Skip to content

Commit dee4ab8

Browse files
authored
ci: add required SAST tasks to Konflux pipelines
Add two SAST tasks.
1 parent 2348b95 commit dee4ab8

File tree

2 files changed

+96
-0
lines changed

2 files changed

+96
-0
lines changed

.tekton/provisioning-backend-pull-request.yaml

Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -329,6 +329,54 @@ spec:
329329
workspaces:
330330
- name: workspace
331331
workspace: workspace
332+
- name: sast-shell-check
333+
params:
334+
- name: image-digest
335+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
336+
- name: image-url
337+
value: $(tasks.build-image-index.results.IMAGE_URL)
338+
runAfter:
339+
- build-image-index
340+
taskRef:
341+
params:
342+
- name: name
343+
value: sast-shell-check
344+
- name: bundle
345+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check:0.1@sha256:1b3d68c33a92dfc3da3975581cae80c99c8d1995cab519ae98c6331b5677ded0
346+
- name: kind
347+
value: task
348+
resolver: bundles
349+
when:
350+
- input: $(params.skip-checks)
351+
operator: in
352+
values:
353+
- "false"
354+
workspaces:
355+
- name: workspace
356+
workspace: workspace
357+
- name: sast-unicode-check
358+
params:
359+
- name: image-url
360+
value: $(tasks.build-image-index.results.IMAGE_URL)
361+
runAfter:
362+
- build-image-index
363+
taskRef:
364+
params:
365+
- name: name
366+
value: sast-unicode-check
367+
- name: bundle
368+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check:0.1@sha256:b1a9af196a79baa75632ef494eb6db987f57e870d882d47f5b495e1441c01e3b
369+
- name: kind
370+
value: task
371+
resolver: bundles
372+
when:
373+
- input: $(params.skip-checks)
374+
operator: in
375+
values:
376+
- "false"
377+
workspaces:
378+
- name: workspace
379+
workspace: workspace
332380
- name: deprecated-base-image-check
333381
params:
334382
- name: IMAGE_URL

.tekton/provisioning-backend-push.yaml

Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -326,6 +326,54 @@ spec:
326326
workspaces:
327327
- name: workspace
328328
workspace: workspace
329+
- name: sast-shell-check
330+
params:
331+
- name: image-digest
332+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
333+
- name: image-url
334+
value: $(tasks.build-image-index.results.IMAGE_URL)
335+
runAfter:
336+
- build-image-index
337+
taskRef:
338+
params:
339+
- name: name
340+
value: sast-shell-check
341+
- name: bundle
342+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check:0.1@sha256:1b3d68c33a92dfc3da3975581cae80c99c8d1995cab519ae98c6331b5677ded0
343+
- name: kind
344+
value: task
345+
resolver: bundles
346+
when:
347+
- input: $(params.skip-checks)
348+
operator: in
349+
values:
350+
- "false"
351+
workspaces:
352+
- name: workspace
353+
workspace: workspace
354+
- name: sast-unicode-check
355+
params:
356+
- name: image-url
357+
value: $(tasks.build-image-index.results.IMAGE_URL)
358+
runAfter:
359+
- build-image-index
360+
taskRef:
361+
params:
362+
- name: name
363+
value: sast-unicode-check
364+
- name: bundle
365+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check:0.1@sha256:b1a9af196a79baa75632ef494eb6db987f57e870d882d47f5b495e1441c01e3b
366+
- name: kind
367+
value: task
368+
resolver: bundles
369+
when:
370+
- input: $(params.skip-checks)
371+
operator: in
372+
values:
373+
- "false"
374+
workspaces:
375+
- name: workspace
376+
workspace: workspace
329377
- name: deprecated-base-image-check
330378
params:
331379
- name: IMAGE_URL

0 commit comments

Comments
 (0)