Skip to content

bump rtask-show-sbom to sha256:78c8d7960c6db284356d94aaae64d1fca34fff4de6a6e20d897a088af0c81cf5#262

Closed
eranco74 wants to merge 1 commit intorh-ecosystem-edge:mainfrom
eranco74:fix_rpms-signature-scan
Closed

bump rtask-show-sbom to sha256:78c8d7960c6db284356d94aaae64d1fca34fff4de6a6e20d897a088af0c81cf5#262
eranco74 wants to merge 1 commit intorh-ecosystem-edge:mainfrom
eranco74:fix_rpms-signature-scan

Conversation

@eranco74
Copy link
Collaborator

@eranco74 eranco74 commented Nov 23, 2025

Untrusted version of PipelineTask "rpms-signature-scan" (Task "rpms-signature-scan") was included in build chain comprised of: rpms-signature-scan. Please upgrade the task version to: sha256:78c8d7960c6db284356d94aaae64d1fca34fff4de6a6e20d897a088af0c81cf5

Summary by CodeRabbit

  • Chores
    • Updated build pipeline configuration to use the latest version of the Software Bill of Materials (SBOM) task.

✏️ Tip: You can customize this high-level summary in your review settings.

…4de6a6e20d897a088af0c81cf5

Untrusted version of PipelineTask "rpms-signature-scan" (Task "rpms-signature-scan") was included in build chain
comprised of: rpms-signature-scan. Please upgrade the task version to:
sha256:78c8d7960c6db284356d94aaae64d1fca34fff4de6a6e20d897a088af0c81cf5

Signed-off-by: Eran Cohen <eranco@redhat.com>
@openshift-ci openshift-ci bot requested review from carbonin and omertuc November 23, 2025 14:24
@openshift-ci
Copy link

openshift-ci bot commented Nov 23, 2025

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: eranco74

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@coderabbitai
Copy link

coderabbitai bot commented Nov 23, 2025

Walkthrough

The pull request updates a task bundle reference in the Tekton pipeline configuration. The Show SBOM task bundle hash in the PipelineRun's final stage was replaced with a new hash value, with no other structural or behavioral modifications.

Changes

Cohort / File(s) Summary
Tekton Pipeline Configuration
.tekton/assisted-chat-saas-main-pull-request.yaml
Updated the Show SBOM task bundle hash from beb0616db051952b4b861dd8c3e00fa1c0eccbd926feddf71194d3bb3ace9ce7 to 78c8d7960c6db284356d94aaae64d1fca34fff4de6a6e20d897a088af0c81cf5

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Suggested labels

lgtm, ok-to-test

Suggested reviewers

  • omertuc

Pre-merge checks and finishing touches

✅ Passed checks (3 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and specifically summarizes the main change: upgrading the rtask-show-sbom bundle to a new SHA256 hash.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@eranco74 eranco74 changed the title bump rtask-show-sbom to sha256:78c8d7960c6db284356d94aaae64d1fca34fff… bump rtask-show-sbom to sha256:78c8d7960c6db284356d94aaae64d1fca34fffUntrusted version of PipelineTask "rpms-signature-scan" (Task "rpms-signature-scan") was included in build chain comprised of: rpms-signature-scan. Please upgrade the task version to: sha256:78c8d7960c6db284356d94aaae64d1fca34fff4de6a6e20d897a088af0c81cf5 Nov 23, 2025
@eranco74 eranco74 changed the title bump rtask-show-sbom to sha256:78c8d7960c6db284356d94aaae64d1fca34fffUntrusted version of PipelineTask "rpms-signature-scan" (Task "rpms-signature-scan") was included in build chain comprised of: rpms-signature-scan. Please upgrade the task version to: sha256:78c8d7960c6db284356d94aaae64d1fca34fff4de6a6e20d897a088af0c81cf5 bump rtask-show-sbom to sha256:78c8d7960c6db284356d94aaae64d1fca34fff4de6a6e20d897a088af0c81cf5 Nov 23, 2025
@eranco74
Copy link
Collaborator Author

/close
Already fixed here: #236

@eranco74 eranco74 closed this Nov 23, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant