Skip to content

Commit 72dd820

Browse files
Added new rpms check task in konflux (#642)
1 parent 58757f4 commit 72dd820

File tree

2 files changed

+24
-4
lines changed

2 files changed

+24
-4
lines changed

.tekton/network-observability-console-plugin-1-7-push.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@ metadata:
66
build.appstudio.redhat.com/commit_sha: '{{revision}}'
77
build.appstudio.redhat.com/target_branch: '{{target_branch}}'
88
pipelinesascode.tekton.dev/max-keep-runs: "3"
9+
build.appstudio.openshift.io/build-nudge-files: "hack/container_digest.sh"
910
pipelinesascode.tekton.dev/on-cel-expression: event == "push" && target_branch
1011
== "release-1.7"
1112
creationTimestamp: null

.tekton/pipeline-ref.yaml

Lines changed: 23 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ spec:
6262
description: Image tag expiration time, time values could be something like
6363
1h, 2d, 3w for hours, days, and weeks, respectively.
6464
name: image-expires-after
65-
- default: "false"
65+
- default: "true"
6666
description: Build a source image.
6767
name: build-source-image
6868
type: string
@@ -250,15 +250,12 @@ spec:
250250
operator: in
251251
values:
252252
- "true"
253-
254253
- name: build-source-image
255254
params:
256255
- name: BINARY_IMAGE
257256
value: $(params.output-image)
258257
- name: SOURCE_ARTIFACT
259258
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
260-
- name: CACHI2_ARTIFACT
261-
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
262259
runAfter:
263260
- build-image-index
264261
taskRef:
@@ -279,6 +276,28 @@ spec:
279276
operator: in
280277
values:
281278
- "true"
279+
- name: rpms-signature-scan
280+
params:
281+
- name: image-url
282+
value: $(tasks.build-image-index.results.IMAGE_URL)
283+
- name: image-digest
284+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
285+
runAfter:
286+
- build-image-index
287+
taskRef:
288+
params:
289+
- name: name
290+
value: rpms-signature-scan
291+
- name: bundle
292+
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8
293+
- name: kind
294+
value: task
295+
resolver: bundles
296+
when:
297+
- input: $(params.skip-checks)
298+
operator: in
299+
values:
300+
- "false"
282301
- name: deprecated-base-image-check
283302
params:
284303
- name: IMAGE_URL

0 commit comments

Comments
 (0)