metadata: annotations: prow.k8s.io/context: ci/prow/security prow.k8s.io/job: pull-ci-openshift-hypershift-main-security creationTimestamp: "2026-09-18T03:56:25Z" generation: 11 labels: capability/arm64: arm64 ci.openshift.io/generator: prowgen created-by-prow: "true" event-GUID: dd3e9520-b314-11f1-82a9-4a1a6ff1e3d9 pj-rehearse.openshift.io/can-be-rehearsed: "true" prow.k8s.io/build-id: "2100796057674846208" prow.k8s.io/context: security prow.k8s.io/id: d0babfe2-183a-452c-b577-2de8f58d0c7d prow.k8s.io/is-optional: "false" prow.k8s.io/job: pull-ci-openshift-hypershift-main-security prow.k8s.io/refs.base_ref: main prow.k8s.io/refs.org: openshift prow.k8s.io/refs.pull: "9680" prow.k8s.io/refs.repo: hypershift prow.k8s.io/type: presubmit name: d0babfe2-183a-452c-b577-2de8f58d0c7d namespace: ci resourceVersion: "8215327695" uid: 16baa756-56e3-4e71-b80e-2b05b00675d3 spec: agent: kubernetes cluster: build09 context: ci/prow/security decoration_config: censor_secrets: true censoring_options: minimum_secret_length: 6 gcs_configuration: bucket: test-platform-results-public compress_file_types: - txt - log - json - tar - html - yaml default_org: openshift default_repo: origin mediaTypes: log: text/plain path_strategy: single gcs_credentials_secret: gce-sa-credentials-gcs-publisher grace_period: 1h0m0s resources: clonerefs: limits: memory: 3Gi requests: cpu: 100m memory: 500Mi initupload: limits: memory: 200Mi requests: cpu: 100m memory: 50Mi place_entrypoint: limits: memory: 100Mi requests: cpu: 100m memory: 25Mi sidecar: limits: memory: 2Gi requests: cpu: 100m memory: 250Mi sparse_checkout_files: - .ci-operator.yaml - Dockerfile - Dockerfile.control-plane - Dockerfile.e2e timeout: 24h0m0s utility_images: clonerefs: us-docker.pkg.dev/k8s-infra-prow/images/clonerefs:v20260908-104d452f4 entrypoint: us-docker.pkg.dev/k8s-infra-prow/images/entrypoint:v20260908-104d452f4 initupload: us-docker.pkg.dev/k8s-infra-prow/images/initupload:v20260908-104d452f4 sidecar: us-docker.pkg.dev/k8s-infra-prow/images/sidecar:v20260908-104d452f4 job: pull-ci-openshift-hypershift-main-security namespace: ci pod_spec: containers: - args: - --enable-secrets-store-csi-driver=true - --gcs-upload-secret=/secrets/gcs/service-account.json - --gsm-config=/etc/gsm-config/gsm-config.yaml - --gsm-credentials-file=/etc/gsm-credentials/key.json - --gsm-project-config=/etc/gsm-config/gsm-project-config.yaml - --image-import-pull-secret=/etc/pull-secret/.dockerconfigjson - --lease-server-credentials-file=/etc/boskos/credentials - --report-credentials-file=/etc/report/credentials - --secret-dir=/secrets/ci-pull-credentials - --target=security command: - ci-operator env: - name: HTTP_SERVER_IP valueFrom: fieldRef: fieldPath: status.podIP image: quay-proxy.ci.openshift.org/openshift/ci:ci_ci-operator_latest imagePullPolicy: Always name: "" ports: - containerPort: 8080 name: http resources: requests: cpu: 10m volumeMounts: - mountPath: /etc/boskos name: boskos readOnly: true - mountPath: /secrets/ci-pull-credentials name: ci-pull-credentials readOnly: true - mountPath: /secrets/gcs name: gcs-credentials readOnly: true - mountPath: /etc/gsm-config name: gsm-config readOnly: true - mountPath: /etc/gsm-credentials name: gsm-sa-key readOnly: true - mountPath: /secrets/manifest-tool name: manifest-tool-local-pusher readOnly: true - mountPath: /etc/pull-secret name: pull-secret readOnly: true - mountPath: /etc/report name: result-aggregator readOnly: true serviceAccountName: ci-operator volumes: - name: boskos secret: items: - key: credentials path: credentials secretName: boskos-credentials - name: ci-pull-credentials secret: secretName: ci-pull-credentials - configMap: name: gsm-config name: gsm-config - csi: driver: secrets-store.csi.k8s.io readOnly: true volumeAttributes: secretProviderClass: ci-operator-sa-key-spc name: gsm-sa-key - name: manifest-tool-local-pusher secret: secretName: manifest-tool-local-pusher - name: pull-secret secret: secretName: registry-pull-credentials - name: result-aggregator secret: secretName: result-aggregator prowjob_defaults: tenant_id: GlobalDefaultID refs: base_link: https://github.com/openshift/hypershift/commit/c1d6599bcd458600134f3640ebae6712d0f8b3b5 base_ref: main base_sha: c1d6599bcd458600134f3640ebae6712d0f8b3b5 org: openshift pulls: - author: dependabot[bot] author_link: https://github.com/apps/dependabot commit_link: https://github.com/openshift/hypershift/pull/9680/commits/b7e574332d47d513f48f7e9eeed47e8782242edb head_ref: dependabot/go_modules/azure-github-dependencies-1aa2cb2a13 link: https://github.com/openshift/hypershift/pull/9680 number: 9680 sha: b7e574332d47d513f48f7e9eeed47e8782242edb title: 'build(deps): bump the azure-github-dependencies group across 1 directory with 3 updates' repo: hypershift repo_link: https://github.com/openshift/hypershift sparse_checkout_files: - .ci-operator.yaml - Dockerfile - Dockerfile.control-plane - Dockerfile.e2e report: true rerun_command: /test security type: presubmit status: build_id: "2100796057674846208" completionTime: "2026-09-18T04:13:02Z" description: Job succeeded. pendingTime: "2026-09-18T03:56:25Z" pod_name: d0babfe2-183a-452c-b577-2de8f58d0c7d prev_report_states: gcsk8sreporter: success gcsreporter: success github-reporter: success startTime: "2026-09-18T03:56:25Z" state: success url: https://prow.ci.openshift.org/view/gs/test-platform-results-public/pr-logs/pull/openshift_hypershift/9680/pull-ci-openshift-hypershift-main-security/2100796057674846208