Skip to content

Commit 31be494

Browse files
committed
Add shell and unicode sast pipeline tasks
https://issues.redhat.com/browse/KONFLUX-2264
1 parent 1a3abdc commit 31be494

File tree

2 files changed

+104
-100
lines changed

2 files changed

+104
-100
lines changed

.tekton/registry-viewer-main-pull-request.yaml

Lines changed: 52 additions & 50 deletions
Original file line numberDiff line numberDiff line change
@@ -379,6 +379,58 @@ spec:
379379
operator: in
380380
values:
381381
- "false"
382+
- name: sast-shell-check
383+
params:
384+
- name: image-digest
385+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
386+
- name: image-url
387+
value: $(tasks.build-image-index.results.IMAGE_URL)
388+
- name: SOURCE_ARTIFACT
389+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
390+
- name: CACHI2_ARTIFACT
391+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
392+
runAfter:
393+
- build-image-index
394+
taskRef:
395+
params:
396+
- name: name
397+
value: sast-shell-check-oci-ta
398+
- name: bundle
399+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:a591675c72f06fb9c5b1a3d60e6e4c58e4df5f7da180c7a4691a692a6e7e6496
400+
- name: kind
401+
value: task
402+
resolver: bundles
403+
when:
404+
- input: $(params.skip-checks)
405+
operator: in
406+
values:
407+
- "false"
408+
workspaces: []
409+
- name: sast-unicode-check
410+
params:
411+
- name: image-url
412+
value: $(tasks.build-image-index.results.IMAGE_URL)
413+
- name: SOURCE_ARTIFACT
414+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
415+
- name: CACHI2_ARTIFACT
416+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
417+
runAfter:
418+
- build-image-index
419+
taskRef:
420+
params:
421+
- name: name
422+
value: sast-unicode-check-oci-ta
423+
- name: bundle
424+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.1@sha256:424f2f659c02998dc3a43e1ce869e3148982c59adb74f953f8fa91ff1c9ab86e
425+
- name: kind
426+
value: task
427+
resolver: bundles
428+
when:
429+
- input: $(params.skip-checks)
430+
operator: in
431+
values:
432+
- "false"
433+
workspaces: []
382434
- name: clamav-scan
383435
params:
384436
- name: image-digest
@@ -465,56 +517,6 @@ spec:
465517
operator: in
466518
values:
467519
- "false"
468-
- name: sast-shell-check
469-
params:
470-
- name: image-digest
471-
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
472-
- name: image-url
473-
value: $(tasks.build-image-index.results.IMAGE_URL)
474-
- name: SOURCE_ARTIFACT
475-
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
476-
- name: CACHI2_ARTIFACT
477-
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
478-
runAfter:
479-
- build-image-index
480-
taskRef:
481-
params:
482-
- name: name
483-
value: sast-shell-check-oci-ta
484-
- name: bundle
485-
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:a591675c72f06fb9c5b1a3d60e6e4c58e4df5f7da180c7a4691a692a6e7e6496
486-
- name: kind
487-
value: task
488-
resolver: bundles
489-
when:
490-
- input: $(params.skip-checks)
491-
operator: in
492-
values:
493-
- "false"
494-
- name: sast-unicode-check
495-
params:
496-
- name: image-url
497-
value: $(tasks.build-image-index.results.IMAGE_URL)
498-
- name: SOURCE_ARTIFACT
499-
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
500-
- name: CACHI2_ARTIFACT
501-
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
502-
runAfter:
503-
- build-image-index
504-
taskRef:
505-
params:
506-
- name: name
507-
value: sast-shell-check-oci-ta
508-
- name: bundle
509-
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:a591675c72f06fb9c5b1a3d60e6e4c58e4df5f7da180c7a4691a692a6e7e6496
510-
- name: kind
511-
value: task
512-
resolver: bundles
513-
when:
514-
- input: $(params.skip-checks)
515-
operator: in
516-
values:
517-
- "false"
518520
- name: apply-tags
519521
params:
520522
- name: IMAGE

