Update Konflux references - #2
Open
konflux-staging[bot] wants to merge 1 commit into
Open
Conversation
Author
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
from
February 15, 2025 08:04
7d32db8 to
e07757f
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
from
February 22, 2025 08:08
e07757f to
c56ecfb
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
2 times, most recently
from
March 8, 2025 08:04
12693c6 to
6868602
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
2 times, most recently
from
March 22, 2025 08:11
6f619b3 to
a71c88a
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
from
March 29, 2025 08:10
a71c88a to
e998d15
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
2 times, most recently
from
April 12, 2025 08:11
b896f78 to
4136f2e
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
2 times, most recently
from
April 26, 2025 08:08
43b5d7c to
dbec8d0
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
2 times, most recently
from
May 10, 2025 08:04
f92745f to
7d96ae1
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
from
May 17, 2025 08:10
7d96ae1 to
76f4a8c
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
2 times, most recently
from
May 31, 2025 08:13
447505a to
8091087
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
from
June 7, 2025 08:22
8091087 to
92e4a79
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
from
July 12, 2025 08:09
92e4a79 to
b4624ab
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
from
July 19, 2025 12:10
b4624ab to
5583e43
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
from
August 9, 2025 08:12
5583e43 to
716ffe5
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
from
September 6, 2025 08:07
716ffe5 to
bdb6d45
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
2 times, most recently
from
September 13, 2025 12:13
76e6162 to
2768ec1
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
6 times, most recently
from
September 25, 2025 04:18
7f330f7 to
49bbc61
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
2 times, most recently
from
October 25, 2025 20:22
04b9a90 to
2188c57
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
2 times, most recently
from
November 8, 2025 08:25
919690b to
1de29b2
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
2 times, most recently
from
November 8, 2025 20:24
a2b3697 to
e2312cf
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
from
November 15, 2025 16:34
e2312cf to
27dc019
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
2 times, most recently
from
December 13, 2025 20:24
27f25ff to
2c6b28a
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
from
December 20, 2025 20:21
2c6b28a to
c375ca0
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
from
January 3, 2026 16:21
c375ca0 to
57c9681
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
2 times, most recently
from
January 10, 2026 20:22
6a75c09 to
6385ac5
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
3 times, most recently
from
January 24, 2026 08:23
9f05ed5 to
0fece2a
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
2 times, most recently
from
January 31, 2026 20:23
597bda7 to
e0af56f
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
2 times, most recently
from
February 14, 2026 08:20
5ff8aaa to
c0dd7b9
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
from
February 21, 2026 08:13
c0dd7b9 to
2036e16
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
from
February 28, 2026 12:14
2036e16 to
d5b6fe7
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
2 times, most recently
from
March 14, 2026 12:28
0bf27ba to
7ed61e7
Compare
konflux-staging
Bot
force-pushed
the
konflux/references/main
branch
from
May 2, 2026 08:20
7ed61e7 to
a996c4c
Compare
Signed-off-by: konflux-staging <124796549+konflux-staging[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.1→0.30.1→0.3.10.2→0.12.00.2→0.4.10.1→0.3.20.4→0.50.1→0.20.1→0.2.60.2→0.4.30.1→0.10.10.1→0.3.10.2→0.2.20.2→0.50.1→0.30.1→0.3Warning
Some dependencies could not be looked up. Check the warning logs for more information.
Release Notes
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-apply-tags)
v0.30.1and0.2versions.konflux-ci/build-pipeline-tasks (quay.io/konflux-ci/tekton-catalog/task-build-image-index)
v0.3.1Fixed
SBOM_SKIP_VALIDATIONinto the step environment so the create-sbom step honors the parameter.The parameter did nothing before. Now it works as expected.
v0.3Fixed
SBOM_SKIP_VALIDATIONinto the step environment so the create-sbom step honors the parameter.The parameter did nothing before. Now it works as expected.
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-buildah-oci-ta)
v0.12.0Changed
CONTEXTUALIZE_SBOMis now set tofalseby default. The SBOMcontextualization received an overhaul, enabling the support for builder
content contextualization in SBOMs. To get involved in UAT, set this value
to
trueand report issuesto Mobster maintainers.
CONTEXTUALIZE_SBOMis set totrue, the built image will containnew labels,
io.buildah.stage.nameandio.buildah.stage.base.v0.11.2Fixed
include the
x86_64RPMs (and no other arches) from the prefetch SBOM,even for images built on other arches.
v0.11.1Version 0.11.1 only has relevant changes for the remote variants of this task.
v0.11.0Changed
a directory instead of scanning the the image as an OCI archive. This improves
the scanning time, disk usage and may improve memory usage. More details in
konflux-build-cli/docs/design/syft-image-scanning.md.
from the build VM instead of rsyncing the image back to the cluster first.
For large images, this significantly reduces the time spent on network transfers.
Removed
sbom-syft-generatestep, SBOM generation now happensin the
buildstep.pushstep, the push now happens in thebuildstep.the pipeline will fail with
invalid StepOverride. See the migration guidance below.Migration guidance
Buildah v0.11.0 comes with a migration script that will attempt to automatically
fix the step overrides in your PipelineRuns. In most cases, no manual action will
be needed. But there are cases that the script cannot handle:
script will never get a chance to run on the PipelineRun.
than the build itself and the remote VMs do not have sufficient resources.
If the migration script doesn't solve the problem, please follow the procedure below.
Manual procedure
If you have
sbom-syft-generateorpushstep overrides in the.spec.taskRunSpecssection in your PipelineRun, please remove them. In most cases, this should be all.
However, if you were previously requesting more resources for SBOM generation
than for the build step itself, there is a chance that the build will fail.
In this case, move the relevant overrides to the build step. The same technically
applies for the push step, but it's highly unlikely that pushing would require
more resources than the build.
For example:
spec: taskRunSpecs: - pipelineTaskName: build-container stepSpecs: - - name: sbom-syft-generate + - name: build computeResources: requests: memory: 16Gi limits: memory: 16GiThis will work for build steps that run in-cluster - single-platform builds
and typically also the amd64 builds in a multi-platform build setup.
For build steps that run on remote VMs, the overrides have no effect. In case
the build fails, please switch to a larger VM flavor (consult the documentation
of your particular Konflux deployment to see what's available).
For example:
spec: params: - name: build-platforms value: - localhost - - linux/arm64 + - linux-mxlarge/arm64v0.10.7Fixed
ignore files, same as buildah itself.
.containerignoreand.dockerignorefilesin the root of the context directory, but not the
<containerfile>.containerignoreand
<containerfile>.dockerignorefiles.v0.10.6Fixed
versions 0.10.4 and 0.10.5, when the upload-sbom step upgraded cosign to v3.
service URLs directly as CLI flags. The konflux-ci/konflux-ci deployment
of Konflux doesn't provide the config file in the TUF mirror. Fixed
by setting
--use-signing-config=falseto still allow direct URLs.Changed
Previously, if keyless signing was enabled, the task would sign the image
in the push step and then the SBOM in upload-sbom step. Now, it will sign both
in the upload-sbom step. This has no practical impact, but enables a larger
rework of the push step in the future.
v0.10.5Added
--rhsm-mount-ca-certsoption.v0.10Fixed
ignore files, same as buildah itself.
.containerignoreand.dockerignorefilesin the root of the context directory, but not the
<containerfile>.containerignoreand
<containerfile>.dockerignorefiles.v0.9Fixed
doesn't match the host architecture, preventing silent emulation builds.
v0.8Fixed
for ARM architectures (e.g.,
linux/arm/v7orlinux/arm64/v8instead of justlinux/armor
linux/arm64).v0.7Fixed
ignore files, same as buildah itself.
.containerignoreand.dockerignorefilesin the root of the context directory, but not the
<containerfile>.containerignoreand
<containerfile>.dockerignorefiles.v0.6Fixed
versions 0.10.4 and 0.10.5, when the upload-sbom step upgraded cosign to v3.
service URLs directly as CLI flags. The konflux-ci/konflux-ci deployment
of Konflux doesn't provide the config file in the TUF mirror. Fixed
by setting
--use-signing-config=falseto still allow direct URLs.Changed
Previously, if keyless signing was enabled, the task would sign the image
in the push step and then the SBOM in upload-sbom step. Now, it will sign both
in the upload-sbom step. This has no practical impact, but enables a larger
rework of the push step in the future.
v0.5Added
--rhsm-mount-ca-certsoption.v0.4Fixed
/cachi2/cachi2.envmount that version 0.10.3 removed.Despite being an undocumented implementation detail, some builds use
the presence of this file as an indicator that the build is hermetic.
Enable them to do so for the time being.
v0.3Added
which don't match build host architecture.
Changed
in order to set the prefetch environment variables. Instead, sets the variables
using buildah
--mount+--secretflags. Details in konflux-build-cli#151.Fixes [#1200].
/cachi2/cachi2.envfile,whose only purpose was to enable the automatic setting of prefetch variables.
konflux-ci/konflux-test-tasks (quay.io/konflux-ci/tekton-catalog/task-clair-scan)
v0.4.1Changed
Allign script and task version.
v0.4Changed
Allign script and task version.
v0.3.2Changed
quay.io/konflux-ci/oras:latestimage withquay.io/konflux-ci/task-runner:1.5.0in the oci-attach-report step.Added
v0.3.1Added
v0.3Changed
quay.io/konflux-ci/oras:latestimage withquay.io/konflux-ci/task-runner:1.5.0in the oci-attach-report step.Added
konflux-ci/konflux-test-tasks (quay.io/konflux-ci/tekton-catalog/task-clamav-scan)
v0.3.2Added
(
.safetensors,.gguf,.ggml). Other layers are still extracted andscanned. If layer listing fails, the task falls back to extracting the
full image.
v0.3Changed
model-weight files (
.safetensors,.gguf,.ggml,.pt,.pth,.onnx,.onnx_data/.onnx_data_*), usingorg.opencontainers.image.titleandolot.layer.content.inlayerpath. Any other annotated layer is skipped whenthe OCI descriptor
sizeis at least 2000MiB (slightly under ClamAV's ~2GiBMaxFileSize), regardless of extension. Layers without those annotations are
still listed with
--dry-runas in 0.3.2. The--dry-runskip uses thesame name list.
v0.2Changed
konflux-ci/konflux-test-tasks (quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check)
v0.5Added
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta)
v0.10.1Changed
inputis empty, only run theskip-tastep and skip other stepsquay.io/konflux-ci/task-runnerfor theskip-tastep instead ofubi-minimalv0.10.0v0.9.0Added
pip-index-urlparameter to passPIP_INDEX_URLto Hermeto for pip dependency prefetch.When set, this URL is used as a fallback package index when
requirements.txtdoes not specify--index-url.To use this parameter, add
pip-index-url(type: string, default:"") to your pipeline paramsand pass it to the prefetch-dependencies task.
v0.8.0v0.7.1v0.7.0.repofile for RPM dependencies is now namedhermeto.repoinstead ofcachi2.repov0.6.0v0.5.0v0.4.1Fixed
trusted-cavolume in theuse-trusted-artifactandcreate-trusted-artifactsteps.Previously, the mount was missing, which means the task did not support container registries
with certificates signed by a private/self-signed CA.
v0.4.0v0.3.2enable-package-registry-proxyparameter to enable use of the package registry proxy when prefetching dependencies.SERVICE_CA_TRUST_CONFIG_MAP_NAMEandSERVICE_CA_TRUST_CONFIG_MAP_KEYparameters to mount the OpenShift service CA for verifying TLS connections to in-cluster services such as the package registry proxy.v0.3enable-package-registry-proxyparameter to enable use of the package registry proxy when prefetching dependencies.SERVICE_CA_TRUST_CONFIG_MAP_NAMEandSERVICE_CA_TRUST_CONFIG_MAP_KEYparameters to mount the OpenShift service CA for verifying TLS connections to in-cluster services such as the package registry proxy.v0.2konflux-ci/build-definitions (quay.io/konflux-ci/tekton-catalog/task-show-sbom)
v0.3Fixed
The migration script wasn't attached to the task bundle.
v0.2Removed
The task
show-sbomis deprecated. The migration script deletes it from the pipeline.konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta)
v0.3Added
BREAKING: new required parameter:
BINARY_IMAGE_DIGEST.For pipelines that include the
build-image-indextask, pass its result to this param:For those that don't, pass the result from the
build-containertask instead:Note: the MintMaker PR updating source-build to v0.3 should apply these changes automatically.
Started tracking changes in this file.
Configuration
📅 Schedule: (UTC)
* 5-23 * * 6)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.