Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@

## Build

FROM docker.io/library/golang:1.26.3@sha256:2d6c80227255c3112a4d08e67ba98e58efd3846daf15d9d7d4c389565d881b1a AS build
FROM docker.io/library/golang:1.26.5@sha256:3aff6657219a4d9c14e27fb1d8976c49c29fddb70ba835014f477e1c70636647 AS build

Check failure on line 19 in Dockerfile

View workflow job for this annotation

GitHub Actions / Test

Containerfile version incompatible, saw 1.26.5, running with version: 1.26.3

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[low] version-consistency

The Dockerfile is updated to Go 1.26.5 while go.mod, .tool-versions, Dockerfile.dist, and other module files still specify Go 1.26.3. Go patch versions are fully backward compatible, so this causes no build or runtime issues. This is expected behavior for scoped Renovate updates β€” separate PRs or rules will update the other files. If the repo golang-version-check CI step enforces strict alignment, it may flag this mismatch.

Suggested fix: No action required on this PR. Verify that separate Renovate rules or manual processes will update go.mod, .tool-versions, and Dockerfile.dist to 1.26.5 as well.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[high] protected-path

This PR modifies Dockerfile, which is a protected governance/infrastructure file requiring human approval. The PR has no linked issue providing explicit authorization for the change. Note: renovate.json is configured in this repository and extends the shared org config (github>conforma/.github//config/renovate/renovate.json), indicating that Renovate is authorized to propose Dockerfile updates. However, human review and approval is still required for all protected-path changes regardless of automation source.

Suggested fix: A human reviewer must explicitly approve this protected-path change. Consider linking a tracking issue or policy reference that authorizes automated Dockerfile updates to streamline future Renovate PRs.


ARG TARGETOS
ARG TARGETARCH
Expand Down
Loading