Skip to content

chore(deps): Update ubi-minimal base image (v0.8) - #3569

Merged
simonbaird merged 1 commit into
conforma:release-v0.8from
simonbaird:ubi-bump-release-v0.8
Sep 15, 2026
Merged

simonbaird merged 1 commit into
conforma:release-v0.8from
simonbaird:ubi-bump-release-v0.8

Conversation

@simonbaird

@simonbaird simonbaird commented Sep 15, 2026 •

Copy link
Copy Markdown
Member

Update ubi-minimal base image to latest digest.

Old digest: sha256:7fbeae18dc9476399f565e68255f602a3374ea8614ba3d14843565131a13ff93
New digest: sha256:e5161a7d7d99cf22e4f34b72e111211a399d956d9b0e8714da18e9c4c8151041

RPM changes

- coreutils-single-8.32-41.el9_8.x86_64
+ coreutils-single-8.32-41.el9_8.1.x86_64
- glib2-2.68.4-19.el9_8.9.x86_64
+ glib2-2.68.4-19.el9_8.10.x86_64
- openssl-libs-3.5.5-6.el9_8.x86_64
+ openssl-libs-3.5.8-1.el9_8.x86_64

Ref: https://redhat.atlassian.net/browse/EC-2184
Ref: https://redhat.atlassian.net/browse/EC-2207

Old digest: sha256:7fbeae18dc9476399f565e68255f602a3374ea8614ba3d14843565131a13ff93
New digest: sha256:e5161a7d7d99cf22e4f34b72e111211a399d956d9b0e8714da18e9c4c8151041

RPM changes:

- coreutils-single-8.32-41.el9_8.x86_64
+ coreutils-single-8.32-41.el9_8.1.x86_64
- glib2-2.68.4-19.el9_8.9.x86_64
+ glib2-2.68.4-19.el9_8.10.x86_64
- openssl-libs-3.5.5-6.el9_8.x86_64
+ openssl-libs-3.5.8-1.el9_8.x86_64
@coderabbitai

coderabbitai Bot commented Sep 15, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Enterprise

Run ID: cef2db84-24ac-4177-bb9b-45c2e541150a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@qodo-for-conforma

Copy link
Copy Markdown

PR Summary by Qodo

Update UBI Minimal Base Image Digest

⚙️ Configuration changes 🕐 Less than 5 minutes

Grey Divider

AI Description

• Updates both runtime images to the latest pinned UBI Minimal digest.
• Incorporates patch releases for coreutils-single, glib2, and OpenSSL libraries.
High-Level Assessment

Updating the immutable digest in both Dockerfiles is the optimal approach because it preserves reproducible builds while applying upstream RPM patches. Using an unpinned tag was dismissed because it would make image contents non-deterministic.

Files changed (2) +2 / -2

Other (2) +2 / -2
DockerfileRefresh the standard runtime UBI Minimal image +1/-1

Refresh the standard runtime UBI Minimal image

• Updates the pinned UBI 9 Minimal final-stage image digest. The refreshed image includes patch-level coreutils-single, glib2, and OpenSSL library updates.

Dockerfile

Dockerfile.distRefresh the distribution runtime UBI Minimal image +1/-1

Refresh the distribution runtime UBI Minimal image

• Updates the distribution build's final-stage UBI 9 Minimal digest to match the standard image and consume the same RPM patches.

Dockerfile.dist

@qodo-for-conforma

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can reply 'qodo' on any finding to push back, ask questions, or dig deeper

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:38 PM UTC · Completed 3:44 PM UTC

Commit: e8f0a9f · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $1.98

@fullsend-ai-review fullsend-ai-review Bot added the risk/moderate PR risk: moderate label Sep 15, 2026
@fullsend-ai-review

Copy link
Copy Markdown

Risk Assessment: moderate (2/5)

Details

Mechanical ubi-minimal base image digest bump on a release branch touches protected Dockerfiles and is a supply-chain touchpoint, but the change is a routine minor RPM update within the same tag.

@fullsend-ai-review

Copy link
Copy Markdown

Review

Findings

High

  • [protected-path] Dockerfile, Dockerfile.dist — This PR modifies protected build/infrastructure files but has no linked issue authorizing the change. The change itself is a routine, mechanical ubi-minimal base image digest bump on release-v0.8 (the PR body records the old/new digests and the RPM version deltas for coreutils-single, glib2, and openssl-libs), and no correctness, security, or style concerns were found in the diff. However, governance requires explicit authorization for changes under protected paths (Dockerfile, Dockerfile.dist), and human approval is required regardless of the change's mechanical nature.
    Remediation: Link an issue that authorizes the base image refresh (scheduled ubi-minimal maintenance, CVE remediation, or an automated-dependency policy such as Renovate/Konflux Mintmaker) so the change traces to authorized work, and obtain human approval before merge.

Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR

@fullsend-ai-review fullsend-ai-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See the review comment for full details.

Comment thread Dockerfile
Comment thread Dockerfile.dist
@codecov

codecov Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Flag Coverage Δ
acceptance 54.86% <ø> (+<0.01%) ⬆️
generative 18.14% <ø> (ø)
integration 26.99% <ø> (ø)
unit 68.66% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@robnester-rh robnester-rh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@simonbaird
simonbaird merged commit 808c13c into conforma:release-v0.8 Sep 15, 2026
15 checks passed
@fullsend-ai-retro

fullsend-ai-retro Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 7:51 PM UTC · Completed 7:57 PM UTC

Commit: e8f0a9f · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $3.18

@fullsend-ai-retro

Copy link
Copy Markdown

Retro for PR #3569

Outcome: Merged in ~4h with two human approvals (robnester-rh, joejstuart) and no code changes after review. The workflow overall did what it was supposed to do.

Change under review: A 2-file, 4-line ubi-minimal base image digest bump on release-v0.8 (Dockerfile, Dockerfile.dist). PR body documents old/new digests, RPM version deltas, and links two Jira tickets (EC-2184, EC-2207) as authorization.

Review agent behavior (run 34989659020, $1.98, opus/high, 6 min):

  • Risk assessment correctly scored the change moderate 2/5 ("routine minor RPM update within the same tag").
  • Orchestrator nonetheless emitted a single high-severity [protected-path] finding whose only substantive complaint was governance ("no linked issue authorizing the change"), producing a CHANGES_REQUESTED verdict.
  • The intent-coherence sub-agent produced an info-level scope-authorization-implicit finding recognizing the change as mechanical; that evidence was filtered by REVIEW_FINDING_SEVERITY_THRESHOLD=low and did not survive to reconciliation.
  • Both human reviewers approved without addressing the protected-path remediation. The Jira refs in the PR body already satisfy the intent of the rule, but the skill only understands GitHub-native "linked issues."

Also observed: 3 of 8 sub-agent invocations initially failed with The model claude-sonnet-4-5@20250929 is not available on your vertex deployment; retries recovered.

No new proposals filed — every improvement this run points to is already tracked by an open issue. Filing more would create duplicate triage load per the retro-analysis skill's "Before proposing" guidance. Fresh evidence from this run, attached to the closest existing issues:

Suggested next action: revisit #718 first — it is the highest-leverage single change for this class of PR and would have prevented the false-positive here without any other refactoring.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

risk/moderate PR risk: moderate size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants