Skip to content

Pin conforma tekton task to digest - #3491

Open
joejstuart wants to merge 1 commit into
conforma:mainfrom
joejstuart:pin-conforma
Open

Pin conforma tekton task to digest#3491
joejstuart wants to merge 1 commit into
conforma:mainfrom
joejstuart:pin-conforma

Conversation

@joejstuart

Copy link
Copy Markdown
Contributor

Pin this to a digest so we can control when changes are released. This is to sync the changes with the release-service.

Pin this to a digest so we can control when
changes are released. This is to sync the changes
with the release-service.
@coderabbitai

coderabbitai Bot commented Aug 11, 2026

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Enterprise

Run ID: 1179e871-9f7f-4ff0-8087-3f461e3438e2

📥 Commits

Reviewing files that changed from the base of the PR and between 0250ec5 and 091bf89.

📒 Files selected for processing (1)
  • pipelines/enterprise-contract/0.1/enterprise-contract.yaml

📝 Walkthrough

Walkthrough

The enterprise contract pipeline replaces the mutable konflux tag with an immutable SHA256 digest for two Tekton bundle references.

Changes

Enterprise contract bundle pinning

Layer / File(s) Summary
Pin Tekton bundle references
pipelines/enterprise-contract/0.1/enterprise-contract.yaml
The collect-keyless-params and verify-enterprise-contract bundle references now use the specified immutable SHA256 digest instead of the konflux tag.

Estimated code review effort: 1 (Trivial) | ~2 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely states that the Conforma Tekton task is pinned to a digest.
Description check ✅ Passed The description explains what changed and why, and it is sufficiently complete despite omitting the template headings and a ticket link.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 11, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:57 PM UTC · Completed 4:05 PM UTC

Commit: 87c4a29 · View workflow run →

@fullsend-ai-review

Copy link
Copy Markdown

Looks good to me


Labels: PR modifies pipeline configuration (Tekton task digest pinning)

@fullsend-ai-review fullsend-ai-review Bot added ready-for-merge All reviewers approved — ready to merge config labels Aug 11, 2026
@codecov

codecov Bot commented Aug 11, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Flag Coverage Δ
acceptance 54.42% <ø> (+<0.01%) ⬆️
generative 16.35% <ø> (ø)
integration 27.56% <ø> (ø)
unit 72.14% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

config ready-for-merge All reviewers approved — ready to merge size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant