7171 description : Path to a file with build arguments for buildah, see https://www.mankier.com/1/buildah-build#--build-arg-file
7272 name : build-args-file
7373 type : string
74+ - default : " false"
75+ description : Whether to enable privileged mode, should be used only with remote VMs
76+ name : privileged-nested
77+ type : string
7478 results :
7579 - description : " "
7680 name : IMAGE_URL
@@ -123,7 +127,7 @@ spec:
123127 - name : name
124128 value : git-clone-oci-ta
125129 - name : bundle
126- value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:8ecf57d5a6697ce709bee65b62781efe79a10b0c2b95e05576442b67fbd61744
130+ value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:0fea1e4bd2fdde46c5b7786629f423a51e357f681c32ceddd744a6e3d48b8327
127131 - name : kind
128132 value : task
129133 resolver : bundles
@@ -154,7 +158,7 @@ spec:
154158 - name : name
155159 value : prefetch-dependencies-oci-ta
156160 - name : bundle
157- value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.2@sha256:1f6e2c9beba52d21c562ba1dea55f579f67e33b80099615bfd2043864896284d
161+ value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.2@sha256:adbd819c6b727ac0c5519475d174dcad64cfa8df6ee50acd58f7fb562c59d4f7
158162 - name : kind
159163 value : task
160164 resolver : bundles
@@ -184,6 +188,8 @@ spec:
184188 - $(params.build-args[*])
185189 - name : BUILD_ARGS_FILE
186190 value : " $(params.build-args-file)"
191+ - name : PRIVILEGED_NESTED
192+ value : $(params.privileged-nested)
187193 - name : SOURCE_ARTIFACT
188194 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
189195 - name : CACHI2_ARTIFACT
@@ -351,24 +357,20 @@ spec:
351357 operator : in
352358 values :
353359 - " false"
354- - name : sast-shell-check
360+ - name : clamav-scan
355361 params :
356362 - name : image-digest
357363 value : $(tasks.build-image-index.results.IMAGE_DIGEST)
358364 - name : image-url
359365 value : $(tasks.build-image-index.results.IMAGE_URL)
360- - name : SOURCE_ARTIFACT
361- value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
362- - name : CACHI2_ARTIFACT
363- value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
364366 runAfter :
365367 - build-image-index
366368 taskRef :
367369 params :
368370 - name : name
369- value : sast-shell-check-oci-ta
371+ value : clamav-scan
370372 - name : bundle
371- value : quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta :0.1 @sha256:a7766190229785bc5db9c62af92d46a83ea580a111b4b64a4e27f6caecae9489
373+ value : quay.io/konflux-ci/tekton-catalog/task-clamav-scan :0.2 @sha256:386c8c3395b44f6eb927dbad72382808b0ae42008f183064ca77cb4cad998442
372374 - name : kind
373375 value : task
374376 resolver : bundles
@@ -377,9 +379,10 @@ spec:
377379 operator : in
378380 values :
379381 - " false"
380- workspaces : []
381- - name : sast-unicode-check
382+ - name : sast-shell-check
382383 params :
384+ - name : image-digest
385+ value : $(tasks.build-image-index.results.IMAGE_DIGEST)
383386 - name : image-url
384387 value : $(tasks.build-image-index.results.IMAGE_URL)
385388 - name : SOURCE_ARTIFACT
@@ -391,9 +394,9 @@ spec:
391394 taskRef :
392395 params :
393396 - name : name
394- value : sast-unicode -check-oci-ta
397+ value : sast-shell -check-oci-ta
395398 - name : bundle
396- value : quay.io/konflux-ci/tekton-catalog/task-sast-unicode -check-oci-ta:0.2 @sha256:9613b9037e4199495800c2054c13d0479e3335ec94e0f15f031a5bce844003a9
399+ value : quay.io/konflux-ci/tekton-catalog/task-sast-shell -check-oci-ta:0.1 @sha256:60a7ee6ec5d00920389f03befd328cdaa159b7122a94ff3c87da287e0f32420f
397400 - name : kind
398401 value : task
399402 resolver : bundles
@@ -403,20 +406,24 @@ spec:
403406 values :
404407 - " false"
405408 workspaces : []
406- - name : clamav-scan
409+ - name : sast-unicode-check
407410 params :
408411 - name : image-digest
409412 value : $(tasks.build-image-index.results.IMAGE_DIGEST)
410413 - name : image-url
411414 value : $(tasks.build-image-index.results.IMAGE_URL)
415+ - name : SOURCE_ARTIFACT
416+ value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
417+ - name : CACHI2_ARTIFACT
418+ value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
412419 runAfter :
413420 - build-image-index
414421 taskRef :
415422 params :
416423 - name : name
417- value : clamav-scan
424+ value : sast-unicode-check-oci-ta
418425 - name : bundle
419- value : quay.io/konflux-ci/tekton-catalog/task-clamav-scan :0.2@sha256:386c8c3395b44f6eb927dbad72382808b0ae42008f183064ca77cb4cad998442
426+ value : quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta :0.2@sha256:9613b9037e4199495800c2054c13d0479e3335ec94e0f15f031a5bce844003a9
420427 - name : kind
421428 value : task
422429 resolver : bundles
@@ -425,6 +432,7 @@ spec:
425432 operator : in
426433 values :
427434 - " false"
435+ workspaces : []
428436 - name : apply-tags
429437 params :
430438 - name : IMAGE
@@ -464,26 +472,27 @@ spec:
464472 value : task
465473 resolver : bundles
466474 - name : rpms-signature-scan
467- when :
468- - input : $(params.skip-checks)
469- operator : in
470- values : ["false"]
475+ params :
476+ - name : image-url
477+ value : $(tasks.build-image-index.results.IMAGE_URL)
478+ - name : image-digest
479+ value : $(tasks.build-image-index.results.IMAGE_DIGEST)
471480 runAfter :
472481 - build-image-index
473482 taskRef :
474483 params :
475484 - name : name
476485 value : rpms-signature-scan
477486 - name : bundle
478- value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:80a4562d5f86eb6812f00d4e30e94c1ad27ec937735dc29f5a63e9335676b3dc
487+ value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:ec7f6de651458e4a5842b145e761b0d86b03b52bec1515d6d8a1b8cf107af95c
479488 - name : kind
480489 value : task
481490 resolver : bundles
482- params :
483- - name : image-url
484- value : $(tasks.build-image-index.results.IMAGE_URL)
485- - name : image-digest
486- value : $(tasks.build-image-index.results.IMAGE_DIGEST)
491+ when :
492+ - input : $(params.skip-checks)
493+ operator : in
494+ values :
495+ - " false "
487496 workspaces :
488497 - name : git-auth
489498 optional : true
0 commit comments