Fedora Account System
Red Hat Associate
Red Hat Customer
## No automated dependency-update configuration for submodules or Containerfile **Component:** operator-sdk-builder The repository has no Renovate/Dependabot configuration covering git submodules, the Containerfile base image, or Tekton bundle references, so stale/vulnerable pins are not automatically flagged. ### Remediation Add a renovate.json (or enable Konflux MintMaker rules) covering `git-submodules`, `dockerfile` and `tekton` managers so submodule SHAs and base-image digests receive automated update PRs. --- *Source: Ex-Wing/Glasswing Konflux CI security assessment (Mythos), finding FIND-004*