Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@

## Build

FROM docker.io/library/golang:1.26.7 AS build
FROM docker.io/library/golang:1.27.1 AS build

Check failure on line 19 in Dockerfile

View workflow job for this annotation

GitHub Actions / Test

Containerfile version incompatible, saw 1.27.1, running with version: 1.26.7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[medium] protected-path

This PR modifies Dockerfile, which is on the repository protected-paths list (governance/infrastructure files that require human approval). Context is sufficient: the PR body describes an automated Renovate-managed minor version bump of the docker.io/library/golang build-stage base image (1.26.7 -> 1.27.1) on the release-v0.7 branch, and renovate.json at the repository root extends the org-wide Renovate config (github>conforma/.github//config/renovate/renovate.json), which authorizes automated Docker tag updates. Human approval is still required for protected-path changes regardless of authorization evidence.

Suggested fix: A repository maintainer must review and approve the Dockerfile change directly. Confirm that (a) crossing a Go minor version boundary on a release branch (1.26.x -> 1.27.x) is intentional β€” Go minor releases can include compiler/runtime/toolchain changes beyond patch-level fixes β€” and (b) the change is consistent with the repo Renovate configuration policy for release branches.


ARG TARGETOS
ARG TARGETARCH
Expand Down
Loading