[main] ESO-569, ESO-570, ESO-571: Pin hack tools and harden Renovate - #387
[main] ESO-569, ESO-570, ESO-571: Pin hack tools and harden Renovate#387bharath-b-rh wants to merge 3 commits into
Conversation
Signed-off-by: Bharath B <bhb@redhat.com>
Signed-off-by: Bharath B <bhb@redhat.com>
Signed-off-by: Bharath B <bhb@redhat.com>
|
@bharath-b-rh: No Jira issue with key ESO-569 exists in the tracker at https://redhat.atlassian.net. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
@bharath-b-rh: No Jira issue with key ESO-570 exists in the tracker at https://redhat.atlassian.net. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
@bharath-b-rh: No Jira issue with key ESO-571 exists in the tracker at https://redhat.atlassian.net. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: bharath-b-rh The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Summary
hack/tool-images.shopmversion with per-arch SHA-256 verification inhack/get-opm.sh(used for FBC/catalog updates)renovate.json: default-deny Containerfile/Tekton docker updates, digest-only for already-pinned Containerfiles, Konflux Tekton catalog rules, and major/minor-only updates for hack tool imagesTest plan
make verify-shell-scriptsmake verify-containerfilesmake validate-renovate-configmake get-opmdownloads and reportssha256 OK; rerunning is a no-op when the pin matches