Skip to content

CNTRLPLANE-2568: Update Konflux Tekton tasks to latest versions - #7551

Merged
openshift-merge-bot[bot] merged 1 commit into
openshift:mainfrom
jparrill:update-konflux-task
Jan 20, 2026
Merged

CNTRLPLANE-2568: Update Konflux Tekton tasks to latest versions#7551
openshift-merge-bot[bot] merged 1 commit into
openshift:mainfrom
jparrill:update-konflux-task

Conversation

@jparrill

@jparrill jparrill commented Jan 20, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Resolved merge conflicts in Konflux Tekton task updates
  • Accepted upstream changes with newer task digest values
  • Ensured all tasks are using the latest trusted versions

Task Updates

The following tasks were updated with newer upstream digests:

  • prefetch-dependencies-oci-ta: 0.2@8eac535f...
  • ecosystem-cert-preflight-checks: 0.2@04f75593...
  • clamav-scan: 0.3@f3d2d179...
  • rpms-signature-scan: 0.2@20eb21c6...

Additional upstream task updates included:

  • buildah-remote-oci-ta: 0.7@fe66734c...
  • deprecated-image-check: 0.5@808fe09b...
  • sast-snyk-check-oci-ta: 0.4@0eca130f...
  • coverity-availability-check: 0.2@36400873...
  • sast-shell-check-oci-ta: 0.1@d44336d7...
  • sast-unicode-check-oci-ta: 0.3@e5a8d3e8...
  • apply-tags: 0.2@c89cd10b...

Fixes

Test plan

  • Verify builds complete successfully with updated task versions
  • Confirm enterprise contract verification passes
  • Check that all security scans execute properly

🤖 Generated with Claude Code

@openshift-ci-robot

openshift-ci-robot commented Jan 20, 2026

Copy link
Copy Markdown

@jparrill: This pull request references CNTRLPLANE-2568 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "4.22.0" version, but no target version was set.

Details

In response to this:

Summary

  • Resolved merge conflicts in Konflux Tekton task updates
  • Accepted upstream changes with newer task digest values
  • Ensured all tasks are using the latest trusted versions

Task Updates

The following tasks were updated with newer upstream digests:

  • prefetch-dependencies-oci-ta: 0.2@8eac535f...
  • ecosystem-cert-preflight-checks: 0.2@04f75593...
  • clamav-scan: 0.3@f3d2d179...
  • rpms-signature-scan: 0.2@20eb21c6...

Additional upstream task updates included:

  • buildah-remote-oci-ta: 0.7@fe66734c...
  • deprecated-image-check: 0.5@808fe09b...
  • sast-snyk-check-oci-ta: 0.4@0eca130f...
  • coverity-availability-check: 0.2@36400873...
  • sast-shell-check-oci-ta: 0.1@d44336d7...
  • sast-unicode-check-oci-ta: 0.3@e5a8d3e8...
  • apply-tags: 0.2@c89cd10b...

Fixed

Test plan

  • Verify builds complete successfully with updated task versions
  • Confirm enterprise contract verification passes
  • Check that all security scans execute properly

🤖 Generated with Claude Code

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Jan 20, 2026
@openshift-ci-robot

openshift-ci-robot commented Jan 20, 2026

Copy link
Copy Markdown

@jparrill: This pull request references CNTRLPLANE-2568 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "4.22.0" version, but no target version was set.

Details

In response to this:

Summary

  • Resolved merge conflicts in Konflux Tekton task updates
  • Accepted upstream changes with newer task digest values
  • Ensured all tasks are using the latest trusted versions

Task Updates

The following tasks were updated with newer upstream digests:

  • prefetch-dependencies-oci-ta: 0.2@8eac535f...
  • ecosystem-cert-preflight-checks: 0.2@04f75593...
  • clamav-scan: 0.3@f3d2d179...
  • rpms-signature-scan: 0.2@20eb21c6...

Additional upstream task updates included:

  • buildah-remote-oci-ta: 0.7@fe66734c...
  • deprecated-image-check: 0.5@808fe09b...
  • sast-snyk-check-oci-ta: 0.4@0eca130f...
  • coverity-availability-check: 0.2@36400873...
  • sast-shell-check-oci-ta: 0.1@d44336d7...
  • sast-unicode-check-oci-ta: 0.3@e5a8d3e8...
  • apply-tags: 0.2@c89cd10b...

Fixed

Test plan

  • Verify builds complete successfully with updated task versions
  • Confirm enterprise contract verification passes
  • Check that all security scans execute properly

🤖 Generated with Claude Code

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci-robot

openshift-ci-robot commented Jan 20, 2026

Copy link
Copy Markdown

@jparrill: This pull request references CNTRLPLANE-2568 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "4.22.0" version, but no target version was set.

Details

In response to this:

Summary

  • Resolved merge conflicts in Konflux Tekton task updates
  • Accepted upstream changes with newer task digest values
  • Ensured all tasks are using the latest trusted versions

Task Updates

The following tasks were updated with newer upstream digests:

  • prefetch-dependencies-oci-ta: 0.2@8eac535f...
  • ecosystem-cert-preflight-checks: 0.2@04f75593...
  • clamav-scan: 0.3@f3d2d179...
  • rpms-signature-scan: 0.2@20eb21c6...

Additional upstream task updates included:

  • buildah-remote-oci-ta: 0.7@fe66734c...
  • deprecated-image-check: 0.5@808fe09b...
  • sast-snyk-check-oci-ta: 0.4@0eca130f...
  • coverity-availability-check: 0.2@36400873...
  • sast-shell-check-oci-ta: 0.1@d44336d7...
  • sast-unicode-check-oci-ta: 0.3@e5a8d3e8...
  • apply-tags: 0.2@c89cd10b...

Fixes

Test plan

  • Verify builds complete successfully with updated task versions
  • Confirm enterprise contract verification passes
  • Check that all security scans execute properly

🤖 Generated with Claude Code

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai

coderabbitai Bot commented Jan 20, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

Updated Tekton task bundle image references across four .tekton YAMLs: multiple bundle SHA256 digests were replaced and one rpms-signature-scan bundle path changed from konflux-vanguard to tekton-catalog. No task names, parameters, control flow, or other definitions were modified. A few lines show a formatting anomaly (extra space before a sha256 digest).

Changes

Cohort / File(s) Summary
Common operator build pipeline
​.tekton/pipelines/common-operator-build.yaml
Updated bundle image digests for multiple tasks (e.g., prefetch-dependencies-oci-ta:0.2, buildah-remote-oci-ta:0.7, build-image-index:0.2, clair-scan:0.3, ecosystem-cert-preflight-checks:0.2, clamav-scan:0.3, rpms-signature-scan:0.2). Only bundle references changed.
Hypershift webhook & operator pipelines
​.tekton/hypershift-gomaxprocs-webhook-pull-request.yaml, ​.tekton/hypershift-gomaxprocs-webhook-push.yaml, ​.tekton/hypershift-operator-main-tag.yaml
Replaced SHA256 digests for prefetch-dependencies-oci-ta:0.2, clair-scan:0.3, ecosystem-cert-preflight-checks:0.2, clamav-scan:0.3, and rpms-signature-scan:0.2. rpms-signature-scan registry/path changed from konflux-vanguard to tekton-catalog. Some occurrences show an extra space before a sha256 digest. No other fields altered.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes


Comment @coderabbitai help to get the list of available commands and usage tips.

@jparrill

Copy link
Copy Markdown
Contributor Author

/auto-cc

@openshift-ci-robot

openshift-ci-robot commented Jan 20, 2026

Copy link
Copy Markdown

@jparrill: This pull request references CNTRLPLANE-2568 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "4.22.0" version, but no target version was set.

Details

In response to this:

Summary

  • Resolved merge conflicts in Konflux Tekton task updates
  • Accepted upstream changes with newer task digest values
  • Ensured all tasks are using the latest trusted versions

Task Updates

The following tasks were updated with newer upstream digests:

  • prefetch-dependencies-oci-ta: 0.2@8eac535f...
  • ecosystem-cert-preflight-checks: 0.2@04f75593...
  • clamav-scan: 0.3@f3d2d179...
  • rpms-signature-scan: 0.2@20eb21c6...

Additional upstream task updates included:

  • buildah-remote-oci-ta: 0.7@fe66734c...
  • deprecated-image-check: 0.5@808fe09b...
  • sast-snyk-check-oci-ta: 0.4@0eca130f...
  • coverity-availability-check: 0.2@36400873...
  • sast-shell-check-oci-ta: 0.1@d44336d7...
  • sast-unicode-check-oci-ta: 0.3@e5a8d3e8...
  • apply-tags: 0.2@c89cd10b...

Fixes

Test plan

  • Verify builds complete successfully with updated task versions
  • Confirm enterprise contract verification passes
  • Check that all security scans execute properly

🤖 Generated with Claude Code

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci
openshift-ci Bot requested review from csrwng and muraee January 20, 2026 11:57
@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jan 20, 2026
@openshift-ci
openshift-ci Bot requested review from bryan-cox and enxebre January 20, 2026 11:57
@jparrill

Copy link
Copy Markdown
Contributor Author

/hold

@openshift-ci openshift-ci Bot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Jan 20, 2026
@jparrill

Copy link
Copy Markdown
Contributor Author

/hold cancel

@openshift-ci openshift-ci Bot removed the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Jan 20, 2026
@jparrill
jparrill force-pushed the update-konflux-task branch from fc7014e to c36063a Compare January 20, 2026 14:29
@openshift-merge-robot openshift-merge-robot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Jan 20, 2026
@jparrill
jparrill force-pushed the update-konflux-task branch from c36063a to d4d7e4a Compare January 20, 2026 14:45
@openshift-merge-robot openshift-merge-robot removed the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Jan 20, 2026
@jparrill
jparrill force-pushed the update-konflux-task branch from d4d7e4a to 9acd3f1 Compare January 20, 2026 15:10
@jparrill

Copy link
Copy Markdown
Contributor Author

/area ci-tooling

@openshift-ci openshift-ci Bot added area/ci-tooling Indicates the PR includes changes for CI or tooling and removed do-not-merge/needs-area labels Jan 20, 2026
@jparrill
jparrill force-pushed the update-konflux-task branch from 9acd3f1 to cf1fd35 Compare January 20, 2026 15:42
@red-hat-konflux

Copy link
Copy Markdown
Contributor

Caution

There are some errors in your PipelineRun template.

PipelineRun Error
hypershift-gomaxprocs-webhook-pull-request.yaml yaml validation error: line 359: mapping values are not allowed in this context

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Fix all issues with AI agents
In @.tekton/hypershift-gomaxprocs-webhook-pull-request.yaml:
- Around line 358-360: The env entry named "bundle" has an extra space after
"sha256:" in its value which breaks YAML parsing; edit the "bundle" env value
(the string assigned to the value key) to remove the space so the digest
immediately follows "sha256:" (i.e., change "@sha256: 654b..." to
"@sha256:654b...") ensuring the value becomes a single continuous token.

In @.tekton/hypershift-gomaxprocs-webhook-push.yaml:
- Around line 355-357: The YAML value for the environment variable `bundle`
contains an extra space after `sha256:` which breaks parsing; update the `value`
string for the `bundle` entry (the line with "name: bundle" / `value:
quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256: 654b989d...`) to
remove the space immediately after `sha256:` so the digest is contiguous with
`sha256:` (i.e., `...@sha256:<digest>`).

In @.tekton/hypershift-operator-main-tag.yaml:
- Around line 367-369: The YAML value for the env var named "bundle" contains an
invalid space after "sha256:" in the string
"quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:
654b989d7cdc03d082e56f216a29de04847215ee379a8d9ca315e453ad2b15c2"; remove the
extra space so the digest immediately follows the colon (i.e.,
"…@sha256:654b989...") to produce a valid YAML scalar for the bundle value.

In @.tekton/pipelines/common-operator-build.yaml:
- Around line 259-261: The bundle image value has an invalid space after
"sha256:" causing YAML parsing errors; update the value under the mapping with
"name: bundle" (the bundle value for the
quay.io/konflux-ci/tekton-catalog/task-clair-scan entry) to remove the space so
the digest is immediately after "sha256:" (e.g., change "sha256: 654b..." to
"sha256:654b...") ensuring the YAML string is a valid digest.

Comment thread .tekton/hypershift-gomaxprocs-webhook-pull-request.yaml
Comment thread .tekton/hypershift-gomaxprocs-webhook-push.yaml
Comment on lines 367 to 369
- name: bundle
value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:a7cc183967f89c4ac100d04ab8f81e54733beee60a0528208107c9a22d3c43af
value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256: 654b989d7cdc03d082e56f216a29de04847215ee379a8d9ca315e453ad2b15c2
- name: kind

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Fix YAML syntax error: remove extra space after sha256:.

The space between sha256: and the digest value creates an invalid YAML mapping context, causing a parse error. This will break pipeline execution.

