Skip to content

chore: bump version to 1.0.4 and update Tekton to 1.5.0 - #101

Merged
ompushkara merged 1 commit into
mainfrom
mt-1.0.4
Sep 10, 2026
Merged

ompushkara merged 1 commit into
mainfrom
mt-1.0.4

Conversation

@ompushkara

Copy link
Copy Markdown

Summary

Checklist
  • All commits are signed-off, using DCO
  • All new code has docstrings and type annotations
  • All new code is covered by tests. Aim for at least 90% coverage. CI is configured to highlight lines not covered by tests.
  • Public facing changes are paired with documentation changes
  • Release note has been added to CHANGELOG.md if needed

Signed-off-by: ompushkara <omotilal@redhat.com>
@qodo-for-securesign

Copy link
Copy Markdown

PR Summary by Qodo

Align package 1.0.4 with Tekton release 1.5.0

⚙️ Configuration changes 🕐 Less than 5 minutes

Grey Divider

AI Description

• Publishes model-signing package metadata as version 1.0.4.
• Aligns pull-request and push builds with Tekton 1.5.0 and image 1.0.4.
Diagram

graph TD
  PREvent["Pull Request"] --> PRConfig["PR PipelineRun"] --> Build["Tekton Build"] --> Package["Package 1.0.4"]
  PushEvent["Main Push"] --> PushConfig["Push PipelineRun"] --> Build
Loading
High-Level Assessment

The direct, synchronized version bump is optimal for this release-only change. Centralized version derivation was considered but would add unnecessary pipeline coupling for three explicit metadata values.

Files changed (3) +5 / -5

Other (3) +5 / -5
model-transparency-pull-request.yamlBump pull-request build versions +2/-2

Bump pull-request build versions

• Sets the pull-request PipelineRun release version to 1.5.0 and its image version to 1.0.4.

.tekton/model-transparency-pull-request.yaml

model-transparency-push.yamlBump push build versions +2/-2

Bump push build versions

• Sets the push PipelineRun release version to 1.5.0 and its image version to 1.0.4.

.tekton/model-transparency-push.yaml

__init__.pyPublish package version 1.0.4 +1/-1

Publish package version 1.0.4

• Updates the package-level '__version__' value from 1.0.3 to 1.0.4.

src/model_signing/init.py

@qodo-for-securesign

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (1) 📘 Rule violations (0) 🔗 Cross-repo conflicts (0) 📜 Skill insights (0)

Grey Divider


Remediation recommended

1. Users cannot find 1.0.4 release notes 🐞 Bug ⚙ Maintainability
Description
__version__ advances the package to 1.0.4 without adding a matching release section or advancing
the [Unreleased] comparison base in CHANGELOG.md. Once v1.0.4 is tagged, the package's published
Changelog URL still presents 1.0.3 as the latest release and includes 1.0.4 commits in the future
unreleased comparison.
Code

src/model_signing/init.py[128]

+__version__ = "1.0.4"
Relevance

●●● Strong

Recent release PRs consistently pair version bumps with release notes and updated comparison links.

PR-#78
PR-#71

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The changelog ends its downstream release history at 1.0.3, and its Unreleased comparison still
starts at v1.0.3. The package metadata exposes this file as the public changelog, so the stale
release history is user-facing.

CHANGELOG.md[8-15]
CHANGELOG.md[136-140]
pyproject.toml[76-79]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The package version is advanced to 1.0.4, but the public changelog still identifies 1.0.3 as the latest release and compares unreleased work from the v1.0.3 tag.

## Fix Focus Areas
- CHANGELOG.md[8-15]
- CHANGELOG.md[136-140]

## Recommended Fix
Add a dated 1.0.4 release section describing the release, update the `[Unreleased]` link to compare `v1.0.4...HEAD`, and add a `[1.0.4]` comparison link from `v1.0.3` to `v1.0.4`.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context sources
✅ Cross-repo context — repo relationships
  Explored: repo: securesign/pipelines (sha: e6b10661)
  Explored: repo: securesign/releases (sha: 5a36d32f)
Review mode: ⚖️ Balanced: This is a small version/configuration update, but it changes runtime package metadata and Tekton release/image parameters, so a complete review is warranted; it is not dense enough for extended.

Grey Divider

Tip of the day
💡 Did you know, you can turn these tips off under Display preferences

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 79.70%. Comparing base (bc7c389) to head (294065c).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #101   +/-   ##
=======================================
  Coverage   79.70%   79.70%           
=======================================
  Files          21       21           
  Lines        1922     1922           
=======================================
  Hits         1532     1532           
  Misses        390      390           
Flag Coverage Δ
unit 79.70% <100.00%> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@sampras343

Copy link
Copy Markdown
Member

Check if oidc token fetch is failing. Otherwise lgtm

@ompushkara

Copy link
Copy Markdown
Author

@sampras343 , yes thats right and I fixed it now as part of #102

@ompushkara
ompushkara merged commit 718efec into main Sep 10, 2026
27 of 55 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants