Skip to content

Commit e88d272

Browse files
authored
Merge pull request #175 from simonbaird/add-sast-shell-and-unicode-tasks
Add two new sast tasks to Konflux build pipeline
2 parents 4561945 + 7e9b998 commit e88d272

File tree

2 files changed

+104
-0
lines changed

2 files changed

+104
-0
lines changed

.tekton/rhtap-task-runner-pull-request.yaml

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -400,6 +400,58 @@ spec:
400400
operator: in
401401
values:
402402
- "false"
403+
- name: sast-shell-check
404+
params:
405+
- name: image-digest
406+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
407+
- name: image-url
408+
value: $(tasks.build-image-index.results.IMAGE_URL)
409+
- name: SOURCE_ARTIFACT
410+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
411+
- name: CACHI2_ARTIFACT
412+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
413+
runAfter:
414+
- build-image-index
415+
taskRef:
416+
params:
417+
- name: name
418+
value: sast-shell-check-oci-ta
419+
- name: bundle
420+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:a591675c72f06fb9c5b1a3d60e6e4c58e4df5f7da180c7a4691a692a6e7e6496
421+
- name: kind
422+
value: task
423+
resolver: bundles
424+
when:
425+
- input: $(params.skip-checks)
426+
operator: in
427+
values:
428+
- "false"
429+
workspaces: []
430+
- name: sast-unicode-check
431+
params:
432+
- name: image-url
433+
value: $(tasks.build-image-index.results.IMAGE_URL)
434+
- name: SOURCE_ARTIFACT
435+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
436+
- name: CACHI2_ARTIFACT
437+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
438+
runAfter:
439+
- build-image-index
440+
taskRef:
441+
params:
442+
- name: name
443+
value: sast-unicode-check-oci-ta
444+
- name: bundle
445+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.1@sha256:424f2f659c02998dc3a43e1ce869e3148982c59adb74f953f8fa91ff1c9ab86e
446+
- name: kind
447+
value: task
448+
resolver: bundles
449+
when:
450+
- input: $(params.skip-checks)
451+
operator: in
452+
values:
453+
- "false"
454+
workspaces: []
403455
- name: clamav-scan
404456
params:
405457
- name: image-digest

.tekton/rhtap-task-runner-push.yaml

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -397,6 +397,58 @@ spec:
397397
operator: in
398398
values:
399399
- "false"
400+
- name: sast-shell-check
401+
params:
402+
- name: image-digest
403+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
404+
- name: image-url
405+
value: $(tasks.build-image-index.results.IMAGE_URL)
406+
- name: SOURCE_ARTIFACT
407+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
408+
- name: CACHI2_ARTIFACT
409+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
410+
runAfter:
411+
- build-image-index
412+
taskRef:
413+
params:
414+
- name: name
415+
value: sast-shell-check-oci-ta
416+
- name: bundle
417+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:a591675c72f06fb9c5b1a3d60e6e4c58e4df5f7da180c7a4691a692a6e7e6496
418+
- name: kind
419+
value: task
420+
resolver: bundles
421+
when:
422+
- input: $(params.skip-checks)
423+
operator: in
424+
values:
425+
- "false"
426+
workspaces: []
427+
- name: sast-unicode-check
428+
params:
429+
- name: image-url
430+
value: $(tasks.build-image-index.results.IMAGE_URL)
431+
- name: SOURCE_ARTIFACT
432+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
433+
- name: CACHI2_ARTIFACT
434+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
435+
runAfter:
436+
- build-image-index
437+
taskRef:
438+
params:
439+
- name: name
440+
value: sast-unicode-check-oci-ta
441+
- name: bundle
442+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.1@sha256:424f2f659c02998dc3a43e1ce869e3148982c59adb74f953f8fa91ff1c9ab86e
443+
- name: kind
444+
value: task
445+
resolver: bundles
446+
when:
447+
- input: $(params.skip-checks)
448+
operator: in
449+
values:
450+
- "false"
451+
workspaces: []
400452
- name: clamav-scan
401453
params:
402454
- name: image-digest

0 commit comments

Comments
 (0)