Skip to content

chore(deps): Update ubi-minimal base image (main) - #3570

Merged
simonbaird merged 1 commit into
conforma:mainfrom
simonbaird:ubi-bump-main
Sep 15, 2026
Merged

simonbaird merged 1 commit into
conforma:mainfrom
simonbaird:ubi-bump-main

Conversation

@simonbaird

@simonbaird simonbaird commented Sep 15, 2026 •

Copy link
Copy Markdown
Member

Update ubi-minimal base image to latest digest.

Old digest: sha256:7fbeae18dc9476399f565e68255f602a3374ea8614ba3d14843565131a13ff93
New digest: sha256:e5161a7d7d99cf22e4f34b72e111211a399d956d9b0e8714da18e9c4c8151041

RPM changes

- coreutils-single-8.32-41.el9_8.x86_64
+ coreutils-single-8.32-41.el9_8.1.x86_64
- glib2-2.68.4-19.el9_8.9.x86_64
+ glib2-2.68.4-19.el9_8.10.x86_64
- openssl-libs-3.5.5-6.el9_8.x86_64
+ openssl-libs-3.5.8-1.el9_8.x86_64

Ref: https://redhat.atlassian.net/browse/EC-2184
Ref: https://redhat.atlassian.net/browse/EC-2207

Old digest: sha256:7fbeae18dc9476399f565e68255f602a3374ea8614ba3d14843565131a13ff93
New digest: sha256:e5161a7d7d99cf22e4f34b72e111211a399d956d9b0e8714da18e9c4c8151041

RPM changes:

- coreutils-single-8.32-41.el9_8.x86_64
+ coreutils-single-8.32-41.el9_8.1.x86_64
- glib2-2.68.4-19.el9_8.9.x86_64
+ glib2-2.68.4-19.el9_8.10.x86_64
- openssl-libs-3.5.5-6.el9_8.x86_64
+ openssl-libs-3.5.8-1.el9_8.x86_64
@simonbaird
simonbaird requested a review from a team as a code owner September 15, 2026 15:37
@coderabbitai

coderabbitai Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Enterprise

Run ID: 61f0a8b9-e955-4b07-9b16-131a9d9cbfd9

📥 Commits

Reviewing files that changed from the base of the PR and between d377100 and 22ad101.

📒 Files selected for processing (3)
  • Dockerfile
  • Dockerfile.dist
  • acceptance/kubernetes/kind/acceptance.Dockerfile

Included review availability: Your plan provides up to 12 included reviews per hour; 11 remain after this review.


📝 Walkthrough

Walkthrough

The production, distribution, and Kubernetes acceptance Dockerfiles now use updated pinned UBI minimal image digests. No other Dockerfile behavior changed.

Changes

Container image updates

Layer / File(s) Summary
Pinned digest updates
Dockerfile, Dockerfile.dist, acceptance/kubernetes/kind/acceptance.Dockerfile
Updated the pinned UBI minimal base image digests. Installed packages, copied binaries, user configuration, entrypoints, and other build behavior remain unchanged.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Suggested reviewers: st3penta, acepresso

Merge Risk: ⚪ Minimal · up to 22ad1

The change only updates pinned base-image digests, with no reported behavior changes.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies the main change: updating the UBI minimal base image dependency.
Description check ✅ Passed The description explains the digest update, lists the RPM changes, and links related tickets. It does not use the template headings, but it provides the required change, context, and ticket informatio…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@qodo-for-conforma

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can reply 'qodo' on any finding to push back, ask questions, or dig deeper

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@qodo-for-conforma

Copy link
Copy Markdown

PR Summary by Qodo

Update UBI Minimal Base Image Digest

⚙️ Configuration changes 🕐 Less than 5 minutes

Grey Divider

AI Description

• Pins all runtime images to the latest UBI Minimal digest.
• Includes coreutils, GLib, and OpenSSL patch-level RPM updates.
Diagram

graph TD
  UBI["UBI Minimal"] --> PROD["Production Image"] & DIST["Distribution Image"] & ACCEPT["Acceptance Image"]
Loading
High-Level Assessment

Updating the immutable digest consistently across all dependent Dockerfiles is the optimal approach. Retaining digest pinning provides reproducible builds while incorporating the intended RPM security and patch updates; switching to an unpinned tag would weaken reproducibility.

Files changed (3) +3 / -3

Other (3) +3 / -3
DockerfileUpdate production UBI Minimal digest +1/-1

Update production UBI Minimal digest

• Pins the final production image to the new UBI 9 Minimal digest, incorporating updated coreutils, GLib, and OpenSSL packages.

