced. Requires the clamav-db image to ship bsdtar
    (added in konflux-clamav).

v0.3.3

Changed
  • Skip downloading OCI layers whose manifest annotations name only unscannable
    model-weight files (.safetensors, .gguf, .ggml, .pt, .pth, .onnx,
    .onnx_data / .onnx_data_*), using org.opencontainers.image.title and
    olot.layer.content.inlayerpath. Any other annotated layer is skipped when
    the OCI descriptor size is at least 2000MiB (slightly under ClamAV's ~2GiB
    MaxFileSize), regardless of extension. Layers without those annotations are
    still listed with --dry-run as in 0.3.2. The --dry-run skip uses the
    same name list.
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta)

v0.10.3

v0.10.2

konflux-ci/konflux-sast-tasks (quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta)

v0.1.1

Fixed
  • Added the missing migration that removes the obsolete CACHI2_ARTIFACT parameter
    from user pipelines. The parameter was dropped from the task definition in an
    earlier release, but pipelines kept passing it.
konflux-ci/konflux-sast-tasks (quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta)

v0.5.1

Fixed
  • Added the missing migration that removes the obsolete CACHI2_ARTIFACT parameter
    from user pipelines. The parameter was dropped from the task definition in an
    earlier release, but pipelines kept passing it.
konflux-ci/konflux-sast-tasks (quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta)

v0.4.1

Fixed
  • Added the missing migration that removes the obsolete CACHI2_ARTIFACT parameter
    from user pipelines. The parameter was dropped from the task definition in an
    earlier release, but pipelines kept passing it.
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta)

v0.3.2

Fixed
  • Cargo prefetched dependencies are now included in the source image. They are
    vendored as unpacked source trees rather than archives, so previously they
    were missed by the archive-type filter and left out of the source image.

v0.3.1

Changed
  • Nothing. Started using semver specification for version labels.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Only on Saturday (* * * * 6)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux-kflux-prd-rh02 red-hat-konflux-kflux-prd-rh02 Bot added the ok-to-test Used by openshift-ci bot. label Sep 5, 2026
@openshift-ci

openshift-ci Bot commented Sep 5, 2026

Copy link
Copy Markdown

Hi @red-hat-konflux-kflux-prd-rh02[bot]. Thanks for your PR.

I'm waiting for a ComplianceAsCode member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@macko1
macko1 requested a review from yuumasato September 16, 2026 15:44
@red-hat-konflux-kflux-prd-rh02
red-hat-konflux-kflux-prd-rh02 Bot force-pushed the konflux/references/master branch 2 times, most recently from 4e442f5 to bfe00b3 Compare October 10, 2026 00:05
Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ok-to-test Used by openshift-ci bot.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants