@@ -104,6 +104,14 @@ spec:
104104 VMs
105105 name : privileged-nested
106106 type : string
107+ - name : sast-target-dirs
108+ type : string
109+ default : .
110+ description : Target directories to scan with SAST tools. Multiple values should be separated with commas.
111+ - name : enable-package-registry-proxy
112+ default : ' true'
113+ description : Use the package registry proxy when prefetching dependencies
114+ type : string
107115 results :
108116 - description : " "
109117 name : IMAGE_URL
@@ -127,7 +135,7 @@ spec:
127135 - name : name
128136 value : init
129137 - name : bundle
130- value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:288f3106118edc1d0f0c79a89c960abf5841a4dd8bc3f38feb10527253105b19
138+ value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:5a423246792ac501ea279229b42ee57da9927da441c04b5c9ff86817b0856b08
131139 - name : kind
132140 value : task
133141 resolver : bundles
@@ -148,7 +156,7 @@ spec:
148156 - name : name
149157 value : git-clone-oci-ta
150158 - name : bundle
151- value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:2c388d28651457db60bb90287e7d8c3680303197196e4476878d98d81e8b6dc9
159+ value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:13d49df7dc9ae301627e45f95a236011422996152f1bea46cd60217b0f057407
152160 - name : kind
153161 value : task
154162 resolver : bundles
@@ -165,14 +173,16 @@ spec:
165173 value : $(params.output-image).prefetch
166174 - name : ociArtifactExpiresAfter
167175 value : $(params.image-expires-after)
176+ - name : enable-package-registry-proxy
177+ value : $(params.enable-package-registry-proxy)
168178 runAfter :
169179 - clone-repository
170180 taskRef :
171181 params :
172182 - name : name
173183 value : prefetch-dependencies-oci-ta
174184 - name : bundle
175- value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:2229dbc5e15acc0a6d8aec526465aeb0ad54e269c311ac3d0aba88013845e308
185+ value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:a2efbcdcecfa5293a622eb356a18f5c88e5714046b214fe8730b43b1a7dbb77d
176186 - name : kind
177187 value : task
178188 resolver : bundles
@@ -223,18 +233,14 @@ spec:
223233 - name : name
224234 value : buildah-oci-ta
225235 - name : bundle
226- value : quay.io/konflux-ci/tekton-catalog/task-buildah-oci-ta:0.9@sha256:cad04a0f4464283714c23940ef6052753821eff7544ec282e2a4707aa264aaf3
236+ value : quay.io/konflux-ci/tekton-catalog/task-buildah-oci-ta:0.9@sha256:681d9f65a7f50cb260ee576ccab551e11d63c549f1e1ef3d201da3c112855bd6
227237 - name : kind
228238 value : task
229239 resolver : bundles
230240 - name : build-image-index
231241 params :
232242 - name : IMAGE
233243 value : $(params.output-image)
234- - name : COMMIT_SHA
235- value : $(tasks.clone-repository.results.commit)
236- - name : IMAGE_EXPIRES_AFTER
237- value : $(params.image-expires-after)
238244 - name : ALWAYS_BUILD_INDEX
239245 value : $(params.build-image-index)
240246 - name : IMAGES
@@ -249,7 +255,7 @@ spec:
249255 - name : name
250256 value : build-image-index
251257 - name : bundle
252- value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.2 @sha256:3fa26d2c0768329c2df93c646bf5855245b74db7196ad55f83756ce22cd7f0f1
258+ value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.3 @sha256:550afde50349e22ec11191ea0db9a49395ab46fef4e8317d820b6e946677ebeb
253259 - name : kind
254260 value : task
255261 resolver : bundles
@@ -270,7 +276,7 @@ spec:
270276 - name : name
271277 value : source-build-oci-ta
272278 - name : bundle
273- value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.3@sha256:362f0475df00e7dfb5f15dea0481d1b68b287f60411718d70a23da3c059a5613
279+ value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.3@sha256:0917cfc7772e82cb8e74743c2104f43bcf2596aceafe87eec6fce69a8cac5f06
274280 - name : kind
275281 value : task
276282 resolver : bundles
@@ -292,7 +298,7 @@ spec:
292298 - name : name
293299 value : deprecated-image-check
294300 - name : bundle
295- value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:3457a4ca93f8d55f14ebd407532b1223c689eacc34f0abb3003db4111667bdae
301+ value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:e78d0d3baf3c8cfc1a5ad278196b74032d9568b143a87c7a79ab780fedfb296e
296302 - name : kind
297303 value : task
298304 resolver : bundles
@@ -314,7 +320,7 @@ spec:
314320 - name : name
315321 value : clair-scan
316322 - name : bundle
317- value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:9397d3eb9f1cbebaa15e93256e0ca9eaca148baa674be72f07f4a00df63c4609
323+ value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:8fad4c2e2f470f82ee43d6b2ac72327b4d9c6e9cb514a678911c1c9359c29894
318324 - name : kind
319325 value : task
320326 resolver : bundles
@@ -334,7 +340,7 @@ spec:
334340 - name : name
335341 value : ecosystem-cert-preflight-checks
336342 - name : bundle
337- value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:b4ac586edea81dcd25dfc17f1bd57899825be2b443e48d572cd05ce058f153bb
343+ value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:9c300728a03f41beee9a689422d66513d32ab5f804664fe561b11cebacd07799
338344 - name : kind
339345 value : task
340346 resolver : bundles
@@ -353,14 +359,16 @@ spec:
353359 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
354360 - name : CACHI2_ARTIFACT
355361 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
362+ - name : TARGET_DIRS
363+ value : $(params.sast-target-dirs)
356364 runAfter :
357365 - build-image-index
358366 taskRef :
359367 params :
360368 - name : name
361369 value : sast-snyk-check-oci-ta
362370 - name : bundle
363- value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4@sha256:6045ed6f2d37cfdf75cb3f2bf88706839c276a59f892ae027a315456c2914cf3
371+ value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4@sha256:8f3ecbeaff579e41b8278f82d7fabac27845db17a8e687ea6c510c0c9aceabbb
364372 - name : kind
365373 value : task
366374 resolver : bundles
@@ -382,7 +390,7 @@ spec:
382390 - name : name
383391 value : clamav-scan
384392 - name : bundle
385- value : quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.3@sha256:9f18b216ce71a66909e7cb17d9b34526c02d73cf12884ba32d1f10614f7b9f5a
393+ value : quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.3@sha256:567cb66bd2e1f4b58b9d4d756f3317fc62479e0b40aa0de66094b1f12d296cfc
386394 - name : kind
387395 value : task
388396 resolver : bundles
@@ -420,14 +428,16 @@ spec:
420428 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
421429 - name : CACHI2_ARTIFACT
422430 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
431+ - name : TARGET_DIRS
432+ value : $(params.sast-target-dirs)
423433 runAfter :
424434 - coverity-availability-check
425435 taskRef :
426436 params :
427437 - name : name
428438 value : sast-coverity-check-oci-ta
429439 - name : bundle
430- value : quay.io/konflux-ci/tekton-catalog/task-sast-coverity-check-oci-ta:0.3@sha256:ab60e90de028036be823e75343fdc205418edcfa7c4de569bb5f8ab833bc2037
440+ value : quay.io/konflux-ci/tekton-catalog/task-sast-coverity-check-oci-ta:0.3@sha256:e92d00ed858233d0096627861192d3e4fc013cf1559c0d0b0ea0657d3377ce75
431441 - name : kind
432442 value : task
433443 resolver : bundles
@@ -448,7 +458,7 @@ spec:
448458 - name : name
449459 value : coverity-availability-check
450460 - name : bundle
451- value : quay.io/konflux-ci/tekton-catalog/task-coverity-availability-check:0.2@sha256:de35caf2f090e3275cfd1019ea50d9662422e904fb4aebd6ea29fb53a1ad57f5
461+ value : quay.io/konflux-ci/tekton-catalog/task-coverity-availability-check:0.2@sha256:8b501440a960aec446db2ebc6625a49d0317a9fc7bf0f7bd9b18cb63052db7de
452462 - name : kind
453463 value : task
454464 resolver : bundles
@@ -467,14 +477,16 @@ spec:
467477 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
468478 - name : CACHI2_ARTIFACT
469479 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
480+ - name : TARGET_DIRS
481+ value : $(params.sast-target-dirs)
470482 runAfter :
471483 - build-image-index
472484 taskRef :
473485 params :
474486 - name : name
475487 value : sast-shell-check-oci-ta
476488 - name : bundle
477- value : quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:c314b4d5369d7961af51c865be28cd792d5f233aef94ecf035b3f84acde398bf
489+ value : quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:c4ef47e3b4e0508572d266fb745be7e374c29dc02580328cbe9f4d472a8aca57
478490 - name : kind
479491 value : task
480492 resolver : bundles
@@ -493,14 +505,16 @@ spec:
493505 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
494506 - name : CACHI2_ARTIFACT
495507 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
508+ - name : TARGET_DIRS
509+ value : $(params.sast-target-dirs)
496510 runAfter :
497511 - build-image-index
498512 taskRef :
499513 params :
500514 - name : name
501515 value : sast-unicode-check-oci-ta
502516 - name : bundle
503- value : quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.4@sha256:3d8a6902ab7c5c2125be07263f395426342c5032b3abfd0140162ad838437bab
517+ value : quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.4@sha256:90efa582de7770d55102b74014a765cd16a25a56f2cf644b56a788c70c4dc749
504518 - name : kind
505519 value : task
506520 resolver : bundles
@@ -522,7 +536,7 @@ spec:
522536 - name : name
523537 value : apply-tags
524538 - name : bundle
525- value : quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.3@sha256:aa62b41861c09e2e59c69cc6e9a1f740bf0c81e6a1eb03f57f59dfda0f65840e
539+ value : quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.3@sha256:a291081de7fb27f832c6fc3c4b078acf7e6162ca4c085db38b118ca87e8b5b66
526540 - name : kind
527541 value : task
528542 resolver : bundles
@@ -545,7 +559,7 @@ spec:
545559 - name : name
546560 value : push-dockerfile-oci-ta
547561 - name : bundle
548- value : quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.3@sha256:1bc2d0f26b89259db090a47bb38217c82c05e335d626653d184adf1d196ca131
562+ value : quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.3@sha256:7855471abfe87de080b914f2f3ca27c59e64f6448a7c2435e51435b764494c71
549563 - name : kind
550564 value : task
551565 resolver : bundles
@@ -562,7 +576,7 @@ spec:
562576 - name : name
563577 value : rpms-signature-scan
564578 - name : bundle
565- value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:47b81d6b3d752649eddfbb8b3fd8f6522c4bb07f6d1946f9bc45dae3f92e2c9a
579+ value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:d4e3499ad4af6869470233bef6faaa1bdd69ef56276841eeec93ce6e62deeb93
566580 - name : kind
567581 value : task
568582 resolver : bundles
0 commit comments