@@ -6,6 +6,7 @@ metadata:
6
6
build.appstudio.redhat.com/commit_sha : ' {{revision}}'
7
7
build.appstudio.redhat.com/pull_request_number : ' {{pull_request_number}}'
8
8
build.appstudio.redhat.com/target_branch : ' {{target_branch}}'
9
+ pipelinesascode.tekton.dev/cancel-in-progress : " true"
9
10
pipelinesascode.tekton.dev/max-keep-runs : " 3"
10
11
pipelinesascode.tekton.dev/on-cel-expression : event == "pull_request" && target_branch
11
12
== "release-4.18"
44
45
- name : name
45
46
value : show-sbom
46
47
- name : bundle
47
- value : quay.io/konflux-ci/tekton-catalog/task-show-sbom:0.1@sha256:04f15cbce548e1db7770eee3f155ccb2cc0140a6c371dc67e9a34d83673ea0c0
48
+ value : quay.io/konflux-ci/tekton-catalog/task-show-sbom:0.1@sha256:002f7c8c1d2f9e09904035da414aba1188ae091df0ea9532cd997be05e73d594
48
49
- name : kind
49
50
value : task
50
51
resolver : bundles
@@ -105,6 +106,11 @@ spec:
105
106
description : Path to a file with build arguments for buildah, see https://www.mankier.com/1/buildah-build#--build-arg-file
106
107
name : build-args-file
107
108
type : string
109
+ - default : " false"
110
+ description : Whether to enable privileged mode, should be used only with remote
111
+ VMs
112
+ name : privileged-nested
113
+ type : string
108
114
- default :
109
115
- linux/x86_64
110
116
- linux/arm64
@@ -141,7 +147,7 @@ spec:
141
147
- name : name
142
148
value : init
143
149
- name : bundle
144
- value : quay.io/konflux-ci/tekton-catalog/task-init:0.2@sha256:38660e69f8a8b8bedc0264964d8811e1faaaaaa03a9fc908e811bf8f705f393a
150
+ value : quay.io/konflux-ci/tekton-catalog/task-init:0.2@sha256:7a24924417260b7094541caaedd2853dc8da08d4bb0968f710a400d3e8062063
145
151
- name : kind
146
152
value : task
147
153
resolver : bundles
@@ -162,7 +168,7 @@ spec:
162
168
- name : name
163
169
value : git-clone-oci-ta
164
170
- name : bundle
165
- value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:88367f7e80d282237f6cbe9bcc76ac9a72c3f379983d3c3ccba21d767da7d49f
171
+ value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:8ecf57d5a6697ce709bee65b62781efe79a10b0c2b95e05576442b67fbd61744
166
172
- name : kind
167
173
value : task
168
174
resolver : bundles
@@ -191,7 +197,7 @@ spec:
191
197
- name : name
192
198
value : prefetch-dependencies-oci-ta
193
199
- name : bundle
194
- value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.2@sha256:153ef0382deef840d155f5146f134f39b480523a7d5c38ba9fea2b58792dd4b5
200
+ value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.2@sha256:d48c621ae828a3cbca162e12ec166210d2d77a7ba23b0e5d60c4a1b94491adeb
195
201
- name : kind
196
202
value : task
197
203
resolver : bundles
@@ -226,6 +232,8 @@ spec:
226
232
- $(params.build-args[*])
227
233
- name : BUILD_ARGS_FILE
228
234
value : $(params.build-args-file)
235
+ - name : PRIVILEGED_NESTED
236
+ value : $(params.privileged-nested)
229
237
- name : SOURCE_ARTIFACT
230
238
value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
231
239
- name : CACHI2_ARTIFACT
@@ -239,7 +247,7 @@ spec:
239
247
- name : name
240
248
value : buildah-remote-oci-ta
241
249
- name : bundle
242
- value : quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.4@sha256:57a4a8b37d7bf486f419b4a6a540cdffafb27717935b05a91f12d6d9cf663b74
250
+ value : quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.4@sha256:6a5f714dd0c301ac421c232d2658e336b862681cf0bcbcbf01ef38d8969664e0
243
251
- name : kind
244
252
value : task
245
253
resolver : bundles
@@ -268,7 +276,7 @@ spec:
268
276
- name : name
269
277
value : build-image-index
270
278
- name : bundle
271
- value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.1@sha256:4d5ab47286c1c7ac525786c9a4d0cce9fc73f22635cd623f1d2d12ebc76d83e5
279
+ value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.1@sha256:462ecbf94ec44a8b770d6ef8838955f91f57ee79795e5c18bdc0fcb0df593742
272
280
- name : kind
273
281
value : task
274
282
resolver : bundles
@@ -292,7 +300,7 @@ spec:
292
300
- name : name
293
301
value : source-build-oci-ta
294
302
- name : bundle
295
- value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.2@sha256:f0e6c6fc5f101ecc660f744757f30ddcb5856d63299d86be5f1a772b85326f48
303
+ value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.2@sha256:56fa2cbfc04bad4765b7fe1fa8022587f4042d4e8533bb5f65311d46b43226ee
296
304
- name : kind
297
305
value : task
298
306
resolver : bundles
@@ -318,7 +326,7 @@ spec:
318
326
- name : name
319
327
value : deprecated-image-check
320
328
- name : bundle
321
- value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:5d63b920b71192906fe4d6c4903f594e6f34c5edcff9d21714a08b5edcfbc667
329
+ value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:eb8136b543147b4a3e88ca3cc661ca6a11e303f35f0db44059f69151beea8496
322
330
- name : kind
323
331
value : task
324
332
resolver : bundles
@@ -340,7 +348,7 @@ spec:
340
348
- name : name
341
349
value : clair-scan
342
350
- name : bundle
343
- value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.2@sha256:712afcf63f3b5a97c371d37e637efbcc9e1c7ad158872339d00adc6413cd8851
351
+ value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.2@sha256:7c73e2beca9b8306387efeaf775831440ec799b05a5f5c008a65bb941a1e91f6
344
352
- name : kind
345
353
value : task
346
354
resolver : bundles
@@ -360,7 +368,7 @@ spec:
360
368
- name : name
361
369
value : ecosystem-cert-preflight-checks
362
370
- name : bundle
363
- value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:00b13d06d17328e105b11619ee4db98b215ca6ac02314a4776aa5fc2a974f9c1
371
+ value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:dea8d9b4bec3e99d612d799798acf132df48276164b5193ea68f9f3c25ae425b
364
372
- name : kind
365
373
value : task
366
374
resolver : bundles
@@ -386,7 +394,7 @@ spec:
386
394
- name : name
387
395
value : sast-snyk-check-oci-ta
388
396
- name : bundle
389
- value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.3 @sha256:a1cb59ed66a7be1949c9720660efb0a006e95ef05b3f67929dd8e310e1d7baef
397
+ value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4 @sha256:89aead32dc21404e4e0913be9668bdd2eea795db3e4caa762fb619044e479cb8
390
398
- name : kind
391
399
value : task
392
400
resolver : bundles
@@ -408,7 +416,7 @@ spec:
408
416
- name : name
409
417
value : clamav-scan
410
418
- name : bundle
411
- value : quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.2@sha256:62c835adae22e36fce6684460b39206bc16752f1a4427cdbba4ee9afdd279670
419
+ value : quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.2@sha256:59094118aa07d5b0199565c4e0b2d0f4feb9a4741877c8716877572e2c4804f9
412
420
- name : kind
413
421
value : task
414
422
resolver : bundles
@@ -419,6 +427,8 @@ spec:
419
427
- " false"
420
428
- name : sast-coverity-check
421
429
params :
430
+ - name : image-digest
431
+ value : $(tasks.build-image-index.results.IMAGE_DIGEST)
422
432
- name : image-url
423
433
value : $(tasks.build-image-index.results.IMAGE_URL)
424
434
- name : IMAGE
@@ -451,7 +461,7 @@ spec:
451
461
- name : name
452
462
value : sast-coverity-check-oci-ta
453
463
- name : bundle
454
- value : quay.io/konflux-ci/tekton-catalog/task-sast-coverity-check-oci-ta:0.2 @sha256:07cb09253da53235f83d1a2327faebb8505091c509fc1e3af12a43cfe34f63a6
464
+ value : quay.io/konflux-ci/tekton-catalog/task-sast-coverity-check-oci-ta:0.3 @sha256:a9a3c472624d0598c28aaa67319e74a807ac1948946002dd7b181d200e672b8b
455
465
- name : kind
456
466
value : task
457
467
resolver : bundles
@@ -472,7 +482,7 @@ spec:
472
482
- name : name
473
483
value : coverity-availability-check
474
484
- name : bundle
475
- value : quay.io/konflux-ci/tekton-catalog/task-coverity-availability-check:0.2@sha256:aeb4ecc32ed4012686ab370b3417902082b894a9b1e27aa4f6e35a301c50f4cb
485
+ value : quay.io/konflux-ci/tekton-catalog/task-coverity-availability-check:0.2@sha256:8b58c4fae00c0dfe3937abfb8a9a61aa3c408cca4278b817db53d518428d944e
476
486
- name : kind
477
487
value : task
478
488
resolver : bundles
@@ -498,7 +508,7 @@ spec:
498
508
- name : name
499
509
value : sast-shell-check-oci-ta
500
510
- name : bundle
501
- value : quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:a591675c72f06fb9c5b1a3d60e6e4c58e4df5f7da180c7a4691a692a6e7e6496
511
+ value : quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:57b3262138eb06186ae7375f84ca53788bba2a66cfd03d39cb82c78df050aba5
502
512
- name : kind
503
513
value : task
504
514
resolver : bundles
@@ -509,6 +519,8 @@ spec:
509
519
- " false"
510
520
- name : sast-unicode-check
511
521
params :
522
+ - name : image-digest
523
+ value : $(tasks.build-image-index.results.IMAGE_DIGEST)
512
524
- name : image-url
513
525
value : $(tasks.build-image-index.results.IMAGE_URL)
514
526
- name : SOURCE_ARTIFACT
@@ -522,7 +534,7 @@ spec:
522
534
- name : name
523
535
value : sast-unicode-check-oci-ta
524
536
- name : bundle
525
- value : quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.1 @sha256:424f2f659c02998dc3a43e1ce869e3148982c59adb74f953f8fa91ff1c9ab86e
537
+ value : quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.2 @sha256:df185dbe4e2852668f9c46f938dd752e90ea9c79696363378435a6499596c319
526
538
- name : kind
527
539
value : task
528
540
resolver : bundles
@@ -542,7 +554,7 @@ spec:
542
554
- name : name
543
555
value : apply-tags
544
556
- name : bundle
545
- value : quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.1@sha256:4973fa42a8f06238613447fbdb3d0c55eb2d718fd16f2f2591a577c29c1edb17
557
+ value : quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.1@sha256:3f89ba89cacf8547261b5ce064acce81bfe470c8ace127794d0e90aebc8c347d
546
558
- name : kind
547
559
value : task
548
560
resolver : bundles
@@ -565,7 +577,7 @@ spec:
565
577
- name : name
566
578
value : push-dockerfile-oci-ta
567
579
- name : bundle
568
- value : quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.1@sha256:6ad0ae81269fdc4008363993b4d140f98c3e8ff8336be4b6fbacb5005cf7092e
580
+ value : quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.1@sha256:278f84550844c1c050a65536799f4b54e7c203e0ac51393aa75379dd974c82e9
569
581
- name : kind
570
582
value : task
571
583
resolver : bundles
@@ -582,7 +594,7 @@ spec:
582
594
- name : name
583
595
value : rpms-signature-scan
584
596
- name : bundle
585
- value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:998b5466417c324aea94d3e8b302c558aeb13f746976d89a4ff85f1b84a42c2b
597
+ value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:297c2d8928aa3b114fcb1ba5d9da8b10226b68fed30706e78a6a5089c6cd30e3
586
598
- name : kind
587
599
value : task
588
600
resolver : bundles
0 commit comments