Update Konflux references - #318
Merged
Merged
Conversation
Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com>
syedriko
added a commit
that referenced
this pull request
Sep 17, 2026
* fix(deps): bump pypdf to >=6.14.2 for CVE fixes LCORE-2903 Addresses CVE-2026-59935, CVE-2026-59936, CVE-2026-59937, CVE-2026-59938 — infinite loops and memory exhaustion in pypdf. Bumps transitive dep floor from 6.14.0 to 6.14.2 via explicit constraint in pyproject.toml. Updates RHOAI CPU and CUDA lockfiles. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(deps): upgrade mcp to >=1.28.1 for 3 CVEs LCORE-3207 Fixes CVE-2026-52869 (HTTP session hijack), CVE-2026-52870 (task access control bypass), and CVE-2026-59950 (WebSocket origin validation bypass). Bumps mcp from 1.28.0 in uv.lock, 1.27.2 (CPU) / 1.27.0 (CUDA) in Konflux requirements to 1.28.1 across all lockfiles. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(deps): correct mcp==1.28.1 wheel sha256 hashes LCORE-3207 Replace incorrect hashes in CPU and CUDA wheel requirement files with the published PyPI hash matching uv.lock. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(deps): use RHOAI index hashes for mcp==1.28.1 wheels LCORE-3207 Previous hashes were from PyPI, not from RHOAI index. CPU uses build -2, CUDA uses build -8 — different sha256. * Red Hat Konflux kflux-prd-rh02 update rag-content-cuda-12-9-0-8 (#269) Signed-off-by: red-hat-konflux-kflux-prd-rh02[bot] <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> Co-authored-by: red-hat-konflux-kflux-prd-rh02[bot] <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> * Red Hat Konflux kflux-prd-rh02 update rag-content-cpu-0-8 (#268) Signed-off-by: red-hat-konflux-kflux-prd-rh02[bot] <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> Co-authored-by: red-hat-konflux-kflux-prd-rh02[bot] <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> * Update Lightspeed Core 0.8 Konflux pipelines (#270) * Migrate the integration test to Lightspeed Core 0.8 [main] (#271) * LCORE-3058: Migrate the main and release/0.7 branches of rag-content to RHOAI 3.5 index + PyPI sdists [main] (#267) * Migrate Llama Stack to OGX (#273) * Set CPE labels to 0.8 [main] (#277) * Update Konflux references (#282) Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> Co-authored-by: red-hat-konflux-kflux-prd-rh02[bot] <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> * Only install CUDA RPMs in the non-hermetic build [main] (#288) * Add the RHELAI RPM repo as used in the AIPCC base image [main] (#290) * LCORE-3051: In the rag-content images, only install what is needed (#246) * Update Konflux references (#293) Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> Co-authored-by: red-hat-konflux-kflux-prd-rh02[bot] <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> * Migrate ITS from LLama Stack to OGX [main] (#296) * LCORE-1426: Update generated lightspeed-stack.yaml to new unified RAG config format (#247) Align config templates with the BYOK config refactoring in lightspeed-stack: - byok_rag → rag.byok.stores - rag_type → backend (faiss instead of inline::faiss, pgvector instead of remote::pgvector) - rag.tool → rag.retrieval.tool.sources Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * Update Konflux references (#300) Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> Co-authored-by: red-hat-konflux-kflux-prd-rh02[bot] <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> * Update Konflux references (#306) Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> Co-authored-by: red-hat-konflux-kflux-prd-rh02[bot] <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> * LCORE-3884: Remove support for the CUDA variant of rag-content from 0.7.0 forward [main] (#310) * LCORE-3946: Bump OGX version to 1.2.5 in rag-content [main] (#312) * Update Konflux references (#318) Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> Co-authored-by: red-hat-konflux-kflux-prd-rh02[bot] <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> * LCORE-3962: Update the AIPCC base image in rag-content [main] (#315) * Update Konflux references (#325) Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> Co-authored-by: red-hat-konflux-kflux-prd-rh02[bot] <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> * LCORE-4169: Update CVEs (#328) * feat(scripts): make generate-rpm-lock.sh macOS compatible * deps(konflux): update base image * deps(konflux): update packages * removed 0.8 pipelines * regenerated files --------- Signed-off-by: red-hat-konflux-kflux-prd-rh02[bot] <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> Co-authored-by: platex-rehor-bot <platform-experience-services@redhat.com> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Co-authored-by: Cesare Pompeiano <195810094+are-ces@users.noreply.github.com> Co-authored-by: red-hat-konflux-kflux-prd-rh02[bot] <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com> Co-authored-by: Sergey Yedrikov <48031344+syedriko@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.3→0.3.1c2cda69→290c9ec0.12.0→0.12.10.3.2→0.3.3b961f8b→c07d2be3bcd4c3→2e8fe305f68715→4be93430.10.1→0.10.2393b4d0→ef00a8676ed85a→97e2b2cf110c53→9ef4dabc06bee8→afa8ba897231d2→67a409d6a7fbfa→69d5fca0.3→0.3.1Release Notes
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-apply-tags)
v0.3.1Changed
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta)
v0.12.1Changed
prepare-sbomsstep memory from 256Mi to 512Mi (requests = limits) to prevent OOM kills on large container images (GPU/ML, bootc, driver-toolkit).prepare-sbomsCPU limit (was 100m) to allow burst CPU and prevent throttling. CPU requests remain at 100m.konflux-ci/konflux-test-tasks (quay.io/konflux-ci/tekton-catalog/task-clamav-scan)
v0.3.3Changed
model-weight files (
.safetensors,.gguf,.ggml,.pt,.pth,.onnx,.onnx_data/.onnx_data_*), usingorg.opencontainers.image.titleandolot.layer.content.inlayerpath. Any other annotated layer is skipped whenthe OCI descriptor
sizeis at least 2000MiB (slightly under ClamAV's ~2GiBMaxFileSize), regardless of extension. Layers without those annotations are
still listed with
--dry-runas in 0.3.2. The--dry-runskip uses thesame name list.
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta)
v0.10.2konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta)
v0.3.1Changed
Configuration
📅 Schedule: (UTC)
* 5-23 * * 6)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.