Skip to content

Commit 10126e1

Browse files
authored
Tekton add sast checks (#816)
1 parent 2ad7bd0 commit 10126e1

File tree

1 file changed

+50
-0
lines changed

1 file changed

+50
-0
lines changed

.tekton/pipeline-ref.yaml

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -384,6 +384,56 @@ spec:
384384
operator: in
385385
values:
386386
- "false"
387+
- name: sast-shell-check
388+
params:
389+
- name: image-digest
390+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
391+
- name: image-url
392+
value: $(tasks.build-image-index.results.IMAGE_URL)
393+
- name: SOURCE_ARTIFACT
394+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
395+
- name: CACHI2_ARTIFACT
396+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
397+
runAfter:
398+
- build-image-index
399+
taskRef:
400+
params:
401+
- name: name
402+
value: sast-shell-check-oci-ta
403+
- name: bundle
404+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:8e817af22b04305676597a556a975bde8552949ca2bf8918bf62414f135f93c8
405+
- name: kind
406+
value: task
407+
resolver: bundles
408+
when:
409+
- input: $(params.skip-checks)
410+
operator: in
411+
values:
412+
- "false"
413+
- name: sast-unicode-check
414+
params:
415+
- name: image-url
416+
value: $(tasks.build-image-index.results.IMAGE_URL)
417+
- name: SOURCE_ARTIFACT
418+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
419+
- name: CACHI2_ARTIFACT
420+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
421+
runAfter:
422+
- build-image-index
423+
taskRef:
424+
params:
425+
- name: name
426+
value: sast-unicode-check-oci-ta
427+
- name: bundle
428+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.1@sha256:b9c3dfe732a0d9581c75d07d59043f675ddcbe5e9a3152daad99076bedfd5b85
429+
- name: kind
430+
value: task
431+
resolver: bundles
432+
when:
433+
- input: $(params.skip-checks)
434+
operator: in
435+
values:
436+
- "false"
387437
- name: clamav-scan
388438
params:
389439
- name: image-digest

0 commit comments

Comments
 (0)