Skip to content

[OPENJDK-4847] installWeakDeps: false for rpm lockfile generation#640

Merged
jmtd merged 1 commit into
rh-openjdk:ubi10from
jmtd:ubi10-weakdeps
Jun 11, 2026
Merged

[OPENJDK-4847] installWeakDeps: false for rpm lockfile generation#640
jmtd merged 1 commit into
rh-openjdk:ubi10from
jmtd:ubi10-weakdeps

Conversation

@jmtd

@jmtd jmtd commented Apr 2, 2026

Copy link
Copy Markdown
Member

[OPENJDK-4847] installWeakDeps: false for rpm lockfile generation

This file is consumed by
https://github.com/konflux-ci/rpm-lockfile-prototype which resolves
the transitive dependencies of the specified RPMs. Without this, the
tool will generate a lockfile containing all transitive weak
dependencies, which results in the security scanning tools flagging
containers erroneously, and merge request churn to update the NVRs
for the unnecessary packages.

https://redhat.atlassian.net/browse/OPENJDK-4847

Note: we are building and shipping images with the effect of this change downstream of cekit.

@jmtd jmtd marked this pull request as ready for review June 9, 2026 09:38
@jmtd jmtd changed the title installWeakDeps: false for rpm lockfile generation ]OPENJDK-4847installWeakDeps: false for rpm lockfile generation Jun 9, 2026
@jmtd jmtd changed the title ]OPENJDK-4847installWeakDeps: false for rpm lockfile generation [OPENJDK-4847] installWeakDeps: false for rpm lockfile generation Jun 9, 2026
This file is consumed by
<https://github.com/konflux-ci/rpm-lockfile-prototype> which resolves
the transitive dependencies of the specified RPMs. Without this, the
tool will generate a lockfile containing all transitive weak
dependencies, which results in the security scanning tools flagging
containers erroneously, and merge request churn to update the NVRs
for the unnecessary packages.

Signed-off-by: Jonathan Dowland <jdowland@redhat.com>
@jmtd jmtd force-pushed the ubi10-weakdeps branch from 96e2254 to 8aa0c4a Compare June 9, 2026 09:42
@jmtd jmtd requested a review from jerboaa June 9, 2026 09:43
@jmtd jmtd merged commit e2ecbae into rh-openjdk:ubi10 Jun 11, 2026
2 of 4 checks passed
@jmtd jmtd deleted the ubi10-weakdeps branch June 11, 2026 15:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants