Skip to content

Commit 2a8f2a1

Browse files
JasonPowrlance
andauthored
add_rpm_scan (#278)
Co-authored-by: Lance Ball <[email protected]>
1 parent a9617da commit 2a8f2a1

10 files changed

+170
-0
lines changed

.tekton/client-server-cg-pull-request.yaml

+17
Original file line numberDiff line numberDiff line change
@@ -309,6 +309,23 @@ spec:
309309
operator: in
310310
values:
311311
- "false"
312+
- name: rpms-signature-scan
313+
params:
314+
- name: image-digest
315+
value: $(tasks.build-container.results.IMAGE_DIGEST)
316+
- name: image-url
317+
value: $(tasks.build-container.results.IMAGE_URL)
318+
runAfter:
319+
- build-container
320+
taskRef:
321+
params:
322+
- name: name
323+
value: rpms-signature-scan
324+
- name: bundle
325+
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8
326+
- name: kind
327+
value: task
328+
resolver: bundles
312329
- name: sast-snyk-check
313330
runAfter:
314331
- build-container

.tekton/client-server-cg-push.yaml

+17
Original file line numberDiff line numberDiff line change
@@ -307,6 +307,23 @@ spec:
307307
operator: in
308308
values:
309309
- "false"
310+
- name: rpms-signature-scan
311+
params:
312+
- name: image-digest
313+
value: $(tasks.build-container.results.IMAGE_DIGEST)
314+
- name: image-url
315+
value: $(tasks.build-container.results.IMAGE_URL)
316+
runAfter:
317+
- build-container
318+
taskRef:
319+
params:
320+
- name: name
321+
value: rpms-signature-scan
322+
- name: bundle
323+
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8
324+
- name: kind
325+
value: task
326+
resolver: bundles
310327
- name: sast-snyk-check
311328
runAfter:
312329
- build-container

.tekton/client-server-f-pull-request.yaml

+17
Original file line numberDiff line numberDiff line change
@@ -323,6 +323,23 @@ spec:
323323
operator: in
324324
values:
325325
- "false"
326+
- name: rpms-signature-scan
327+
params:
328+
- name: image-digest
329+
value: $(tasks.build-container.results.IMAGE_DIGEST)
330+
- name: image-url
331+
value: $(tasks.build-container.results.IMAGE_URL)
332+
runAfter:
333+
- build-container
334+
taskRef:
335+
params:
336+
- name: name
337+
value: rpms-signature-scan
338+
- name: bundle
339+
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8
340+
- name: kind
341+
value: task
342+
resolver: bundles
326343
- name: ecosystem-cert-preflight-checks
327344
params:
328345
- name: image-url

.tekton/client-server-f-push.yaml

+17
Original file line numberDiff line numberDiff line change
@@ -320,6 +320,23 @@ spec:
320320
operator: in
321321
values:
322322
- "false"
323+
- name: rpms-signature-scan
324+
params:
325+
- name: image-digest
326+
value: $(tasks.build-container.results.IMAGE_DIGEST)
327+
- name: image-url
328+
value: $(tasks.build-container.results.IMAGE_URL)
329+
runAfter:
330+
- build-container
331+
taskRef:
332+
params:
333+
- name: name
334+
value: rpms-signature-scan
335+
- name: bundle
336+
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8
337+
- name: kind
338+
value: task
339+
resolver: bundles
323340
- name: ecosystem-cert-preflight-checks
324341
params:
325342
- name: image-url

.tekton/client-server-pull-request.yaml

+17
Original file line numberDiff line numberDiff line change
@@ -324,6 +324,23 @@ spec:
324324
operator: in
325325
values:
326326
- "false"
327+
- name: rpms-signature-scan
328+
params:
329+
- name: image-digest
330+
value: $(tasks.build-container.results.IMAGE_DIGEST)
331+
- name: image-url
332+
value: $(tasks.build-container.results.IMAGE_URL)
333+
runAfter:
334+
- build-container
335+
taskRef:
336+
params:
337+
- name: name
338+
value: rpms-signature-scan
339+
- name: bundle
340+
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8
341+
- name: kind
342+
value: task
343+
resolver: bundles
327344
- name: ecosystem-cert-preflight-checks
328345
params:
329346
- name: image-url

.tekton/client-server-push.yaml

+17
Original file line numberDiff line numberDiff line change
@@ -321,6 +321,23 @@ spec:
321321
operator: in
322322
values:
323323
- "false"
324+
- name: rpms-signature-scan
325+
params:
326+
- name: image-digest
327+
value: $(tasks.build-container.results.IMAGE_DIGEST)
328+
- name: image-url
329+
value: $(tasks.build-container.results.IMAGE_URL)
330+
runAfter:
331+
- build-container
332+
taskRef:
333+
params:
334+
- name: name
335+
value: rpms-signature-scan
336+
- name: bundle
337+
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8
338+
- name: kind
339+
value: task
340+
resolver: bundles
324341
- name: ecosystem-cert-preflight-checks
325342
params:
326343
- name: image-url

.tekton/client-server-re-pull-request.yaml

+17
Original file line numberDiff line numberDiff line change
@@ -309,6 +309,23 @@ spec:
309309
operator: in
310310
values:
311311
- "false"
312+
- name: rpms-signature-scan
313+
params:
314+
- name: image-digest
315+
value: $(tasks.build-container.results.IMAGE_DIGEST)
316+
- name: image-url
317+
value: $(tasks.build-container.results.IMAGE_URL)
318+
runAfter:
319+
- build-container
320+
taskRef:
321+
params:
322+
- name: name
323+
value: rpms-signature-scan
324+
- name: bundle
325+
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8
326+
- name: kind
327+
value: task
328+
resolver: bundles
312329
- name: sast-snyk-check
313330
runAfter:
314331
- build-container

.tekton/client-server-re-push.yaml

+17
Original file line numberDiff line numberDiff line change
@@ -307,6 +307,23 @@ spec:
307307
operator: in
308308
values:
309309
- "false"
310+
- name: rpms-signature-scan
311+
params:
312+
- name: image-digest
313+
value: $(tasks.build-container.results.IMAGE_DIGEST)
314+
- name: image-url
315+
value: $(tasks.build-container.results.IMAGE_URL)
316+
runAfter:
317+
- build-container
318+
taskRef:
319+
params:
320+
- name: name
321+
value: rpms-signature-scan
322+
- name: bundle
323+
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8
324+
- name: kind
325+
value: task
326+
resolver: bundles
310327
- name: sast-snyk-check
311328
runAfter:
312329
- build-container

.tekton/cosign-pull-request.yaml

+17
Original file line numberDiff line numberDiff line change
@@ -293,6 +293,23 @@ spec:
293293
operator: in
294294
values:
295295
- "false"
296+
- name: rpms-signature-scan
297+
params:
298+
- name: image-digest
299+
value: $(tasks.build-container.results.IMAGE_DIGEST)
300+
- name: image-url
301+
value: $(tasks.build-container.results.IMAGE_URL)
302+
runAfter:
303+
- build-container
304+
taskRef:
305+
params:
306+
- name: name
307+
value: rpms-signature-scan
308+
- name: bundle
309+
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8
310+
- name: kind
311+
value: task
312+
resolver: bundles
296313
- name: sast-snyk-check
297314
runAfter:
298315
- build-container

.tekton/cosign-push.yaml

+17
Original file line numberDiff line numberDiff line change
@@ -292,6 +292,23 @@ spec:
292292
operator: in
293293
values:
294294
- "false"
295+
- name: rpms-signature-scan
296+
params:
297+
- name: image-digest
298+
value: $(tasks.build-container.results.IMAGE_DIGEST)
299+
- name: image-url
300+
value: $(tasks.build-container.results.IMAGE_URL)
301+
runAfter:
302+
- build-container
303+
taskRef:
304+
params:
305+
- name: name
306+
value: rpms-signature-scan
307+
- name: bundle
308+
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8
309+
- name: kind
310+
value: task
311+
resolver: bundles
295312
- name: sast-snyk-check
296313
runAfter:
297314
- build-container

0 commit comments

Comments
 (0)