Skip to content

chore(deps): refresh rpm lockfiles [SECURITY] - #333

Open
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/lock-file-maintenance-vulnerability
Open

chore(deps): refresh rpm lockfiles [SECURITY]#333
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented May 20, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/lock-file-maintenance-vulnerability branch 3 times, most recently from 2482f5c to 27543e3 Compare June 19, 2026 13:34
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/lock-file-maintenance-vulnerability branch 2 times, most recently from 1e13d34 to cf65ed6 Compare June 23, 2026 17:21
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] Refresh RPM lockfiles [SECURITY] Jun 25, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/lock-file-maintenance-vulnerability branch 5 times, most recently from 7e59e15 to 3f47383 Compare July 2, 2026 13:53
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/lock-file-maintenance-vulnerability branch 4 times, most recently from e5ad7ff to f285d9f Compare July 9, 2026 21:46
@red-hat-konflux red-hat-konflux Bot changed the title Refresh RPM lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] Jul 9, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/lock-file-maintenance-vulnerability branch 3 times, most recently from c532c4b to f37aa14 Compare July 10, 2026 17:37
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/lock-file-maintenance-vulnerability branch 2 times, most recently from e0f97ba to 1e575e0 Compare July 17, 2026 17:43
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/lock-file-maintenance-vulnerability branch from 1e575e0 to 4a050e0 Compare August 11, 2026 02:12
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/lock-file-maintenance-vulnerability branch from 4a050e0 to 1df2544 Compare August 26, 2026 02:37
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/lock-file-maintenance-vulnerability branch from 1df2544 to 3ede6cb Compare September 3, 2026 01:19
@coderabbitai

coderabbitai Bot commented Sep 3, 2026

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: f6009e47-589b-4adb-9339-bd374267347f

📥 Commits

Reviewing files that changed from the base of the PR and between 131de96 and 3ede6cb.

📒 Files selected for processing (1)
  • must-gather/rpms.lock.yaml

Included review availability: Your plan provides up to 12 included reviews per hour; 11 remain after this review.


Walkthrough

The RPM lockfile updates rsync and tar entries from EL9.7 to EL9.8 for s390x and x86_64, including package metadata and source RPM references.

Changes

RPM lockfile refresh

Layer / File(s) Summary
Update architecture-specific RPM locks
must-gather/rpms.lock.yaml
Updated binary and source RPM URLs, versions, sizes, checksums, and source RPM references for rsync and tar on s390x and x86_64.

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to 80804

This updates the locked rsync and tar builds to EL9.8 while retaining package coverage and verified artifact references for both architectures. The refresh is ready to merge with no identified release risk.

🚥 Pre-merge checks | ✅ 15
✅ Passed checks (15 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the dependency lockfile refresh and identifies its security purpose. It matches the main changes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed PASS. The pull request changes only must-gather/rpms.lock.yaml. The diff updates RPM URLs, versions, sizes, checksums, and source RPM metadata. It adds no Ginkgo test declarations or test titles, so…
Test Structure And Quality ✅ Passed PASS: The pull request changes only must-gather/rpms.lock.yaml. The exact diff updates RPM URLs, versions, sizes, checksums, and source RPM metadata for rsync and tar; it adds no Ginkgo tests or…
Microshift Test Compatibility ✅ Passed PASS: The pull request changes only must-gather/rpms.lock.yaml (36 additions, 36 deletions). The diff adds no Ginkgo tests or test files, so the MicroShift API and feature compatibility check does…
Single Node Openshift (Sno) Test Compatibility ✅ Passed PASS. The pull request changes only must-gather/rpms.lock.yaml. The diff updates RPM URLs, versions, sizes, checksums, and source RPM metadata for rsync and tar; it adds no Ginkgo e2e tests or o…
Topology-Aware Scheduling Compatibility ✅ Passed PASS. The PR changes only must-gather/rpms.lock.yaml, as shown by the complete diff against origin/main. The changes update RPM URLs, versions, sizes, checksums, and source RPM metadata for `rsync…
Ote Binary Stdout Contract ✅ Passed PASS. The pull request changes only must-gather/rpms.lock.yaml, with RPM URLs, versions, sizes, checksums, and source RPM metadata for rsync and tar. The diff contains no process-level code or s…
Ipv6 And Disconnected Network Test Compatibility ✅ Passed PASS: The pull request changes only must-gather/rpms.lock.yaml. The parent-to-HEAD diff contains no Ginkgo tests or test-like files. The changed file contains RPM metadata and package URLs, not exec…
No-Weak-Crypto ✅ Passed PASS. The pull request changes only must-gather/rpms.lock.yaml. The diff updates RPM URLs, versions, sizes, source RPM names, and SHA-256 checksums for rsync and tar. No MD5, SHA-1, DES, 3DES, R…
Container-Privileges ✅ Passed PASS. The PR changes only must-gather/rpms.lock.yaml, and the base-to-head diff contains only RPM URLs, versions, sizes, checksums, and source RPM metadata for rsync and tar. The changed file ha…
No-Sensitive-Data-In-Logs ✅ Passed PASS: The pull request changes only must-gather/rpms.lock.yaml (36 additions and 36 removals). The changes contain public Red Hat CDN URLs, package versions, sizes, and SHA-256 checksums. No logging…
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.)

Full details: Stable And Deterministic Test Names

Explanation

PASS. The pull request changes only must-gather/rpms.lock.yaml. The diff updates RPM URLs, versions, sizes, checksums, and source RPM metadata. It adds no Ginkgo test declarations or test titles, so it introduces no dynamic or overly specific test name.

Full details: Test Structure And Quality

Explanation

PASS: The pull request changes only must-gather/rpms.lock.yaml. The exact diff updates RPM URLs, versions, sizes, checksums, and source RPM metadata for rsync and tar; it adds no Ginkgo tests or test operations. Therefore, the listed test-structure requirements are not applicable, and no failure condition was introduced.

Full details: Microshift Test Compatibility

Explanation

PASS: The pull request changes only must-gather/rpms.lock.yaml (36 additions, 36 deletions). The diff adds no Ginkgo tests or test files, so the MicroShift API and feature compatibility check does not apply.

Full details: Single Node Openshift (Sno) Test Compatibility

Explanation

PASS. The pull request changes only must-gather/rpms.lock.yaml. The diff updates RPM URLs, versions, sizes, checksums, and source RPM metadata for rsync and tar; it adds no Ginkgo e2e tests or other test declarations. Therefore, the SNO multi-node compatibility check is not applicable.

Full details: Topology-Aware Scheduling Compatibility

Explanation

PASS. The PR changes only must-gather/rpms.lock.yaml, as shown by the complete diff against origin/main. The changes update RPM URLs, versions, sizes, checksums, and source RPM metadata for rsync and tar. They add no deployment manifests, operator code, controllers, or scheduling keys. The topology-aware scheduling check is therefore not applicable.

Full details: Ote Binary Stdout Contract

Explanation

PASS. The pull request changes only must-gather/rpms.lock.yaml, with RPM URLs, versions, sizes, checksums, and source RPM metadata for rsync and tar. The diff contains no process-level code or stdout writes. No OTE binary behavior is changed.

Full details: Ipv6 And Disconnected Network Test Compatibility

Explanation

PASS: The pull request changes only must-gather/rpms.lock.yaml. The parent-to-HEAD diff contains no Ginkgo tests or test-like files. The changed file contains RPM metadata and package URLs, not executable tests or test connectivity logic. Therefore, no IPv4 assumption or external-connectivity requirement was introduced under this check.

Full details: No-Weak-Crypto

Explanation

PASS. The pull request changes only must-gather/rpms.lock.yaml. The diff updates RPM URLs, versions, sizes, source RPM names, and SHA-256 checksums for rsync and tar. No MD5, SHA-1, DES, 3DES, RC4, Blowfish, ECB mode, custom crypto implementation, or secret comparison was introduced.

Full details: Container-Privileges

Explanation

PASS. The PR changes only must-gather/rpms.lock.yaml, and the base-to-head diff contains only RPM URLs, versions, sizes, checksums, and source RPM metadata for rsync and tar. The changed file has no Kubernetes workload markers or privilege settings. No changed line introduces privileged: true, hostPID, hostNetwork, hostIPC, SYS_ADMIN, root execution, or allowPrivilegeEscalation: true.

Full details: No-Sensitive-Data-In-Logs

Explanation

PASS: The pull request changes only must-gather/rpms.lock.yaml (36 additions and 36 removals). The changes contain public Red Hat CDN URLs, package versions, sizes, and SHA-256 checksums. No logging code or sensitive data indicators appear in the changed file.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch konflux/mintmaker/main/lock-file-maintenance-vulnerability

Comment @coderabbitai help to get the list of available commands.

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/lock-file-maintenance-vulnerability branch from 3ede6cb to e81df11 Compare September 4, 2026 02:58
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/lock-file-maintenance-vulnerability branch from e81df11 to 8080456 Compare September 8, 2026 03:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants