Skip to content

chore(deps): update registry.access.redhat.com/ubi10/go-toolset docker digest to a7e505b - #6382

Merged
rh-hemartin merged 1 commit into
mainfrom
renovate/registry.access.redhat.com-ubi10-go-toolset
Aug 21, 2026
Merged

chore(deps): update registry.access.redhat.com/ubi10/go-toolset docker digest to a7e505b#6382
rh-hemartin merged 1 commit into
mainfrom
renovate/registry.access.redhat.com-ubi10-go-toolset

Conversation

@renovate-fullsend

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
registry.access.redhat.com/ubi10/go-toolset stage digest 26d2558a7e505b

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@renovate-fullsend
renovate-fullsend Bot requested a review from a team as a code owner August 19, 2026 15:21
@fullsend-ai-review

fullsend-ai-review Bot commented Aug 19, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:23 PM UTC · Completed 3:29 PM UTC

Commit: 72cee58 · View workflow run →

@codecov

codecov Bot commented Aug 19, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@fullsend-ai-review

Copy link
Copy Markdown

Review

Findings

High

  • [protected-path] images/runner/Containerfile — This PR modifies images/runner/Containerfile, which is under the protected path images/. The PR has no linked issue providing authorization for modifying governance or infrastructure files. Human approval is required for protected-path changes.

Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR

@fullsend-ai-review fullsend-ai-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See the review comment for full details.

Comment thread images/runner/Containerfile
@rh-hemartin
rh-hemartin added this pull request to the merge queue Aug 21, 2026
Merged via the queue into main with commit 039ecd8 Aug 21, 2026
26 checks passed
@rh-hemartin
rh-hemartin deleted the renovate/registry.access.redhat.com-ubi10-go-toolset branch August 21, 2026 08:28
@fullsend-ai-retro

fullsend-ai-retro Bot commented Aug 21, 2026

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 8:30 AM UTC · Completed 8:42 AM UTC

Commit: 72cee58 · View workflow run →

@fullsend-ai-retro

Copy link
Copy Markdown

Retro: PR #6382 — Renovate Docker digest bump flagged by protected-path rule

What happened

PR #6382 was a 1-line Renovate bot PR updating the ubi10/go-toolset Docker image digest in images/runner/Containerfile. The review agent (run #32269579280) ran for ~8 minutes using Opus, consumed ~$0.93 in API costs (509K cached input tokens, 11.5K output tokens), and flagged a [high] protected-path finding because the file is under images/. It submitted CHANGES_REQUESTED, blocking merge.

The CHANGES_REQUESTED event triggered a fix agent dispatch (run #32270394186), which correctly bailed out after ~8 seconds when the eligibility check detected a bot author without the fullsend-fix label — no LLM costs incurred.

Human reviewer rh-hemartin approved ~41 hours later and merged the PR.

Assessment

The protected-path finding is a false positive. Renovate is a trusted bot performing a configured, expected digest bump. The finding provided zero signal — the human overrode it without comment.

Severity escalation trend: This finding was rated [high] with CHANGES_REQUESTED. Older Renovate digest PRs in this repo (#6021, #6047, #6131) received [medium] with COMMENTED. The more recent PRs (#6309, #6382) escalated to [high] / CHANGES_REQUESTED, making the false positive actively block merge rather than just informing. PR #6079 (a claude-code update touching images/sandbox/Containerfile) received the same finding 11 times with CHANGES_REQUESTED.

No new proposals — existing issues cover this

This problem is extensively covered by open issues. Filing new proposals would duplicate existing work:

  • #4387 — Allow conditional protected-path exceptions for trusted bot version-only dependency bumps. This is the primary tracker with the most linked evidence. PR chore(deps): update registry.access.redhat.com/ubi10/go-toolset docker digest to a7e505b #6382 adds another data point: $0.93 spent reviewing a 1-line hash change, 41-hour merge delay.
  • #3061 — Reduce protected-path severity for digest-only Dockerfile changes from trusted bots. Directly applicable to this PR's FROM-line digest update.
  • #5369 — Use COMMENT instead of CHANGES_REQUESTED for governance-only findings on bot PRs. Covers the severity escalation observed here (older PRs got COMMENTED, newer ones get CHANGES_REQUESTED).
  • fullsend-ai/agents#257 — Add pre-review early exit for bot-authored dependency-update PRs. Would avoid the $0.93 API cost entirely.
  • #4293 / #2639 — Fast-path bot-authored dependency PRs. Would reduce both cost and latency.

Agents repo

Discovered from run #32269579280: fullsend-ai/agents at commit 816b89be.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant