Skip to content

Commit cf6b010

Browse files
Merge pull request openshift-kni#1539 from abraham2512/update-nrop-mg-lockfile
konflux: update tekton tasks digests and pull latest RPMs
2 parents 6e0e3ff + 784c933 commit cf6b010

File tree

6 files changed

+80
-46
lines changed

6 files changed

+80
-46
lines changed

.konflux/must-gather/redhat.repo

Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
#
2+
# Certificate-Based Repositories
3+
# Managed by (rhsm) subscription-manager
4+
#
5+
# *** This file is auto-generated. Changes made here will be over-written. ***
6+
# *** Use "subscription-manager repo-override --help" if you wish to make changes. ***
7+
#
8+
# If this file is empty and this system is subscribed consider
9+
# a "yum repolist" to refresh available repos
10+
#
11+
12+
[codeready-builder-for-rhel-9-$basearch-rpms]
13+
name = Red Hat CodeReady Linux Builder for RHEL 9 $basearch (RPMs)
14+
baseurl = https://cdn.redhat.com/content/dist/rhel9/9.4/$basearch/codeready-builder/os
15+
enabled = 1
16+
gpgcheck = 1
17+
gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
18+
sslverify = 1
19+
sslcacert = /etc/rhsm/ca/redhat-uep.pem
20+
sslclientkey = /etc/pki/entitlement/7511773722896751421-key.pem
21+
sslclientcert = /etc/pki/entitlement/7511773722896751421.pem
22+
sslverifystatus = 1
23+
metadata_expire = 86400
24+
enabled_metadata = 1
25+
26+
[rhel-9-for-$basearch-baseos-eus-rpms]
27+
name = Red Hat Enterprise Linux 9 for $basearch - BaseOS - Extended Update Support (RPMs)
28+
baseurl = https://cdn.redhat.com/content/eus/rhel9/9.4/$basearch/baseos/os
29+
enabled = 1
30+
gpgcheck = 1
31+
gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
32+
sslverify = 1
33+
sslcacert = /etc/rhsm/ca/redhat-uep.pem
34+
sslclientkey = /etc/pki/entitlement/7511773722896751421-key.pem
35+
sslclientcert = /etc/pki/entitlement/7511773722896751421.pem
36+
sslverifystatus = 1
37+
metadata_expire = 86400
38+
enabled_metadata = 1
39+

.konflux/must-gather/rpms.in.yaml

Lines changed: 2 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,7 @@
11
contentOrigin:
22
# Define at least one source of packages, but you can have as many as you want.
3-
repos:
4-
- repoid: rhel-9-for-$basearch-appstream-rpms
5-
name: Red Hat Enterprise Linux 9 for $basearch - AppStream (RPMs)
6-
baseurl: https://cdn.redhat.com/content/dist/rhel9/{version}/$basearch/appstream/os
7-
gpgcheck: 1
8-
gpgkey: file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
9-
sslverify: 1
10-
sslcacert: /etc/rhsm/ca/redhat-uep.pem
11-
sslclientkey: /etc/pki/entitlement/739925021166662112-key.pem
12-
sslclientcert: /etc/pki/entitlement/739925021166662112.pem
13-
sslverifystatus: 1
14-
varsFromContainerfile: must-gather.konflux.Dockerfile
3+
repofiles:
4+
- ./redhat.repo
155

166
packages:
177
# list of rpm names to resolve

.konflux/must-gather/rpms.lock.yaml

Lines changed: 8 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -4,26 +4,19 @@ lockfileVendor: redhat
44
arches:
55
- arch: x86_64
66
packages:
7-
- url: https://cdn.redhat.com/content/dist/rhel9/9.4/x86_64/baseos/os/Packages/p/procps-ng-3.3.17-14.el9.x86_64.rpm
8-
repoid: rhel-9-for-x86_64-baseos-rpms
7+
- url: https://cdn.redhat.com/content/eus/rhel9/9.4/x86_64/baseos/os/Packages/p/procps-ng-3.3.17-14.el9.x86_64.rpm
8+
repoid: rhel-9-for-x86_64-baseos-eus-rpms
99
size: 361526
1010
checksum: sha256:506ad778f63821e8d9647ca8e0a3ff21b8af9c1666060d5200f9b26ee718333c
1111
name: procps-ng
1212
evr: 3.3.17-14.el9
1313
sourcerpm: procps-ng-3.3.17-14.el9.src.rpm
14-
- url: https://cdn.redhat.com/content/dist/rhel9/9.4/x86_64/baseos/os/Packages/r/rsync-3.2.3-19.el9.x86_64.rpm
15-
repoid: rhel-9-for-x86_64-baseos-rpms
16-
size: 411313
17-
checksum: sha256:ee29f2138b7f732ba3e552281c4bdf56c71112a17c19dd941135aa56c22cb2c8
14+
- url: https://cdn.redhat.com/content/eus/rhel9/9.4/x86_64/baseos/os/Packages/r/rsync-3.2.3-19.el9_4.1.x86_64.rpm
15+
repoid: rhel-9-for-x86_64-baseos-eus-rpms
16+
size: 409798
17+
checksum: sha256:9202697f872c6bce4e3be7ed61eaa15fc48bf76673ce8f3a48fe94c414a5f783
1818
name: rsync
19-
evr: 3.2.3-19.el9
20-
sourcerpm: rsync-3.2.3-19.el9.src.rpm
21-
- url: https://cdn.redhat.com/content/dist/rhel9/9.4/x86_64/baseos/os/Packages/t/tar-1.34-6.el9_4.1.x86_64.rpm
22-
repoid: rhel-9-for-x86_64-baseos-rpms
23-
size: 910343
24-
checksum: sha256:76f2f5fd1f37153d51a697659db31bd2a672a1a4536b42ce020cf9602ea3cde7
25-
name: tar
26-
evr: 2:1.34-6.el9_4.1
27-
sourcerpm: tar-1.34-6.el9_4.1.src.rpm
19+
evr: 3.2.3-19.el9_4.1
20+
sourcerpm: rsync-3.2.3-19.el9_4.1.src.rpm
2821
source: []
2922
module_metadata: []

.tekton/build-pipeline-must-gather.yaml

Lines changed: 27 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ spec:
1818
- name: name
1919
value: show-sbom
2020
- name: bundle
21-
value: quay.io/konflux-ci/tekton-catalog/task-show-sbom:0.1@sha256:002f7c8c1d2f9e09904035da414aba1188ae091df0ea9532cd997be05e73d594
21+
value: quay.io/konflux-ci/tekton-catalog/task-show-sbom:0.1@sha256:1b1df4da95966d08ac6a5b8198710e09e68b5c2cdc707c37d9d19769e65884b2
2222
- name: kind
2323
value: task
2424
resolver: bundles
@@ -98,6 +98,10 @@ spec:
9898
set of values is determined by the configuration of the multi-platform-controller.
9999
name: build-platforms
100100
type: array
101+
- default: "false"
102+
description: Skip the sast coverity check
103+
name: skip-sast-coverity
104+
type: string
101105
results:
102106
- description: ""
103107
name: IMAGE_URL
@@ -125,7 +129,7 @@ spec:
125129
- name: name
126130
value: init
127131
- name: bundle
128-
value: quay.io/konflux-ci/tekton-catalog/task-init:0.2@sha256:7a24924417260b7094541caaedd2853dc8da08d4bb0968f710a400d3e8062063
132+
value: quay.io/konflux-ci/tekton-catalog/task-init:0.2@sha256:66e90d31e1386bf516fb548cd3e3f0082b5d0234b8b90dbf9e0d4684b70dbe1a
129133
- name: kind
130134
value: task
131135
resolver: bundles
@@ -146,7 +150,7 @@ spec:
146150
- name: name
147151
value: git-clone-oci-ta
148152
- name: bundle
149-
value: quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:8ecf57d5a6697ce709bee65b62781efe79a10b0c2b95e05576442b67fbd61744
153+
value: quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:d35e5d501cb5f5f88369511f76249857cb5ac30250e1dcf086939321964ff6b9
150154
- name: kind
151155
value: task
152156
resolver: bundles
@@ -177,7 +181,7 @@ spec:
177181
- name: name
178182
value: prefetch-dependencies-oci-ta
179183
- name: bundle
180-
value: quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.2@sha256:d48c621ae828a3cbca162e12ec166210d2d77a7ba23b0e5d60c4a1b94491adeb
184+
value: quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.2@sha256:5e15408f997557153b13d492aeccb51c01923bfbe4fbdf6f1e8695ce1b82f826
181185
- name: kind
182186
value: task
183187
resolver: bundles
@@ -227,7 +231,7 @@ spec:
227231
- name: name
228232
value: buildah-remote-oci-ta
229233
- name: bundle
230-
value: quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.4@sha256:6a5f714dd0c301ac421c232d2658e336b862681cf0bcbcbf01ef38d8969664e0
234+
value: quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.4@sha256:5b8d51fa889cdac873750904c3fccc0cca1c4f65af16902ebb2b573151f80657
231235
- name: kind
232236
value: task
233237
resolver: bundles
@@ -256,7 +260,7 @@ spec:
256260
- name: name
257261
value: build-image-index
258262
- name: bundle
259-
value: quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.1@sha256:462ecbf94ec44a8b770d6ef8838955f91f57ee79795e5c18bdc0fcb0df593742
263+
value: quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.1@sha256:846dc9975914f31380ec2712fdbac9df3b06c00a9cc7df678315a7f97145efc2
260264
- name: kind
261265
value: task
262266
resolver: bundles
@@ -280,7 +284,7 @@ spec:
280284
- name: name
281285
value: source-build-oci-ta
282286
- name: bundle
283-
value: quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.2@sha256:56fa2cbfc04bad4765b7fe1fa8022587f4042d4e8533bb5f65311d46b43226ee
287+
value: quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.2@sha256:b424894fc8e806c12658daa565b835fd2d66e7f7608afc47529eb7b410f030d7
284288
- name: kind
285289
value: task
286290
resolver: bundles
@@ -306,7 +310,7 @@ spec:
306310
- name: name
307311
value: deprecated-image-check
308312
- name: bundle
309-
value: quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:eb8136b543147b4a3e88ca3cc661ca6a11e303f35f0db44059f69151beea8496
313+
value: quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:3c8b81fa868e27c6266e7660a4bfb4c822846dcf4304606e71e20893b0d3e515
310314
- name: kind
311315
value: task
312316
resolver: bundles
@@ -328,7 +332,7 @@ spec:
328332
- name: name
329333
value: clair-scan
330334
- name: bundle
331-
value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.2@sha256:7c73e2beca9b8306387efeaf775831440ec799b05a5f5c008a65bb941a1e91f6
335+
value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.2@sha256:d354939892f3a904223ec080cc3771bd11931085a5d202323ea491ee8e8c5e43
332336
- name: kind
333337
value: task
334338
resolver: bundles
@@ -348,7 +352,7 @@ spec:
348352
- name: name
349353
value: ecosystem-cert-preflight-checks
350354
- name: bundle
351-
value: quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:dea8d9b4bec3e99d612d799798acf132df48276164b5193ea68f9f3c25ae425b
355+
value: quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:b550ff4f0b634512ce5200074be7afd7a5a6c05b783620c626e2a3035cd56448
352356
- name: kind
353357
value: task
354358
resolver: bundles
@@ -378,7 +382,7 @@ spec:
378382
- name: name
379383
value: sast-snyk-check-oci-ta
380384
- name: bundle
381-
