@@ -6,10 +6,9 @@ metadata:
6
6
build.appstudio.redhat.com/commit_sha : ' {{revision}}'
7
7
build.appstudio.redhat.com/pull_request_number : ' {{pull_request_number}}'
8
8
build.appstudio.redhat.com/target_branch : ' {{target_branch}}'
9
- pipelinesascode.tekton.dev/max-keep-runs : " 3"
10
- pipelinesascode.tekton.dev/on-cel-expression : event == "pull_request" && target_branch
11
- == "main"
12
- creationTimestamp : null
9
+ pipelinesascode.tekton.dev/max-keep-runs : ' 3'
10
+ pipelinesascode.tekton.dev/on-cel-expression : event == "pull_request" && target_branch == "main"
11
+ creationTimestamp :
13
12
labels :
14
13
appstudio.openshift.io/application : openshift-gitops-operator
15
14
appstudio.openshift.io/component : gitops-must-gather
32
31
- name : dockerfile
33
32
value : .konflux/Containerfile.plugin
34
33
- name : hermetic
35
- value : " true"
34
+ value : ' true'
36
35
pipelineSpec :
37
36
description : |
38
37
This pipeline is ideal for building multi-arch container images from a Containerfile while maintaining trust after pipeline customization.
@@ -49,84 +48,80 @@ spec:
49
48
- name : name
50
49
value : show-sbom
51
50
- name : bundle
52
- value : quay.io/konflux-ci/tekton-catalog/task-show-sbom:0.1@sha256:04f15cbce548e1db7770eee3f155ccb2cc0140a6c371dc67e9a34d83673ea0c0
51
+ value : quay.io/konflux-ci/tekton-catalog/task-show-sbom:0.1@sha256:1b1df4da95966d08ac6a5b8198710e09e68b5c2cdc707c37d9d19769e65884b2
53
52
- name : kind
54
53
value : task
55
54
resolver : bundles
56
55
params :
57
56
- description : Source Repository URL
58
57
name : git-url
59
58
type : string
60
- - default : " "
59
+ - default : ' '
61
60
description : Revision of the Source Repository
62
61
name : revision
63
62
type : string
64
63
- description : Fully Qualified Output Image
65
64
name : output-image
66
65
type : string
67
66
- default : .
68
- description : Path to the source code of an application's component from where
69
- to build image.
67
+ description : Path to the source code of an application's component from where to build image.
70
68
name : path-context
71
69
type : string
72
70
- default : Dockerfile
73
- description : Path to the Dockerfile inside the context specified by parameter
74
- path-context
71
+ description : Path to the Dockerfile inside the context specified by parameter path-context
75
72
name : dockerfile
76
73
type : string
77
- - default : " false"
74
+ - default : ' false'
78
75
description : Force rebuild image
79
76
name : rebuild
80
77
type : string
81
- - default : " false"
78
+ - default : ' false'
82
79
description : Skip checks against built image
83
80
name : skip-checks
84
81
type : string
85
- - default : " false"
82
+ - default : ' false'
86
83
description : Execute the build with network isolation
87
84
name : hermetic
88
85
type : string
89
- - default : " "
86
+ - default : ' '
90
87
description : Build dependencies to be prefetched by Cachi2
91
88
name : prefetch-input
92
89
type : string
93
- - default : " "
94
- description : Image tag expiration time, time values could be something like
95
- 1h, 2d, 3w for hours, days, and weeks, respectively.
90
+ - default : ' '
91
+ description : Image tag expiration time, time values could be something like 1h, 2d, 3w for hours, days, and weeks, respectively.
96
92
name : image-expires-after
97
- - default : " false"
93
+ - default : ' false'
98
94
description : Build a source image.
99
95
name : build-source-image
100
96
type : string
101
- - default : " true"
97
+ - default : ' true'
102
98
description : Add built image into an OCI image index
103
99
name : build-image-index
104
100
type : string
105
101
- default : []
106
102
description : Array of --build-arg values ("arg=value" strings) for buildah
107
103
name : build-args
108
104
type : array
109
- - default : " "
105
+ - default : ' '
110
106
description : Path to a file with build arguments for buildah, see https://www.mankier.com/1/buildah-build#--build-arg-file
111
107
name : build-args-file
112
108
type : string
113
109
- default :
114
110
- linux/x86_64
115
- description : List of platforms to build the container images on. The available
116
- set of values is determined by the configuration of the multi-platform-controller.
111
+ description : List of platforms to build the container images on. The available set of values is determined by the configuration of the multi-platform-controller.
117
112
name : build-platforms
118
113
type : array
119
114
results :
120
- - description : " "
115
+ - description : ' '
121
116
name : IMAGE_URL
122
117
value : $(tasks.build-image-index.results.IMAGE_URL)
123
- - description : " "
118
+ - description : ' '
124
119
name : IMAGE_DIGEST
125
120
value : $(tasks.build-image-index.results.IMAGE_DIGEST)
126
- - description : " "
121
+ - description : ' '
127
122
name : CHAINS-GIT_URL
128
123
value : $(tasks.clone-repository.results.url)
129
- - description : " "
124
+ - description : ' '
130
125
name : CHAINS-GIT_COMMIT
131
126
value : $(tasks.clone-repository.results.commit)
132
127
tasks :
@@ -143,7 +138,7 @@ spec:
143
138
- name : name
144
139
value : init
145
140
- name : bundle
146
- value : quay.io/konflux-ci/tekton-catalog/task-init:0.2@sha256:737682d073a65a486d59b2b30e3104b93edd8490e0cd5e9b4a39703e47363f0f
141
+ value : quay.io/konflux-ci/tekton-catalog/task-init:0.2@sha256:66e90d31e1386bf516fb548cd3e3f0082b5d0234b8b90dbf9e0d4684b70dbe1a
147
142
- name : kind
148
143
value : task
149
144
resolver : bundles
@@ -164,15 +159,15 @@ spec:
164
159
- name : name
165
160
value : git-clone-oci-ta
166
161
- name : bundle
167
- value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:9709088bf3c581d4763e9804d9ee3a1f06ad6a61c23237277057c4f0cdc4f9c3
162
+ value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:d35e5d501cb5f5f88369511f76249857cb5ac30250e1dcf086939321964ff6b9
168
163
- name : kind
169
164
value : task
170
165
resolver : bundles
171
166
when :
172
167
- input : $(tasks.init.results.build)
173
168
operator : in
174
169
values :
175
- - " true"
170
+ - ' true'
176
171
workspaces :
177
172
- name : basic-auth
178
173
workspace : git-auth
@@ -193,7 +188,7 @@ spec:
193
188
- name : name
194
189
value : prefetch-dependencies-oci-ta
195
190
- name : bundle
196
- value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.2@sha256:efc8aebec295bf5986597b6bbeebe093b2764fea79c66094e05ff3d283f54932
191
+ value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.2@sha256:5e15408f997557153b13d492aeccb51c01923bfbe4fbdf6f1e8695ce1b82f826
197
192
- name : kind
198
193
value : task
199
194
resolver : bundles
@@ -233,7 +228,7 @@ spec:
233
228
- name : CACHI2_ARTIFACT
234
229
value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
235
230
- name : IMAGE_APPEND_PLATFORM
236
- value : " true"
231
+ value : ' true'
237
232
- name : LABELS
238
233
value :
239
234
- upstream-source-url=$(tasks.clone-repository.results.url)
@@ -245,15 +240,15 @@ spec:
245
240
- name : name
246
241
value : buildah-remote-oci-ta
247
242
- name : bundle
248
- value : quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.4@sha256:468708e0a5dc3a314d71ca0cf2db80c6d7fefae98b292b10fa1cf07ea3787d9e
243
+ value : quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.4@sha256:ae87472f60dbbf71e4980cd478c92740c145fd9e44acbb9b164a21f1bcd61aa3
249
244
- name : kind
250
245
value : task
251
246
resolver : bundles
252
247
when :
253
248
- input : $(tasks.init.results.build)
254
249
operator : in
255
250
values :
256
- - " true"
251
+ - ' true'
257
252
- name : build-image-index
258
253
params :
259
254
- name : IMAGE
@@ -274,15 +269,15 @@ spec:
274
269
- name : name
275
270
value : build-image-index
276
271
- name : bundle
277
- value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.1@sha256:95be274b6d0432d4671e2c41294ec345121bdf01284b1c6c46b5537dc6b37e15
272
+ value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.1@sha256:846dc9975914f31380ec2712fdbac9df3b06c00a9cc7df678315a7f97145efc2
278
273
- name : kind
279
274
value : task
280
275
resolver : bundles
281
276
when :
282
277
- input : $(tasks.init.results.build)
283
278
operator : in
284
279
values :
285
- - " true"
280
+ - ' true'
286
281
- name : build-source-image
287
282
params :
288
283
- name : BINARY_IMAGE
@@ -298,19 +293,19 @@ spec:
298
293
- name : name
299
294
value : source-build-oci-ta
300
295
- name : bundle
301
- value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.2@sha256:9fe82c9511f282287686f918bf1a543fcef417848e7a503357e988aab2887cee
296
+ value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.2@sha256:b424894fc8e806c12658daa565b835fd2d66e7f7608afc47529eb7b410f030d7
302
297
- name : kind
303
298
value : task
304
299
resolver : bundles
305
300
when :
306
301
- input : $(tasks.init.results.build)
307
302
operator : in
308
303
values :
309
- - " true"
304
+ - ' true'
310
305
- input : $(params.build-source-image)
311
306
operator : in
312
307
values :
313
- - " true"
308
+ - ' true'
314
309
- name : deprecated-base-image-check
315
310
params :
316
311
- name : IMAGE_URL
@@ -324,15 +319,15 @@ spec:
324
319
- name : name
325
320
value : deprecated-image-check
326
321
- name : bundle
327
- value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:5d63b920b71192906fe4d6c4903f594e6f34c5edcff9d21714a08b5edcfbc667
322
+ value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:3c8b81fa868e27c6266e7660a4bfb4c822846dcf4304606e71e20893b0d3e515
328
323
- name : kind
329
324
value : task
330
325
resolver : bundles
331
326
when :
332
327
- input : $(params.skip-checks)
333
328
operator : in
334
329
values :
335
- - " false"
330
+ - ' false'
336
331
- name : clair-scan
337
332
params :
338
333
- name : image-digest
@@ -346,15 +341,15 @@ spec:
346
341
- name : name
347
342
value : clair-scan
348
343
- name : bundle
349
- value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.2@sha256:712afcf63f3b5a97c371d37e637efbcc9e1c7ad158872339d00adc6413cd8851
344
+ value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.2@sha256:d354939892f3a904223ec080cc3771bd11931085a5d202323ea491ee8e8c5e43
350
345
- name : kind
351
346
value : task
352
347
resolver : bundles
353
348
when :
354
349
- input : $(params.skip-checks)
355
350
operator : in
356
351
values :
357
- - " false"
352
+ - ' false'
358
353
- name : ecosystem-cert-preflight-checks
359
354
params :
360
355
- name : image-url
@@ -366,15 +361,15 @@ spec:
366
361
- name : name
367
362
value : ecosystem-cert-preflight-checks
368
363
- name : bundle
369
- value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:00b13d06d17328e105b11619ee4db98b215ca6ac02314a4776aa5fc2a974f9c1
364
+ value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:b550ff4f0b634512ce5200074be7afd7a5a6c05b783620c626e2a3035cd56448
370
365
- name : kind
371
366
value : task
372
367
resolver : bundles
373
368
when :
374
369
- input : $(params.skip-checks)
375
370
operator : in
376
371
values :
377
- - " false"
372
+ - ' false'
378
373
- name : sast-snyk-check
379
374
params :
380
375
- name : image-digest
@@ -392,15 +387,15 @@ spec:
392
387
- name : name
393
388
value : sast-snyk-check-oci-ta
394
389
- name : bundle
395
- value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.3 @sha256:a1cb59ed66a7be1949c9720660efb0a006e95ef05b3f67929dd8e310e1d7baef
390
+ value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4 @sha256:e61f541189b30d14292ef8df36ccaf13f7feb2378fed5f74cb6293b3e79eb687
396
391
- name : kind
397
392
value : task
398
393
resolver : bundles
399
394
when :
400
395
- input : $(params.skip-checks)
401
396
operator : in
402
397
values :
403
- - " false"
398
+ - ' false'
404
399
- name : clamav-scan
405
400
params :
406
401
- name : image-digest
@@ -414,27 +409,29 @@ spec:
414
409
- name : name
415
410
value : clamav-scan
416
411
- name : bundle
417
- value : quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.2@sha256:62c835adae22e36fce6684460b39206bc16752f1a4427cdbba4ee9afdd279670
412
+ value : quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.2@sha256:9cab95ac9e833d77a63c079893258b73b8d5a298d93aaf9bdd6722471bc2f338
418
413
- name : kind
419
414
value : task
420
415
resolver : bundles
421
416
when :
422
417
- input : $(params.skip-checks)
423
418
operator : in
424
419
values :
425
- - " false"
420
+ - ' false'
426
421
- name : apply-tags
427
422
params :
428
- - name : IMAGE
423
+ - name : IMAGE_URL
429
424
value : $(tasks.build-image-index.results.IMAGE_URL)
425
+ - name : IMAGE_DIGEST
426
+ value : $(tasks.build-image-index.results.IMAGE_DIGEST)
430
427
runAfter :
431
428
- build-image-index
432
429
taskRef :
433
430
params :
434
431
- name : name
435
432
value : apply-tags
436
433
- name : bundle
437
- value : quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.1 @sha256:61c90b1c94a2a11cb11211a0d65884089b758c34254fcec164d185a402beae22
434
+ value : quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.2 @sha256:517a51e260c0b59654a9d7b842e1ab07d76bce15ca7ce9c8fd2489a19be6463d
438
435
- name : kind
439
436
value : task
440
437
resolver : bundles
@@ -457,7 +454,7 @@ spec:
457
454
- name : name
458
455
value : push-dockerfile-oci-ta
459
456
- name : bundle
460
- value : quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.1@sha256:55a4ff2910ae2e4502f3841719935d37578bd52156bc789fcdf45ff48c2b048b
457
+ value : quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.1@sha256:5d8013b6a27bbc5e4ff261144616268f28417ed0950d583ef36349fcd59d3d3d
461
458
- name : kind
462
459
value : task
463
460
resolver : bundles
@@ -474,15 +471,15 @@ spec:
474
471
- name : name
475
472
value : rpms-signature-scan
476
473
- name : bundle
477
- value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:c0798ff85ad04f1553d349fe34aa4918597fb35b3b74e344dfbd5af2f3494300
474
+ value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:1b6c20ab3dbfb0972803d3ebcb2fa72642e59400c77bd66dfd82028bdd09e120
478
475
- name : kind
479
476
value : task
480
477
resolver : bundles
481
478
when :
482
479
- input : $(params.skip-checks)
483
480
operator : in
484
481
values :
485
- - " false"
482
+ - ' false'
486
483
workspaces :
487
484
- name : git-auth
488
485
optional : true
0 commit comments