Skip to content

chore(deps): update docker.io/vegardit/openldap:2.6.10 docker digest to fd9af3f - #1049

Merged
cbcoutinho merged 1 commit into
masterfrom
renovate/docker.io-vegardit-openldap-2.6.10
Jul 9, 2026
Merged

chore(deps): update docker.io/vegardit/openldap:2.6.10 docker digest to fd9af3f#1049
cbcoutinho merged 1 commit into
masterfrom
renovate/docker.io-vegardit-openldap-2.6.10

Conversation

@renovate-bot-cbcoutinho

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
docker.io/vegardit/openldap digest 0f24ff1fd9af3f

Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@claude

claude Bot commented Jul 9, 2026

Copy link
Copy Markdown

Claude finished @renovate-bot-cbcoutinho[bot]'s task in 23s —— View job


Review Checklist

  • Gather context (diff, changed files)
  • Understand request (code review of Renovate digest-bump PR)
  • Review change
  • Post feedback

Review

This is a Renovate-generated digest pin update for docker.io/vegardit/openldap:2.6.10, touching a single line in docker-compose.yml:

- image: docker.io/vegardit/openldap:2.6.10@sha256:0f24ff1d4ec0faa560fd88fd9da80f37a404ca849b57c5ec1fe911fb0c1967b6
+ image: docker.io/vegardit/openldap:2.6.10@sha256:fd9af3fd925cda6409ea62156ce9002798bcc4c86eddc4178f137888a2e176d4

Findings:

  • Tag stays 2.6.10; only the content digest changes (0f24ff1…fd9af3f…), consistent with an upstream rebuild of the same version (patch/security update within the tag) rather than a version bump.
  • Digest pinning is preserved (image@sha256:...), so this keeps reproducible builds — good practice, nothing to change.
  • Scope is correctly limited to the openldap service (per docker-compose.yml:494), which backs the ldap profile used for the GH fix(client): resolve DAV paths via current-user-principal discovery #980 LDAP reproduction tests — it's not part of the default stack, so blast radius for other test lanes is none.
  • No code, config schema, or test changes are needed for a digest-only bump.
  • Per this repo's CLAUDE.md guidance, single-line dependency/digest bumps are explicitly exempted from the pre-push-review skill and full test suite — no further local verification was run, consistent with that policy.

Security/quality: No concerns. This is a routine, low-risk automated dependency update.

Nothing further to do here — safe to merge once someone confirms the new image builds/pulls cleanly (Renovate itself doesn't validate registry pulls succeed on private/rate-limited hubs, but vegardit/openldap is a public Docker Hub image so this is a non-issue).

@sonarqubecloud

sonarqubecloud Bot commented Jul 9, 2026

Copy link
Copy Markdown

@cbcoutinho
cbcoutinho merged commit 6d107d6 into master Jul 9, 2026
21 checks passed
@renovate-bot-cbcoutinho
renovate-bot-cbcoutinho Bot deleted the renovate/docker.io-vegardit-openldap-2.6.10 branch July 9, 2026 16:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant