Skip to content

Commit 76eb2c8

Browse files
committed
Tekton add sast checks (#816)
1 parent 1a8ba1b commit 76eb2c8

1 file changed

Lines changed: 50 additions & 0 deletions

File tree

.tekton/pipeline-ref.yaml

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -434,6 +434,56 @@ spec:
434434
operator: in
435435
values:
436436
- "false"
437+
- name: sast-shell-check
438+
params:
439+
- name: image-digest
440+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
441+
- name: image-url
442+
value: $(tasks.build-image-index.results.IMAGE_URL)
443+
- name: SOURCE_ARTIFACT
444+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
445+
- name: CACHI2_ARTIFACT
446+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
447+
runAfter:
448+
- build-image-index
449+
taskRef:
450+
params:
451+
- name: name
452+
value: sast-shell-check-oci-ta
453+
- name: bundle
454+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:8e817af22b04305676597a556a975bde8552949ca2bf8918bf62414f135f93c8
455+
- name: kind
456+
value: task
457+
resolver: bundles
458+
when:
459+
- input: $(params.skip-checks)
460+
operator: in
461+
values:
462+
- "false"
463+
- name: sast-unicode-check
464+
params:
465+
- name: image-url
466+
value: $(tasks.build-image-index.results.IMAGE_URL)
467+
- name: SOURCE_ARTIFACT
468+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
469+
- name: CACHI2_ARTIFACT
470+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
471+
runAfter:
472+
- build-image-index
473+
taskRef:
474+
params:
475+
- name: name
476+
value: sast-unicode-check-oci-ta
477+
- name: bundle
478+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.1@sha256:b9c3dfe732a0d9581c75d07d59043f675ddcbe5e9a3152daad99076bedfd5b85
479+
- name: kind
480+
value: task
481+
resolver: bundles
482+
when:
483+
- input: $(params.skip-checks)
484+
operator: in
485+
values:
486+
- "false"
437487
- name: clamav-scan
438488
params:
439489
- name: image-digest

0 commit comments

Comments
 (0)