@@ -6,15 +6,16 @@ metadata:
6
6
build.appstudio.redhat.com/commit_sha : ' {{revision}}'
7
7
build.appstudio.redhat.com/pull_request_number : ' {{pull_request_number}}'
8
8
build.appstudio.redhat.com/target_branch : ' {{target_branch}}'
9
+ pipelinesascode.tekton.dev/cancel-in-progress : " true"
9
10
pipelinesascode.tekton.dev/max-keep-runs : " 3"
10
11
pipelinesascode.tekton.dev/on-cel-expression : event == "pull_request" && target_branch
11
- == "release-4.18 "
12
+ == "release-4.19 "
12
13
creationTimestamp : null
13
14
labels :
14
- appstudio.openshift.io/application : kube-descheduler-operator-4-18
15
- appstudio.openshift.io/component : kube-descheduler-operator-bundle-4-18
15
+ appstudio.openshift.io/application : kube-descheduler-operator-4-19
16
+ appstudio.openshift.io/component : kube-descheduler-operator-bundle-4-19
16
17
pipelines.appstudio.openshift.io/type : build
17
- name : kube-descheduler-operator-bundle-4-18 -on-pull-request
18
+ name : kube-descheduler-operator-bundle-4-19 -on-pull-request
18
19
namespace : kdo-workloads-tenant
19
20
spec :
20
21
params :
23
24
- name : revision
24
25
value : ' {{revision}}'
25
26
- name : output-image
26
- value : quay.io/redhat-user-workloads/kdo-workloads-tenant/kube-descheduler-operator-bundle-4-18 :on-pr-{{revision}}
27
+ value : quay.io/redhat-user-workloads/kdo-workloads-tenant/kube-descheduler-operator-bundle-4-19 :on-pr-{{revision}}
27
28
- name : image-expires-after
28
29
value : 5d
29
30
- name : dockerfile
44
45
- name : name
45
46
value : show-sbom
46
47
- name : bundle
47
- value : quay.io/konflux-ci/tekton-catalog/task-show-sbom:0.1@sha256:945a7c9066d3e0a95d3fddb7e8a6992e4d632a2a75d8f3a9bd2ff2fef0ec9aa0
48
+ value : quay.io/konflux-ci/tekton-catalog/task-show-sbom:0.1@sha256:002f7c8c1d2f9e09904035da414aba1188ae091df0ea9532cd997be05e73d594
48
49
- name : kind
49
50
value : task
50
51
resolver : bundles
@@ -105,6 +106,11 @@ spec:
105
106
description : Path to a file with build arguments for buildah, see https://www.mankier.com/1/buildah-build#--build-arg-file
106
107
name : build-args-file
107
108
type : string
109
+ - default : " false"
110
+ description : Whether to enable privileged mode, should be used only with remote
111
+ VMs
112
+ name : privileged-nested
113
+ type : string
108
114
results :
109
115
- description : " "
110
116
name : IMAGE_URL
@@ -132,7 +138,7 @@ spec:
132
138
- name : name
133
139
value : init
134
140
- name : bundle
135
- value : quay.io/konflux-ci/tekton-catalog/task-init:0.2@sha256:0523b51c28375a3f222da91690e22eff11888ebc98a0c73c468af44762265c69
141
+ value : quay.io/konflux-ci/tekton-catalog/task-init:0.2@sha256:7a24924417260b7094541caaedd2853dc8da08d4bb0968f710a400d3e8062063
136
142
- name : kind
137
143
value : task
138
144
resolver : bundles
@@ -153,7 +159,7 @@ spec:
153
159
- name : name
154
160
value : git-clone-oci-ta
155
161
- name : bundle
156
- value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:4bf48d038ff12d25bdeb5ab3e98dc2271818056f454c83d7393ebbd413028147
162
+ value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:8ecf57d5a6697ce709bee65b62781efe79a10b0c2b95e05576442b67fbd61744
157
163
- name : kind
158
164
value : task
159
165
resolver : bundles
@@ -182,7 +188,7 @@ spec:
182
188
- name : name
183
189
value : prefetch-dependencies-oci-ta
184
190
- name : bundle
185
- value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.1 @sha256:b1ac9124ad909a8d7dbac01b1a02ef9a973d448d4c94efcf3d1b29e2a5c9e76f
191
+ value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.2 @sha256:d48c621ae828a3cbca162e12ec166210d2d77a7ba23b0e5d60c4a1b94491adeb
186
192
- name : kind
187
193
value : task
188
194
resolver : bundles
@@ -212,6 +218,8 @@ spec:
212
218
- $(params.build-args[*])
213
219
- name : BUILD_ARGS_FILE
214
220
value : $(params.build-args-file)
221
+ - name : PRIVILEGED_NESTED
222
+ value : $(params.privileged-nested)
215
223
- name : SOURCE_ARTIFACT
216
224
value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
217
225
- name : CACHI2_ARTIFACT
@@ -223,7 +231,7 @@ spec:
223
231
- name : name
224
232
value : buildah-oci-ta
225
233
- name : bundle
226
- value : quay.io/konflux-ci/tekton-catalog/task-buildah-oci-ta:0.2 @sha256:ea5f13f235f98e9f0da599439f0b62b729901a5b6ad8d673daf3821f3f9cb66f
234
+ value : quay.io/konflux-ci/tekton-catalog/task-buildah-oci-ta:0.4 @sha256:6ac9d16f598c14a4b56e662eccda0a438e94aa8f87dd27a3ea0ff1abc6e00c66
