Skip to content

Commit e9746e9

Browse files
committed
Add shell and unicode sast pipeline tasks
https://issues.redhat.com/browse/KONFLUX-2264
1 parent 7efe626 commit e9746e9

4 files changed

+208
-0
lines changed

.tekton/windows-machine-config-operator-bundle-master-pull-request.yaml

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -344,6 +344,58 @@ spec:
344344
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
345345
- name: CACHI2_ARTIFACT
346346
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
347+
- name: sast-shell-check
348+
params:
349+
- name: image-digest
350+
value: $(tasks.build-container.results.IMAGE_DIGEST)
351+
- name: image-url
352+
value: $(tasks.build-container.results.IMAGE_URL)
353+
- name: SOURCE_ARTIFACT
354+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
355+
- name: CACHI2_ARTIFACT
356+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
357+
runAfter:
358+
- build-container
359+
taskRef:
360+
params:
361+
- name: name
362+
value: sast-shell-check-oci-ta
363+
- name: bundle
364+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:a591675c72f06fb9c5b1a3d60e6e4c58e4df5f7da180c7a4691a692a6e7e6496
365+
- name: kind
366+
value: task
367+
resolver: bundles
368+
when:
369+
- input: $(params.skip-checks)
370+
operator: in
371+
values:
372+
- "false"
373+
workspaces: []
374+
- name: sast-unicode-check
375+
params:
376+
- name: image-url
377+
value: $(tasks.build-container.results.IMAGE_URL)
378+
- name: SOURCE_ARTIFACT
379+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
380+
- name: CACHI2_ARTIFACT
381+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
382+
runAfter:
383+
- build-container
384+
taskRef:
385+
params:
386+
- name: name
387+
value: sast-unicode-check-oci-ta
388+
- name: bundle
389+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.1@sha256:424f2f659c02998dc3a43e1ce869e3148982c59adb74f953f8fa91ff1c9ab86e
390+
- name: kind
391+
value: task
392+
resolver: bundles
393+
when:
394+
- input: $(params.skip-checks)
395+
operator: in
396+
values:
397+
- "false"
398+
workspaces: []
347399
- name: clamav-scan
348400
params:
349401
- name: image-digest

.tekton/windows-machine-config-operator-bundle-master-push.yaml

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -341,6 +341,58 @@ spec:
341341
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
342342
- name: CACHI2_ARTIFACT
343343
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
344+
- name: sast-shell-check
345+
params:
346+
- name: image-digest
347+
value: $(tasks.build-container.results.IMAGE_DIGEST)
348+
- name: image-url
349+
value: $(tasks.build-container.results.IMAGE_URL)
350+
- name: SOURCE_ARTIFACT
351+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
352+
- name: CACHI2_ARTIFACT
353+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
354+
runAfter:
355+
- build-container
356+
taskRef:
357+
params:
358+
- name: name
359+
value: sast-shell-check-oci-ta
360+
- name: bundle
361+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:a591675c72f06fb9c5b1a3d60e6e4c58e4df5f7da180c7a4691a692a6e7e6496
362+
- name: kind
363+
value: task
364+
resolver: bundles
365+
when:
366+
- input: $(params.skip-checks)
367+
operator: in
368+
values:
369+
- "false"
370+
workspaces: []
371+
- name: sast-unicode-check
372+
params:
373+
- name: image-url
374+
value: $(tasks.build-container.results.IMAGE_URL)
375+
- name: SOURCE_ARTIFACT
376+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
377+
- name: CACHI2_ARTIFACT
378+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
379+
runAfter:
380+
- build-container
381+
taskRef:
382+
params:
383+
- name: name
384+
value: sast-unicode-check-oci-ta
385+
- name: bundle
386+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.1@sha256:424f2f659c02998dc3a43e1ce869e3148982c59adb74f953f8fa91ff1c9ab86e
387+
- name: kind
388+
value: task
389+
resolver: bundles
390+
when:
391+
- input: $(params.skip-checks)
392+
operator: in
393+
values:
394+
- "false"
395+
workspaces: []
344396
- name: clamav-scan
345397
params:
346398
- name: image-digest

.tekton/windows-machine-config-operator-master-pull-request.yaml

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -340,6 +340,58 @@ spec:
340340
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
341341
- name: CACHI2_ARTIFACT
342342
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
343+
- name: sast-shell-check
344+
params:
345+
- name: image-digest
346+
value: $(tasks.build-container.results.IMAGE_DIGEST)
347+
- name: image-url
348+
value: $(tasks.build-container.results.IMAGE_URL)
349+
- name: SOURCE_ARTIFACT
350+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
351+
- name: CACHI2_ARTIFACT
352+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
353+
runAfter:
354+
- build-container
355+
taskRef:
356+
params:
357+
- name: name
358+
value: sast-shell-check-oci-ta
359+
- name: bundle
360+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:a591675c72f06fb9c5b1a3d60e6e4c58e4df5f7da180c7a4691a692a6e7e6496
361+
- name: kind
362+
value: task
363+
resolver: bundles
364+
when:
365+
- input: $(params.skip-checks)
366+
operator: in
367+
values:
368+
- "false"
369+
workspaces: []
370+
- name: sast-unicode-check
371+
params:
372+
- name: image-url
373+
value: $(tasks.build-container.results.IMAGE_URL)
374+
- name: SOURCE_ARTIFACT
375+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
376+
- name: CACHI2_ARTIFACT
377+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
378+
runAfter:
379+
- build-container
380+
taskRef:
381+
params:
382+
- name: name
383+
value: sast-unicode-check-oci-ta
384+
- name: bundle
385+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.1@sha256:424f2f659c02998dc3a43e1ce869e3148982c59adb74f953f8fa91ff1c9ab86e
386+
- name: kind
387+
value: task
388+
resolver: bundles
389+
when:
390+
- input: $(params.skip-checks)
391+
operator: in
392+
values:
393+
- "false"
394+
workspaces: []
343395
- name: clamav-scan
344396
params:
345397
- name: image-digest

.tekton/windows-machine-config-operator-master-push.yaml

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -337,6 +337,58 @@ spec:
337337
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
338338
- name: CACHI2_ARTIFACT
339339
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
340+
- name: sast-shell-check
341+
params:
342+
- name: image-digest
343+
value: $(tasks.build-container.results.IMAGE_DIGEST)
344+
- name: image-url
345+
value: $(tasks.build-container.results.IMAGE_URL)
346+
- name: SOURCE_ARTIFACT
347+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
348+
- name: CACHI2_ARTIFACT
349+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
350+
runAfter:
351+
- build-container
352+
taskRef:
353+
params:
354+
- name: name
355+
value: sast-shell-check-oci-ta
356+
- name: bundle
357+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:a591675c72f06fb9c5b1a3d60e6e4c58e4df5f7da180c7a4691a692a6e7e6496
358+
- name: kind
359+
value: task
360+
resolver: bundles
361+
when:
362+
- input: $(params.skip-checks)
363+
operator: in
364+
values:
365+
- "false"
366+
workspaces: []
367+
- name: sast-unicode-check
368+
params:
369+
- name: image-url
370+
value: $(tasks.build-container.results.IMAGE_URL)
371+
- name: SOURCE_ARTIFACT
372+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
373+
- name: CACHI2_ARTIFACT
374+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
375+
runAfter:
376+
- build-container
377+
taskRef:
378+
params:
379+
- name: name
380+
value: sast-unicode-check-oci-ta
381+
- name: bundle
382+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.1@sha256:424f2f659c02998dc3a43e1ce869e3148982c59adb74f953f8fa91ff1c9ab86e
383+
- name: kind
384+
value: task
385+
resolver: bundles
386+
when:
387+
- input: $(params.skip-checks)
388+
operator: in
389+
values:
390+
- "false"
391+
workspaces: []
340392
- name: clamav-scan
341393
params:
342394
- name: image-digest

0 commit comments

Comments
 (0)