Skip to content

Commit 8f6f247

Browse files
committed
Update cli-build.yaml with new Konflux defaults
Bring in the new params and fresh bundle refs. Useful vimdiff command: vimdiff cli-build.yaml <(yq "{\"spec\":.spec.pipelineSpec}" < cli-v05-pull-request.yaml ) Ref: https://issues.redhat.com/browse/EC-1324
1 parent ef6ef64 commit 8f6f247

File tree

1 file changed

+35
-26
lines changed

1 file changed

+35
-26
lines changed

.tekton/cli-build.yaml

Lines changed: 35 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -71,6 +71,10 @@ spec:
7171
description: Path to a file with build arguments for buildah, see https://www.mankier.com/1/buildah-build#--build-arg-file
7272
name: build-args-file
7373
type: string
74+
- default: "false"
75+
description: Whether to enable privileged mode, should be used only with remote VMs
76+
name: privileged-nested
77+
type: string
7478
results:
7579
- description: ""
7680
name: IMAGE_URL
@@ -123,7 +127,7 @@ spec:
123127
- name: name
124128
value: git-clone-oci-ta
125129
- name: bundle
126-
value: quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:8ecf57d5a6697ce709bee65b62781efe79a10b0c2b95e05576442b67fbd61744
130+
value: quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:0fea1e4bd2fdde46c5b7786629f423a51e357f681c32ceddd744a6e3d48b8327
127131
- name: kind
128132
value: task
129133
resolver: bundles
@@ -154,7 +158,7 @@ spec:
154158
- name: name
155159
value: prefetch-dependencies-oci-ta
156160
- name: bundle
157-
value: quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.2@sha256:1f6e2c9beba52d21c562ba1dea55f579f67e33b80099615bfd2043864896284d
161+
value: quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.2@sha256:adbd819c6b727ac0c5519475d174dcad64cfa8df6ee50acd58f7fb562c59d4f7
158162
- name: kind
159163
value: task
160164
resolver: bundles
@@ -184,6 +188,8 @@ spec:
184188
- $(params.build-args[*])
185189
- name: BUILD_ARGS_FILE
186190
value: "$(params.build-args-file)"
191+
- name: PRIVILEGED_NESTED
192+
value: $(params.privileged-nested)
187193
- name: SOURCE_ARTIFACT
188194
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
189195
- name: CACHI2_ARTIFACT
@@ -351,24 +357,20 @@ spec:
351357
operator: in
352358
values:
353359
- "false"
354-
- name: sast-shell-check
360+
- name: clamav-scan
355361
params:
356362
- name: image-digest
357363
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
358364
- name: image-url
359365
value: $(tasks.build-image-index.results.IMAGE_URL)
360-
- name: SOURCE_ARTIFACT
361-
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
362-
- name: CACHI2_ARTIFACT
363-
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
364366
runAfter:
365367
- build-image-index
366368
taskRef:
367369
params:
368370
- name: name
369-
value: sast-shell-check-oci-ta
371+
value: clamav-scan
370372
- name: bundle
371-
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:a7766190229785bc5db9c62af92d46a83ea580a111b4b64a4e27f6caecae9489
373+
value: quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.2@sha256:386c8c3395b44f6eb927dbad72382808b0ae42008f183064ca77cb4cad998442
372374
- name: kind
373375
value: task
374376
resolver: bundles
@@ -377,9 +379,10 @@ spec:
377379
operator: in
378380
values:
379381
- "false"
380-
workspaces: []
381-
- name: sast-unicode-check
382+
- name: sast-shell-check
382383
params:
384+
- name: image-digest
385+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
383386
- name: image-url
384387
value: $(tasks.build-image-index.results.IMAGE_URL)
385388
- name: SOURCE_ARTIFACT
@@ -391,9 +394,9 @@ spec:
391394
taskRef:
392395
params:
393396
- name: name
394-
value: sast-unicode-check-oci-ta
397+
value: sast-shell-check-oci-ta
395398
- name: bundle
396-
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.2@sha256:9613b9037e4199495800c2054c13d0479e3335ec94e0f15f031a5bce844003a9
399+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:60a7ee6ec5d00920389f03befd328cdaa159b7122a94ff3c87da287e0f32420f
397400
- name: kind
398401
value: task
399402
resolver: bundles
@@ -403,20 +406,24 @@ spec:
403406
values:
404407
- "false"
405408
workspaces: []
406-
- name: clamav-scan
409+
- name: sast-unicode-check
407410
params:
408411
- name: image-digest
409412
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
410413
- name: image-url
411414
value: $(tasks.build-image-index.results.IMAGE_URL)
415+
- name: SOURCE_ARTIFACT
416+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
417+
- name: CACHI2_ARTIFACT
418+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
412419
runAfter:
413420
- build-image-index
414421
taskRef:
415422
params:
416423
- name: name
417-
value: clamav-scan
424+
value: sast-unicode-check-oci-ta
418425
- name: bundle
419-
value: quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.2@sha256:386c8c3395b44f6eb927dbad72382808b0ae42008f183064ca77cb4cad998442
426+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.2@sha256:9613b9037e4199495800c2054c13d0479e3335ec94e0f15f031a5bce844003a9
420427
- name: kind
421428
value: task
422429
resolver: bundles
@@ -425,6 +432,7 @@ spec:
425432
operator: in
426433
values:
427434
- "false"
435+
workspaces: []
428436
- name: apply-tags
429437
params:
430438
- name: IMAGE
@@ -464,26 +472,27 @@ spec:
464472
value: task
465473
resolver: bundles
466474
- name: rpms-signature-scan
467-
when:
468-
- input: $(params.skip-checks)
469-
operator: in
470-
values: ["false"]
475+
params:
476+
- name: image-url
477+
value: $(tasks.build-image-index.results.IMAGE_URL)
478+
- name: image-digest
479+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
471480
runAfter:
472481
- build-image-index
473482
taskRef:
474483
params:
475484
- name: name
476485
value: rpms-signature-scan
477486
- name: bundle
478-
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:80a4562d5f86eb6812f00d4e30e94c1ad27ec937735dc29f5a63e9335676b3dc
487+
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:ec7f6de651458e4a5842b145e761b0d86b03b52bec1515d6d8a1b8cf107af95c
479488
- name: kind
480489
value: task
481490
resolver: bundles
482-
params:
483-
- name: image-url
484-
value: $(tasks.build-image-index.results.IMAGE_URL)
485-
- name: image-digest
486-
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
491+
when:
492+
- input: $(params.skip-checks)
493+
operator: in
494+
values:
495+
- "false"
487496
workspaces:
488497
- name: git-auth
489498
optional: true

0 commit comments

Comments
 (0)