🐛 Proposed fix
        - name: bundle
-          value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256: 654b989d7cdc03d082e56f216a29de04847215ee379a8d9ca315e453ad2b15c2
+          value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:654b989d7cdc03d082e56f216a29de04847215ee379a8d9ca315e453ad2b15c2
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
- name: bundle
value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:a7cc183967f89c4ac100d04ab8f81e54733beee60a0528208107c9a22d3c43af
value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256: 654b989d7cdc03d082e56f216a29de04847215ee379a8d9ca315e453ad2b15c2
- name: kind
- name: bundle
value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:654b989d7cdc03d082e56f216a29de04847215ee379a8d9ca315e453ad2b15c2
- name: kind
🧰 Tools
🪛 YAMLlint (1.38.0)

[error] 368-368: syntax error: mapping values are not allowed here

(syntax)

🤖 Prompt for AI Agents
In @.tekton/hypershift-operator-main-tag.yaml around lines 367 - 369, The YAML
value for the env var named "bundle" contains an invalid space after "sha256:"
in the string "quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:
654b989d7cdc03d082e56f216a29de04847215ee379a8d9ca315e453ad2b15c2"; remove the
extra space so the digest immediately follows the colon (i.e.,
"…@sha256:654b989...") to produce a valid YAML scalar for the bundle value.

Comment on lines 259 to 261
- name: bundle
value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:ee558db6af779ab162163ec88f288a5c1b2d5f70c3361f3690a474866e3bdc74
value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256: 654b989d7cdc03d082e56f216a29de04847215ee379a8d9ca315e453ad2b15c2
- name: kind

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Fix YAML syntax error: remove extra space after sha256:.

Same issue as in other files. The space between sha256: and the digest creates invalid YAML.

🐛 Proposed fix
      - name: bundle
-        value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256: 654b989d7cdc03d082e56f216a29de04847215ee379a8d9ca315e453ad2b15c2
+        value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:654b989d7cdc03d082e56f216a29de04847215ee379a8d9ca315e453ad2b15c2
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
- name: bundle
value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:ee558db6af779ab162163ec88f288a5c1b2d5f70c3361f3690a474866e3bdc74
value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256: 654b989d7cdc03d082e56f216a29de04847215ee379a8d9ca315e453ad2b15c2
- name: kind
- name: bundle
value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:654b989d7cdc03d082e56f216a29de04847215ee379a8d9ca315e453ad2b15c2
- name: kind
🧰 Tools
🪛 YAMLlint (1.38.0)

[error] 260-260: syntax error: mapping values are not allowed here

(syntax)

🤖 Prompt for AI Agents
In @.tekton/pipelines/common-operator-build.yaml around lines 259 - 261, The
bundle image value has an invalid space after "sha256:" causing YAML parsing
errors; update the value under the mapping with "name: bundle" (the bundle value
for the quay.io/konflux-ci/tekton-catalog/task-clair-scan entry) to remove the
space so the digest is immediately after "sha256:" (e.g., change "sha256:
654b..." to "sha256:654b...") ensuring the YAML string is a valid digest.

Updates to Konflux Tekton task versions were resolved by accepting
upstream changes which included newer task digest values than those
initially identified in the enterprise contract verification log.

The following tasks were updated with newer upstream digests:
- prefetch-dependencies-oci-ta: 0.2@8eac535f...
- ecosystem-cert-preflight-checks: 0.2@04f75593...
- clamav-scan: 0.3@f3d2d179...
- rpms-signature-scan: 0.2@20eb21c6...

Additional tasks were also updated upstream:
- buildah-remote-oci-ta: 0.7@fe66734c...
- deprecated-image-check: 0.5@808fe09b...
- sast-snyk-check-oci-ta: 0.4@0eca130f...
- coverity-availability-check: 0.2@36400873...
- sast-shell-check-oci-ta: 0.1@d44336d7...
- sast-unicode-check-oci-ta: 0.3@e5a8d3e8...
- apply-tags: 0.2@c89cd10b...

Co-Authored-By: Claude Sonnet 4 <noreply@anthropic.com>
Signed-off-by: Juan Manuel Parrilla Madrid <jparrill@redhat.com>
@jparrill
jparrill force-pushed the update-konflux-task branch from cf1fd35 to 93a01fe Compare January 20, 2026 15:46
@openshift-ci

openshift-ci Bot commented Jan 20, 2026

Copy link
Copy Markdown
Contributor

@jparrill: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@bryan-cox

Copy link
Copy Markdown
Member

/lgtm
/verified by konflux tests

@openshift-ci-robot openshift-ci-robot added the verified Signifies that the PR passed pre-merge verification criteria label Jan 20, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@bryan-cox: This PR has been marked as verified by konflux tests.

Details

In response to this:

/lgtm
/verified by konflux tests

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@bryan-cox bryan-cox left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Jan 20, 2026
@openshift-ci

openshift-ci Bot commented Jan 20, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: bryan-cox, jparrill

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit ee28abe into openshift:main Jan 20, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/ci-tooling Indicates the PR includes changes for CI or tooling jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. verified Signifies that the PR passed pre-merge verification criteria

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants