Skip to content

Commit 7878da0

Browse files
Merge pull request #706 from raptorsun/EC-fix-sast-checks
Fix EC violations, add 2 tasks to konflux pipeline
2 parents d4f507d + 169bada commit 7878da0

File tree

2 files changed

+100
-0
lines changed

2 files changed

+100
-0
lines changed

.tekton/lightspeed-console-pull-request.yaml

+50
Original file line numberDiff line numberDiff line change
@@ -395,6 +395,56 @@ spec:
395395
operator: in
396396
values:
397397
- "false"
398+
- name: sast-shell-check
399+
params:
400+
- name: image-digest
401+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
402+
- name: image-url
403+
value: $(tasks.build-image-index.results.IMAGE_URL)
404+
- name: SOURCE_ARTIFACT
405+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
406+
- name: CACHI2_ARTIFACT
407+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
408+
runAfter:
409+
- build-image-index
410+
taskRef:
411+
params:
412+
- name: name
413+
value: sast-shell-check-oci-ta
414+
- name: bundle
415+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:8e817af22b04305676597a556a975bde8552949ca2bf8918bf62414f135f93c8
416+
- name: kind
417+
value: task
418+
resolver: bundles
419+
when:
420+
- input: $(params.skip-checks)
421+
operator: in
422+
values:
423+
- "false"
424+
- name: sast-unicode-check
425+
params:
426+
- name: image-url
427+
value: $(tasks.build-image-index.results.IMAGE_URL)
428+
- name: SOURCE_ARTIFACT
429+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
430+
- name: CACHI2_ARTIFACT
431+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
432+
runAfter:
433+
- build-image-index
434+
taskRef:
435+
params:
436+
- name: name
437+
value: sast-unicode-check-oci-ta
438+
- name: bundle
439+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.1@sha256:b9c3dfe732a0d9581c75d07d59043f675ddcbe5e9a3152daad99076bedfd5b85
440+
- name: kind
441+
value: task
442+
resolver: bundles
443+
when:
444+
- input: $(params.skip-checks)
445+
operator: in
446+
values:
447+
- "false"
398448
- name: clamav-scan
399449
params:
400450
- name: image-digest

.tekton/lightspeed-console-push.yaml

+50
Original file line numberDiff line numberDiff line change
@@ -394,6 +394,56 @@ spec:
394394
operator: in
395395
values:
396396
- "false"
397+
- name: sast-shell-check
398+
params:
399+
- name: image-digest
400+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
401+
- name: image-url
402+
value: $(tasks.build-image-index.results.IMAGE_URL)
403+
- name: SOURCE_ARTIFACT
404+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
405+
- name: CACHI2_ARTIFACT
406+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
407+
runAfter:
408+
- build-image-index
409+
taskRef:
410+
params:
411+
- name: name
412+
value: sast-shell-check-oci-ta
413+
- name: bundle
414+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:8e817af22b04305676597a556a975bde8552949ca2bf8918bf62414f135f93c8
415+
- name: kind
416+
value: task
417+
resolver: bundles
418+
when:
419+
- input: $(params.skip-checks)
420+
operator: in
421+
values:
422+
- "false"
423+
- name: sast-unicode-check
424+
params:
425+
- name: image-url
426+
value: $(tasks.build-image-index.results.IMAGE_URL)
427+
- name: SOURCE_ARTIFACT
428+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
429+
- name: CACHI2_ARTIFACT
430+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
431+
runAfter:
432+
- build-image-index
433+
taskRef:
434+
params:
435+
- name: name
436+
value: sast-unicode-check-oci-ta
437+
- name: bundle
438+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.1@sha256:b9c3dfe732a0d9581c75d07d59043f675ddcbe5e9a3152daad99076bedfd5b85
439+
- name: kind
440+
value: task
441+
resolver: bundles
442+
when:
443+
- input: $(params.skip-checks)
444+
operator: in
445+
values:
446+
- "false"
397447
- name: clamav-scan
398448
params:
399449
- name: image-digest

0 commit comments

Comments
 (0)