value: quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4@sha256:89aead32dc21404e4e0913be9668bdd2eea795db3e4caa762fb619044e479cb8
385+
value: quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4@sha256:e61f541189b30d14292ef8df36ccaf13f7feb2378fed5f74cb6293b3e79eb687
382386
- name: kind
383387
value: task
384388
resolver: bundles
@@ -400,7 +404,7 @@ spec:
400404
- name: name
401405
value: clamav-scan
402406
- name: bundle
403-
value: quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.2@sha256:59094118aa07d5b0199565c4e0b2d0f4feb9a4741877c8716877572e2c4804f9
407+
value: quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.2@sha256:9cab95ac9e833d77a63c079893258b73b8d5a298d93aaf9bdd6722471bc2f338
404408
- name: kind
405409
value: task
406410
resolver: bundles
@@ -445,7 +449,7 @@ spec:
445449
- name: name
446450
value: sast-coverity-check-oci-ta
447451
- name: bundle
448-
value: quay.io/konflux-ci/tekton-catalog/task-sast-coverity-check-oci-ta:0.3@sha256:87af64576088ba68f2a5b89998b7ae9e92d7e4f039274e4be6000eff6ce0d95d
452+
value: quay.io/konflux-ci/tekton-catalog/task-sast-coverity-check-oci-ta:0.3@sha256:f9ed979367665223d0539b11542ac174c37cc7fe85d88f05168d9a7a3177475e
449453
- name: kind
450454
value: task
451455
resolver: bundles
@@ -454,6 +458,10 @@ spec:
454458
operator: in
455459
values:
456460
- "false"
461+
- input: $(params.skip-sast-coverity)
462+
operator: in
463+
values:
464+
- "false"
457465
- input: $(tasks.coverity-availability-check.results.STATUS)
458466
operator: in
459467
values:
@@ -466,7 +474,7 @@ spec:
466474
- name: name
467475
value: coverity-availability-check
468476
- name: bundle
469-
value: quay.io/konflux-ci/tekton-catalog/task-coverity-availability-check:0.2@sha256:8b58c4fae00c0dfe3937abfb8a9a61aa3c408cca4278b817db53d518428d944e
477+
value: quay.io/konflux-ci/tekton-catalog/task-coverity-availability-check:0.2@sha256:db2b267dc15e4ed17f704ee91b8e9b38068e1a35b1018a328fdca621819d74c6
470478
- name: kind
471479
value: task
472480
resolver: bundles
@@ -492,7 +500,7 @@ spec:
492500
- name: name
493501
value: sast-shell-check-oci-ta
494502
- name: bundle
495-
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:57b3262138eb06186ae7375f84ca53788bba2a66cfd03d39cb82c78df050aba5
503+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:808bcaf75271db6a999f53fdefb973a385add94a277d37fbd3df68f8ac7dfaa3
496504
- name: kind
497505
value: task
498506
resolver: bundles
@@ -518,7 +526,7 @@ spec:
518526
- name: name
519527
value: sast-unicode-check-oci-ta
520528
- name: bundle
521-
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.2@sha256:df185dbe4e2852668f9c46f938dd752e90ea9c79696363378435a6499596c319
529+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.2@sha256:24ad71fde435fc25abba2c4c550beb088b1530f738d3c377e2f635b5f320d57b
522530
- name: kind
523531
value: task
524532
resolver: bundles
@@ -538,7 +546,7 @@ spec:
538546
- name: name
539547
value: apply-tags
540548
- name: bundle
541-
value: quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.1@sha256:3f89ba89cacf8547261b5ce064acce81bfe470c8ace127794d0e90aebc8c347d
549+
value: quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.1@sha256:1c6f673fe100a49f58aaef62580c8adf0c397790964f4e7bac7fcd3f4d07c92e
542550
- name: kind
543551
value: task
544552
resolver: bundles
@@ -561,7 +569,7 @@ spec:
561569
- name: name
562570
value: push-dockerfile-oci-ta
563571
- name: bundle
564-
value: quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.1@sha256:278f84550844c1c050a65536799f4b54e7c203e0ac51393aa75379dd974c82e9
572+
value: quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.1@sha256:5d8013b6a27bbc5e4ff261144616268f28417ed0950d583ef36349fcd59d3d3d
565573
- name: kind
566574
value: task
567575
resolver: bundles
@@ -578,7 +586,7 @@ spec:
578586
- name: name
579587
value: rpms-signature-scan
580588
- name: bundle
581-
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:297c2d8928aa3b114fcb1ba5d9da8b10226b68fed30706e78a6a5089c6cd30e3
589+
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:1b6c20ab3dbfb0972803d3ebcb2fa72642e59400c77bd66dfd82028bdd09e120
582590
- name: kind
583591
value: task
584592
resolver: bundles

.tekton/numaresources-must-gather-4-20-pull-request.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -42,6 +42,8 @@ spec:
4242
value: "true"
4343
- name: prefetch-input
4444
value: '[{"type": "rpm", "path": ".konflux/must-gather"}]'
45+
- name: skip-sast-coverity
46+
value: "true"
4547
pipelineRef:
4648
name: build-pipeline-must-gather
4749
taskRunTemplate:

.tekton/numaresources-must-gather-4-20-push.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,6 +39,8 @@ spec:
3939
value: "true"
4040
- name: prefetch-input
4141
value: '[{"type": "rpm", "path": ".konflux/must-gather"}]'
42+
- name: skip-sast-coverity
43+
value: "true"
4244
pipelineRef:
4345
name: build-pipeline-must-gather
4446
taskRunTemplate:

0 commit comments

Comments
 (0)