-
Notifications
You must be signed in to change notification settings - Fork 62
NO-ISSUE: Synchronize From Upstream Repositories #811
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
6c1d057
ea5f506
00219d5
4a9aab8
bca481f
83a6311
108ed16
1b67842
6958cdf
85ec0ad
02914d9
e96f4e6
6495c29
a2970f6
7e86443
8089bf3
96ccba5
24a8a72
03f2039
5a76ac0
37b5447
f430f3e
9609ba5
29f71a8
e0af7c1
92ee987
5a045b9
b901ff1
78e15f2
b4a22ec
a78c84f
10b2477
57e53b1
6210149
782f16e
3b6dd09
46b914c
31af032
b5c8cf3
2f8053c
65e196e
ffa99aa
ce2ea4c
5f5bdbc
fa05529
b19c7a2
236f714
49cea8b
e702cd2
90f2b63
fb5e804
75623e0
946cc26
309d86f
bfea171
db3b3f2
cce8a93
75609c0
b38f336
ff7ec8d
76a1f9c
8c3fb78
60534a8
99ac617
c95aecf
2c2bf7c
8a8df58
dbad0d3
8e98eb3
4b2252f
81018f9
28389eb
c8c5341
ec0f444
dab8f68
4dd2468
92d837b
859b9ab
1cfb7b9
047821d
fcd30ab
270d760
06d285d
eb3bbe4
56f2ef4
fee8626
eda9ad2
ce57522
b44e2b9
a490bce
c67916e
78e344d
1ed39bd
bd95d44
dfa0e74
9a54496
ab1b704
3800617
5fddd54
5428c3b
98f4ac2
a1e2aa6
e43ea95
8d554e5
cc87084
50f4565
14c63da
3336cdc
8c4fa8f
f81d028
0d6d46d
fe54883
2a8fc9c
77afd5b
716de79
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -2,7 +2,7 @@ Babel==2.18.0 | |
| beautifulsoup4==4.15.0 | ||
| certifi==2026.7.22 | ||
| charset-normalizer==3.5.1 | ||
| click==8.4.2 | ||
| click==8.5.0 | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🛡️ Analyzed with Security Review | 🟠 Major | 🏗️ Heavy lift 🧩 Analysis chain🏁 Script executed: set -eu
printf '%s\n' '--- root dependency files ---'
git ls-files requirements.txt Makefile.venv
printf '%s\n' '--- requirements.txt ---'
cat -n requirements.txt
printf '%s\n' '--- Makefile.venv install references ---'
rg -n -C 4 -- '--require-hashes|pip(3)?( |$)|requirements\.txt' Makefile.venvRepository: openshift/operator-framework-operator-controller Length of output: 3810 Security Misconfiguration Reachability: External Add artifact hashes and enforce 🤖 Prompt for AI Agents |
||
| colorama==0.4.6 | ||
| cssselect==1.5.0 | ||
| ghp-import==2.1.0 | ||
|
|
@@ -19,7 +19,7 @@ mkdocs-material-extensions==1.3.1 | |
| packaging==26.3 | ||
| paginate==0.5.7 | ||
| pathspec==1.1.1 | ||
| platformdirs==4.11.3 | ||
| platformdirs==4.11.5 | ||
| Pygments==2.21.0 | ||
| pymdown-extensions==11.0.2 | ||
| pyquery==2.1.0 | ||
|
|
||
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🛡️ Analyzed with Security Review | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: openshift/operator-framework-operator-controller
Length of output: 50404
🤖 get_repo_knowledge executed:
get_repo_knowledge openshift/operator-framework-operator-controller /tmp/coderabbit-repo-knowledge/openshift-operator-framework-operator-controller-9c0471ca/conventionsLength of output: 6404
🏁 Script executed:
Repository: openshift/operator-framework-operator-controller
Length of output: 1093
🏁 Script executed:
Repository: openshift/operator-framework-operator-controller
Length of output: 19066
Security Misconfiguration
CWE: CWE-693
Enable SBOM and provenance generation for release artifacts.
.goreleaser.ymlpasses--provenance=falseto every release image build. Enable provenance attestations and add SBOM generation to the release path. Publish and sign these records with the corresponding artifacts.🤖 Prompt for AI Agents
Source: Path instructions
🔒 Security & Privacy | 🛡️ Analyzed with Security Review | 🟠 Major | 🏗️ Heavy lift
🧩 Analysis chain
🏁 Script executed:
Repository: openshift/operator-framework-operator-controller
Length of output: 16558
🤖 get_repo_knowledge executed:
get_repo_knowledge openshift/operator-framework-operator-controller /tmp/coderabbit-repo-knowledge/openshift-operator-framework-operator-controller-9c0471ca/conventionsLength of output: 6404
🏁 Script executed:
Repository: openshift/operator-framework-operator-controller
Length of output: 50405
🏁 Script executed:
Repository: openshift/operator-framework-operator-controller
Length of output: 26631
🏁 Script executed:
Repository: openshift/operator-framework-operator-controller
Length of output: 11326
Security Misconfiguration
CWE: CWE-494 — Download of Code Without Integrity Check
Add mandatory artifact signing to the release pipeline.
.goreleaser.ymlbuilds images with--provenance=falseand defines no signing step. Sign every published image and release artifact with Sigstore or cosign. Enable provenance attestations and fail the release if signing fails.🤖 Prompt for AI Agents
Source: Path instructions