Skip to content

chore(deps): update docker/dockerfile:1 docker digest to ecfaec9 - #62

Open
scality-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/docker-dockerfile-1
Open

chore(deps): update docker/dockerfile:1 docker digest to ecfaec9#62
scality-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/docker-dockerfile-1

Conversation

@scality-renovate

@scality-renovate scality-renovate Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
docker/dockerfile syntax digest 87999aaecfaec9

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 9am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@scality-renovate scality-renovate Bot added the dependencies Pull requests that update a dependency file label Aug 31, 2026
@scality-renovate
scality-renovate Bot requested a review from a team as a code owner August 31, 2026 04:11
@github-actions

Copy link
Copy Markdown

Dependency Bump Evaluation

Package: docker/dockerfile:1 (BuildKit Dockerfile frontend syntax directive)
Version change: digest 87999aaecfaec9 (digest-only update, tracking the docker/dockerfile:1 stable tag)
Semver bump type: digest

Changes:

  • Updates the pinned digest of the BuildKit Dockerfile parser to the latest build of the 1.x stable line
  • The current stable frontend is dockerfile/1.26.0, which contains a single bug fix: incorrect warning when matching .dockerignore patterns to COPY . commands

Breaking changes: None. The docker/dockerfile:1 tag tracks stable releases only; the underlying dockerfile/1.26.0 release contains no breaking changes.

Security concerns: None. No CVEs or security advisories in the Dockerfile frontend. BuildKit v0.32.1 included a security fix for archive extraction, but that applies to the BuildKit daemon, not the Dockerfile frontend syntax image.

Impact on codebase: The Dockerfile uses only basic instructions (FROM, ARG, COPY, RUN, LABEL, USER, ENTRYPOINT) — no advanced features like RUN --mount, RUN --device, or heredoc syntax. The frontend update has no functional impact on this build.

CI status: Several checks (build, lint, test) are still in progress; renovate/stability-days is pending. Verify CI is green before merging.

Recommendation: SAFE TO MERGE (once CI passes)

Notes: Cannot auto-approve as this PR is authored by renovate, not dependabot. A human reviewer should approve after CI completes.

— Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file digest docker

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants