Skip to content

Commit 1a111d6

Browse files
committed
Tekton add sast checks (#911)
1 parent 58e89ae commit 1a111d6

File tree

1 file changed

+50
-0
lines changed

1 file changed

+50
-0
lines changed

.tekton/pipeline-ref.yaml

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -387,6 +387,56 @@ spec:
387387
operator: in
388388
values:
389389
- "false"
390+
- name: sast-shell-check
391+
params:
392+
- name: image-digest
393+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
394+
- name: image-url
395+
value: $(tasks.build-image-index.results.IMAGE_URL)
396+
- name: SOURCE_ARTIFACT
397+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
398+
- name: CACHI2_ARTIFACT
399+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
400+
runAfter:
401+
- build-image-index
402+
taskRef:
403+
params:
404+
- name: name
405+
value: sast-shell-check-oci-ta
406+
- name: bundle
407+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:8e817af22b04305676597a556a975bde8552949ca2bf8918bf62414f135f93c8
408+
- name: kind
409+
value: task
410+
resolver: bundles
411+
when:
412+
- input: $(params.skip-checks)
413+
operator: in
414+
values:
415+
- "false"
416+
- name: sast-unicode-check
417+
params:
418+
- name: image-url
419+
value: $(tasks.build-image-index.results.IMAGE_URL)
420+
- name: SOURCE_ARTIFACT
421+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
422+
- name: CACHI2_ARTIFACT
423+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
424+
runAfter:
425+
- build-image-index
426+
taskRef:
427+
params:
428+
- name: name
429+
value: sast-unicode-check-oci-ta
430+
- name: bundle
431+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.1@sha256:b9c3dfe732a0d9581c75d07d59043f675ddcbe5e9a3152daad99076bedfd5b85
432+
- name: kind
433+
value: task
434+
resolver: bundles
435+
when:
436+
- input: $(params.skip-checks)
437+
operator: in
438+
values:
439+
- "false"
390440
- name: clamav-scan
391441
params:
392442
- name: image-digest

0 commit comments

Comments
 (0)