227
235
- name : kind
228
236
value : task
229
237
resolver : bundles
@@ -252,7 +260,7 @@ spec:
252
260
- name : name
253
261
value : build-image-index
254
262
- name : bundle
255
- value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.1@sha256:ebc17bb22481160eec6eb7277df1e48b90f599bebe563cd4f046807f4e32ced3
263
+ value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.1@sha256:462ecbf94ec44a8b770d6ef8838955f91f57ee79795e5c18bdc0fcb0df593742
256
264
- name : kind
257
265
value : task
258
266
resolver : bundles
@@ -276,7 +284,7 @@ spec:
276
284
- name : name
277
285
value : source-build-oci-ta
278
286
- name : bundle
279
- value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.1 @sha256:bd786bc1d33391bb169f98a1070d1a39e410b835f05fd0db0263754c65bd9bea
287
+ value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.2 @sha256:56fa2cbfc04bad4765b7fe1fa8022587f4042d4e8533bb5f65311d46b43226ee
280
288
- name : kind
281
289
value : task
282
290
resolver : bundles
@@ -302,7 +310,7 @@ spec:
302
310
- name : name
303
311
value : deprecated-image-check
304
312
- name : bundle
305
- value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.4 @sha256:5a1a165fa02270f0a947d8a2131ee9d8be0b8e9d34123828c2bef589e504ee84
313
+ value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5 @sha256:eb8136b543147b4a3e88ca3cc661ca6a11e303f35f0db44059f69151beea8496
306
314
- name : kind
307
315
value : task
308
316
resolver : bundles
@@ -324,7 +332,7 @@ spec:
324
332
- name : name
325
333
value : clair-scan
326
334
- name : bundle
327
- value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.2@sha256:0a5421111e7092740398691d5bd7c125cc0896f29531d19414bb5724ae41692a
335
+ value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.2@sha256:7c73e2beca9b8306387efeaf775831440ec799b05a5f5c008a65bb941a1e91f6
328
336
- name : kind
329
337
value : task
330
338
resolver : bundles
@@ -344,7 +352,7 @@ spec:
344
352
- name : name
345
353
value : ecosystem-cert-preflight-checks
346
354
- name : bundle
347
- value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.1 @sha256:df8a25a3431a70544172ed4844f9d0c6229d39130633960729f825a031a7dea9
355
+ value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2 @sha256:dea8d9b4bec3e99d612d799798acf132df48276164b5193ea68f9f3c25ae425b
348
356
- name : kind
349
357
value : task
350
358
resolver : bundles
@@ -370,7 +378,7 @@ spec:
370
378
- name : name
371
379
value : sast-snyk-check-oci-ta
372
380
- name : bundle
373
- value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.2 @sha256:22ca2db8d94c689dba03d2c257733743cd118759d7af9a68fb08f54a27fd8460
381
+ value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4 @sha256:89aead32dc21404e4e0913be9668bdd2eea795db3e4caa762fb619044e479cb8
374
382
- name : kind
375
383
value : task
376
384
resolver : bundles
@@ -392,7 +400,125 @@ spec:
392
400
- name : name
393
401
value : clamav-scan
394
402
- name : bundle
395
- value : quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.1@sha256:b4f450f1447b166da671f1d5819ab5a1485083e5c27ab91f7d8b7a2ff994c8c2
403
+ value : quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.2@sha256:59094118aa07d5b0199565c4e0b2d0f4feb9a4741877c8716877572e2c4804f9
404
+ - name : kind
405
+ value : task
406
+ resolver : bundles
407
+ when :
408
+ - input : $(params.skip-checks)
409
+ operator : in
410
+ values :
411
+ - " false"
412
+ - name : sast-coverity-check
413
+ params :
414
+ - name : image-digest
415
+ value : $(tasks.build-image-index.results.IMAGE_DIGEST)
416
+ - name : image-url
417
+ value : $(tasks.build-image-index.results.IMAGE_URL)
418
+ - name : IMAGE
419
+ value : $(params.output-image)
420
+ - name : DOCKERFILE
421
+ value : $(params.dockerfile)
422
+ - name : CONTEXT
423
+ value : $(params.path-context)
424
+ - name : HERMETIC
425
+ value : $(params.hermetic)
426
+ - name : PREFETCH_INPUT
427
+ value : $(params.prefetch-input)
428
+ - name : IMAGE_EXPIRES_AFTER
429
+ value : $(params.image-expires-after)
430
+ - name : COMMIT_SHA
431
+ value : $(tasks.clone-repository.results.commit)
432
+ - name : BUILD_ARGS
433
+ value :
434
+ - $(params.build-args[*])
435
+ - name : BUILD_ARGS_FILE
436
+ value : $(params.build-args-file)
437
+ - name : SOURCE_ARTIFACT
438
+ value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
439
+ - name : CACHI2_ARTIFACT
440
+ value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
441
+ runAfter :
442
+ - coverity-availability-check
443
+ taskRef :
444
+ params :
445
+ - name : name
446
+ value : sast-coverity-check-oci-ta
447
+ - name : bundle
448
+ value : quay.io/konflux-ci/tekton-catalog/task-sast-coverity-check-oci-ta:0.3@sha256:87af64576088ba68f2a5b89998b7ae9e92d7e4f039274e4be6000eff6ce0d95d
449
+ - name : kind
450
+ value : task
451
+ resolver : bundles
452
+ when :
453
+ - input : $(params.skip-checks)
454
+ operator : in
455
+ values :
456
+ - " false"
457
+ - input : $(tasks.coverity-availability-check.results.STATUS)
458
+ operator : in
459
+ values :
460
+ - success
461
+ - name : coverity-availability-check
462
+ runAfter :
463
+ - build-image-index
464
+ taskRef :
465
+ params :
466
+ - name : name
467
+ value : coverity-availability-check
468
+ - name : bundle
469
+ value : quay.io/konflux-ci/tekton-catalog/task-coverity-availability-check:0.2@sha256:8b58c4fae00c0dfe3937abfb8a9a61aa3c408cca4278b817db53d518428d944e
470
+ - name : kind
471
+ value : task
472
+ resolver : bundles
473
+ when :
474
+ - input : $(params.skip-checks)
475
+ operator : in
476
+ values :
477
+ - " false"
478
+ - name : sast-shell-check
479
+ params :
480
+ - name : image-digest
481
+ value : $(tasks.build-image-index.results.IMAGE_DIGEST)
482
+ - name : image-url
483
+ value : $(tasks.build-image-index.results.IMAGE_URL)
484
+ - name : SOURCE_ARTIFACT
485
+ value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
486
+ - name : CACHI2_ARTIFACT
487
+ value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
488
+ runAfter :
489
+ - build-image-index
490
+ taskRef :
491
+ params :
492
+ - name : name
493
+ value : sast-shell-check-oci-ta
494
+ - name : bundle
495
+ value : quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:57b3262138eb06186ae7375f84ca53788bba2a66cfd03d39cb82c78df050aba5
496
+ - name : kind
497
+ value : task
498
+ resolver : bundles
499
+ when :
500
+ - input : $(params.skip-checks)
501
+ operator : in
502
+ values :
503
+ - " false"
504
+ - name : sast-unicode-check
505
+ params :
506
+ - name : image-digest
507
+ value : $(tasks.build-image-index.results.IMAGE_DIGEST)
508
+ - name : image-url
509
+ value : $(tasks.build-image-index.results.IMAGE_URL)
510
+ - name : SOURCE_ARTIFACT
511
+ value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
512
+ - name : CACHI2_ARTIFACT
513
+ value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
514
+ runAfter :
515
+ - build-image-index
516
+ taskRef :
517
+ params :
518
+ - name : name
519
+ value : sast-unicode-check-oci-ta
520
+ - name : bundle
521
+ value : quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.2@sha256:df185dbe4e2852668f9c46f938dd752e90ea9c79696363378435a6499596c319
396
522
- name : kind
397
523
value : task
398
524
resolver : bundles
@@ -412,7 +538,7 @@ spec:
412
538
- name : name
413
539
value : apply-tags
414
540
- name : bundle
415
- value : quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.1@sha256:87fd7fc0e937aad1a8db9b6e377d7e444f53394dafde512d68adbea6966a4702
541
+ value : quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.1@sha256:3f89ba89cacf8547261b5ce064acce81bfe470c8ace127794d0e90aebc8c347d
416
542
- name : kind
417
543
value : task
418
544
resolver : bundles
@@ -435,7 +561,7 @@ spec:
435
561
- name : name
436
562
value : push-dockerfile-oci-ta
437
563
- name : bundle
438
- value : quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.1@sha256:80d48a1b9d2707490309941ec9f79338533938f959ca9a207b481b0e8a5e7a93
564
+ value : quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.1@sha256:278f84550844c1c050a65536799f4b54e7c203e0ac51393aa75379dd974c82e9
439
565
- name : kind
440
566
value : task
441
567
resolver : bundles
@@ -452,7 +578,7 @@ spec:
452
578
- name : name
453
579
value : rpms-signature-scan
454
580
- name : bundle
455
- value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:28aaf87d61078a0aeeeabcae455eda7d05c4f9b81d8995bdcf3dde95c1a7a77b
581
+ value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:297c2d8928aa3b114fcb1ba5d9da8b10226b68fed30706e78a6a5089c6cd30e3
456
582
- name : kind
457
583
value : task
458
584
resolver : bundles
@@ -466,7 +592,8 @@ spec:
466
592
optional : true
467
593
- name : netrc
468
594
optional : true
469
- taskRunTemplate : {}
595
+ taskRunTemplate :
596
+ serviceAccountName : build-pipeline-kube-descheduler-operator-bundle-4-19
470
597
workspaces :
471
598
- name : git-auth
472
599
secret :
0 commit comments