Skip to content

Commit 591b255

Browse files
committed
ci: add required SAST tasks to Konflux pipelines
1 parent 322c34d commit 591b255

File tree

2 files changed

+96
-0
lines changed

2 files changed

+96
-0
lines changed

.tekton/provisioning-frontend-pull-request.yaml

Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -310,6 +310,54 @@ spec:
310310
workspaces:
311311
- name: workspace
312312
workspace: workspace
313+
- name: sast-shell-check
314+
params:
315+
- name: image-digest
316+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
317+
- name: image-url
318+
value: $(tasks.build-image-index.results.IMAGE_URL)
319+
runAfter:
320+
- build-image-index
321+
taskRef:
322+
params:
323+
- name: name
324+
value: sast-shell-check
325+
- name: bundle
326+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check:0.1@sha256:1b3d68c33a92dfc3da3975581cae80c99c8d1995cab519ae98c6331b5677ded0
327+
- name: kind
328+
value: task
329+
resolver: bundles
330+
when:
331+
- input: $(params.skip-checks)
332+
operator: in
333+
values:
334+
- "false"
335+
workspaces:
336+
- name: workspace
337+
workspace: workspace
338+
- name: sast-unicode-check
339+
params:
340+
- name: image-url
341+
value: $(tasks.build-image-index.results.IMAGE_URL)
342+
runAfter:
343+
- build-image-index
344+
taskRef:
345+
params:
346+
- name: name
347+
value: sast-unicode-check
348+
- name: bundle
349+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check:0.1@sha256:b1a9af196a79baa75632ef494eb6db987f57e870d882d47f5b495e1441c01e3b
350+
- name: kind
351+
value: task
352+
resolver: bundles
353+
when:
354+
- input: $(params.skip-checks)
355+
operator: in
356+
values:
357+
- "false"
358+
workspaces:
359+
- name: workspace
360+
workspace: workspace
313361
- name: deprecated-base-image-check
314362
params:
315363
- name: IMAGE_URL

.tekton/provisioning-frontend-push.yaml

Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -307,6 +307,54 @@ spec:
307307
workspaces:
308308
- name: workspace
309309
workspace: workspace
310+
- name: sast-shell-check
311+
params:
312+
- name: image-digest
313+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
314+
- name: image-url
315+
value: $(tasks.build-image-index.results.IMAGE_URL)
316+
runAfter:
317+
- build-image-index
318+
taskRef:
319+
params:
320+
- name: name
321+
value: sast-shell-check
322+
- name: bundle
323+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check:0.1@sha256:1b3d68c33a92dfc3da3975581cae80c99c8d1995cab519ae98c6331b5677ded0
324+
- name: kind
325+
value: task
326+
resolver: bundles
327+
when:
328+
- input: $(params.skip-checks)
329+
operator: in
330+
values:
331+
- "false"
332+
workspaces:
333+
- name: workspace
334+
workspace: workspace
335+
- name: sast-unicode-check
336+
params:
337+
- name: image-url
338+
value: $(tasks.build-image-index.results.IMAGE_URL)
339+
runAfter:
340+
- build-image-index
341+
taskRef:
342+
params:
343+
- name: name
344+
value: sast-unicode-check
345+
- name: bundle
346+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check:0.1@sha256:b1a9af196a79baa75632ef494eb6db987f57e870d882d47f5b495e1441c01e3b
347+
- name: kind
348+
value: task
349+
resolver: bundles
350+
when:
351+
- input: $(params.skip-checks)
352+
operator: in
353+
values:
354+
- "false"
355+
workspaces:
356+
- name: workspace
357+
workspace: workspace
310358
- name: deprecated-base-image-check
311359
params:
312360
- name: IMAGE_URL

0 commit comments

Comments
 (0)