Dockerfile

Dockerfile.distUpdate distribution UBI Minimal digest +1/-1

Update distribution UBI Minimal digest

• Aligns the distribution image with the new digest used by the primary production image.

Dockerfile.dist

acceptance.DockerfileUpdate acceptance-test UBI Minimal digest +1/-1

Update acceptance-test UBI Minimal digest

• Updates the Kubernetes acceptance-test container to the same UBI 9 Minimal base-image digest.

acceptance/kubernetes/kind/acceptance.Dockerfile

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:39 PM UTC · Completed 3:45 PM UTC

Commit: e8f0a9f · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $1.92

@fullsend-ai-review

Copy link
Copy Markdown

Review

This PR bumps the ubi9/ubi-minimal:latest digest across the three Dockerfiles. The digest change is consistent across all three files (same old digest → same new digest), the pin remains a well-formed 64-hex sha256: reference, and the PR body accurately describes the RPM-level delta (patch bumps to coreutils-single, glib2, and openssl-libs). The correctness, security, and style-conventions sub-agents returned no findings.

The change modifies files under a protected path (Dockerfile, Dockerfile.dist), which requires human approval per repository governance. Because there is no linked issue, the orchestrator raises a protected-path finding that must be resolved before merge.

Findings

High

  • [protected-path] Dockerfile — This PR modifies files that match the protected paths list (Dockerfile, Dockerfile.dist). No linked issue was provided to authorize the change. The PR description does explain the digest bump and includes an RPM diff (patch-level openssl-libs, glib2, coreutils-single updates), and the repository is Renovate-managed (renovate.json extends conforma/.github renovate config), which typically authorizes this pattern — but per protected-path policy, an explicit authorization signal (linked issue or ADR) is required.
    Remediation: Link the PR to a tracking issue (or reference the Renovate automation that generated it) so protected-path modifications carry explicit authorization. Human maintainer approval is required regardless of severity because governance/infrastructure files are being modified.

Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR

@fullsend-ai-review fullsend-ai-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See the review comment for full details.

@codecov

codecov Bot commented Sep 15, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Flag Coverage Δ
acceptance 54.51% <ø> (ø)
generative 12.25% <ø> (ø)
integration 23.56% <ø> (ø)
unit 72.24% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@cuipinghuo

Copy link
Copy Markdown
Contributor

LGTM

@robnester-rh robnester-rh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@simonbaird
simonbaird merged commit 83b9142 into conforma:main Sep 15, 2026
26 checks passed
@fullsend-ai-retro

fullsend-ai-retro Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 7:13 PM UTC · Completed 7:18 PM UTC

Commit: e8f0a9f · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $2.85

@fullsend-ai-retro

Copy link
Copy Markdown

PR #3570 is a routine, human-authored ubi-minimal base image digest bump (3 files, 6 lines) that Renovate would normally handle. The fullsend review agent issued CHANGES_REQUESTED with a single High [protected-path] finding: Dockerfile and Dockerfile.dist match the protected-paths list and no linked issue authorizes the change. The reasoning trace shows the agent explicitly read renovate.json and recognized this as a mechanical digest bump, but the 6e-1 finding-reconciliation pass never fired because no sub-agent volunteered a countering implicit-authorization finding citing Renovate. Two human maintainers (cuipinghuo, robnester-rh) approved and merged in ~2.5 hours; CI was fully green; codecov, CodeRabbit and Qodo all passed cleanly. Net outcome: the agent's finding was overridden with zero rework — a low-cost false positive, but a recurring one.

No new proposal filed — this scenario is heavily duplicative. The pattern (bot-shaped Dockerfile digest bump flagged [protected-path] and overridden) is already covered by an umbrella issue plus a large cluster of open refinements:

New retro evidence worth attaching to those threads: on run 34989736469 the agent did read renovate.json and did label the diff as mechanical, so the reconciliation machinery was one sub-agent finding away from working — an argument for making 6e-1 proactively query the Renovate/Dependabot manifest rather than waiting for a volunteer finding (relevant to #4387/#3239). Also: REVIEW_PROTECTED_PATHS uses bash prefix matching, so the entry Dockerfile matches Dockerfile.dist as intended — no matching bug, the false positive is purely a policy-scoping question already captured upstream. Filing another issue would add noise; leaving this evidence in the retro comment is sufficient.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants