Skip to content

Commit 69e1e92

Browse files
committed
Add rpms-signature-scan steps
1 parent 60c5dce commit 69e1e92

File tree

2 files changed

+38
-0
lines changed

2 files changed

+38
-0
lines changed

.tekton/ros-backend-pull-request.yaml

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -283,6 +283,25 @@ spec:
283283
operator: in
284284
values:
285285
- "true"
286+
- name: rpms-signature-scan
287+
params:
288+
- name: image-digest
289+
value: $(tasks.build-container.results.IMAGE_DIGEST)
290+
- name: image-url
291+
value: $(tasks.build-container.results.IMAGE_URL)
292+
- name: fail-unsigned
293+
value: true
294+
runAfter:
295+
- build-container
296+
taskRef:
297+
params:
298+
- name: name
299+
value: rpms-signature-scan
300+
- name: bundle
301+
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8
302+
- name: kind
303+
value: task
304+
resolver: bundles
286305
- name: build-source-image
287306
params:
288307
- name: BINARY_IMAGE

.tekton/ros-backend-push.yaml

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -280,6 +280,25 @@ spec:
280280
operator: in
281281
values:
282282
- "true"
283+
- name: rpms-signature-scan
284+
params:
285+
- name: image-digest
286+
value: $(tasks.build-container.results.IMAGE_DIGEST)
287+
- name: image-url
288+
value: $(tasks.build-container.results.IMAGE_URL)
289+
- name: fail-unsigned
290+
value: true
291+
runAfter:
292+
- build-container
293+
taskRef:
294+
params:
295+
- name: name
296+
value: rpms-signature-scan
297+
- name: bundle
298+
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8
299+
- name: kind
300+
value: task
301+
resolver: bundles
283302
- name: build-source-image
284303
params:
285304
- name: BINARY_IMAGE

0 commit comments

Comments
 (0)