.tekton/registry-viewer-main-push.yaml

Lines changed: 52 additions & 50 deletions
Original file line numberDiff line numberDiff line change
@@ -376,6 +376,58 @@ spec:
376376
operator: in
377377
values:
378378
- "false"
379+
- name: sast-shell-check
380+
params:
381+
- name: image-digest
382+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
383+
- name: image-url
384+
value: $(tasks.build-image-index.results.IMAGE_URL)
385+
- name: SOURCE_ARTIFACT
386+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
387+
- name: CACHI2_ARTIFACT
388+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
389+
runAfter:
390+
- build-image-index
391+
taskRef:
392+
params:
393+
- name: name
394+
value: sast-shell-check-oci-ta
395+
- name: bundle
396+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:a591675c72f06fb9c5b1a3d60e6e4c58e4df5f7da180c7a4691a692a6e7e6496
397+
- name: kind
398+
value: task
399+
resolver: bundles
400+
when:
401+
- input: $(params.skip-checks)
402+
operator: in
403+
values:
404+
- "false"
405+
workspaces: []
406+
- name: sast-unicode-check
407+
params:
408+
- name: image-url
409+
value: $(tasks.build-image-index.results.IMAGE_URL)
410+
- name: SOURCE_ARTIFACT
411+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
412+
- name: CACHI2_ARTIFACT
413+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
414+
runAfter:
415+
- build-image-index
416+
taskRef:
417+
params:
418+
- name: name
419+
value: sast-unicode-check-oci-ta
420+
- name: bundle
421+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.1@sha256:424f2f659c02998dc3a43e1ce869e3148982c59adb74f953f8fa91ff1c9ab86e
422+
- name: kind
423+
value: task
424+
resolver: bundles
425+
when:
426+
- input: $(params.skip-checks)
427+
operator: in
428+
values:
429+
- "false"
430+
workspaces: []
379431
- name: clamav-scan
380432
params:
381433
- name: image-digest
@@ -462,56 +514,6 @@ spec:
462514
operator: in
463515
values:
464516
- "false"
465-
- name: sast-shell-check
466-
params:
467-
- name: image-digest
468-
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
469-
- name: image-url
470-
value: $(tasks.build-image-index.results.IMAGE_URL)
471-
- name: SOURCE_ARTIFACT
472-
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
473-
- name: CACHI2_ARTIFACT
474-
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
475-
runAfter:
476-
- build-image-index
477-
taskRef:
478-
params:
479-
- name: name
480-
value: sast-shell-check-oci-ta
481-
- name: bundle
482-
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:a591675c72f06fb9c5b1a3d60e6e4c58e4df5f7da180c7a4691a692a6e7e6496
483-
- name: kind
484-
value: task
485-
resolver: bundles
486-
when:
487-
- input: $(params.skip-checks)
488-
operator: in
489-
values:
490-
- "false"
491-
- name: sast-unicode-check
492-
params:
493-
- name: image-url
494-
value: $(tasks.build-image-index.results.IMAGE_URL)
495-
- name: SOURCE_ARTIFACT
496-
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
497-
- name: CACHI2_ARTIFACT
498-
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
499-
runAfter:
500-
- build-image-index
501-
taskRef:
502-
params:
503-
- name: name
504-
value: sast-shell-check-oci-ta
505-
- name: bundle
506-
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:a591675c72f06fb9c5b1a3d60e6e4c58e4df5f7da180c7a4691a692a6e7e6496
507-
- name: kind
508-
value: task
509-
resolver: bundles
510-
when:
511-
- input: $(params.skip-checks)
512-
operator: in
513-
values:
514-
- "false"
515517
- name: apply-tags
516518
params:
517519
- name: IMAGE

0 commit comments

Comments
 (0)