9393 name : privileged-nested
9494 type : string
9595
96+ - name : sast-target-dirs
97+ type : string
98+ default : .
99+ description : Target directories to scan with SAST tools. Multiple values should be separated with commas.
100+ - name : enable-package-registry-proxy
101+ default : ' true'
102+ description : Use the package registry proxy when prefetching dependencies
103+ type : string
96104 results :
97105 - description : " "
98106 name : IMAGE_URL
@@ -117,7 +125,7 @@ spec:
117125 - name : name
118126 value : init
119127 - name : bundle
120- value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:288f3106118edc1d0f0c79a89c960abf5841a4dd8bc3f38feb10527253105b19
128+ value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:5a423246792ac501ea279229b42ee57da9927da441c04b5c9ff86817b0856b08
121129 - name : kind
122130 value : task
123131 resolver : bundles
@@ -143,7 +151,7 @@ spec:
143151 - name : name
144152 value : git-clone-oci-ta
145153 - name : bundle
146- value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:2c388d28651457db60bb90287e7d8c3680303197196e4476878d98d81e8b6dc9
154+ value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:13d49df7dc9ae301627e45f95a236011422996152f1bea46cd60217b0f057407
147155 - name : kind
148156 value : task
149157 resolver : bundles
@@ -162,14 +170,16 @@ spec:
162170 value : $(params.oci-artifact-expires-after)
163171 - name : ACTIVATION_KEY
164172 value : subscription-manager-activation-key-prod
173+ - name : enable-package-registry-proxy
174+ value : $(params.enable-package-registry-proxy)
165175 runAfter :
166176 - clone-repository
167177 taskRef :
168178 params :
169179 - name : name
170180 value : prefetch-dependencies-oci-ta
171181 - name : bundle
172- value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:2229dbc5e15acc0a6d8aec526465aeb0ad54e269c311ac3d0aba88013845e308
182+ value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:a2efbcdcecfa5293a622eb356a18f5c88e5714046b214fe8730b43b1a7dbb77d
173183 - name : kind
174184 value : task
175185 resolver : bundles
@@ -230,7 +240,7 @@ spec:
230240 - name : name
231241 value : buildah-remote-oci-ta
232242 - name : bundle
233- value : quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.9@sha256:351b8f1ebbae7f6b73bccbbec3170cc392e3b93141b0667faa0ffff5660647ab
243+ value : quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.9@sha256:f667d1146533b1d49829c08097e31faf27db24563da576434a707353de62099f
234244 - name : kind
235245 value : task
236246 resolver : bundles
@@ -239,10 +249,6 @@ spec:
239249 params :
240250 - name : IMAGE
241251 value : $(params.output-image-repo):$(params.revision)
242- - name : COMMIT_SHA
243- value : $(tasks.clone-repository.results.commit)
244- - name : IMAGE_EXPIRES_AFTER
245- value : $(params.image-expires-after)
246252 - name : ALWAYS_BUILD_INDEX
247253 value : $(params.build-image-index)
248254 - name : IMAGES
@@ -257,7 +263,7 @@ spec:
257263 - name : name
258264 value : build-image-index
259265 - name : bundle
260- value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.2 @sha256:3fa26d2c0768329c2df93c646bf5855245b74db7196ad55f83756ce22cd7f0f1
266+ value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.3 @sha256:550afde50349e22ec11191ea0db9a49395ab46fef4e8317d820b6e946677ebeb
261267 - name : kind
262268 value : task
263269 resolver : bundles
@@ -279,7 +285,7 @@ spec:
279285 - name : name
280286 value : source-build-oci-ta
281287 - name : bundle
282- value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.3@sha256:362f0475df00e7dfb5f15dea0481d1b68b287f60411718d70a23da3c059a5613
288+ value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.3@sha256:0917cfc7772e82cb8e74743c2104f43bcf2596aceafe87eec6fce69a8cac5f06
283289 - name : kind
284290 value : task
285291 resolver : bundles
@@ -302,7 +308,7 @@ spec:
302308 - name : name
303309 value : deprecated-image-check
304310 - name : bundle
305- value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:5ff16b7e6b4a8aa1adb352e74b9f831f77ff97bafd1b89ddb0038d63335f1a67
311+ value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:e78d0d3baf3c8cfc1a5ad278196b74032d9568b143a87c7a79ab780fedfb296e
306312 - name : kind
307313 value : task
308314 resolver : bundles
@@ -330,7 +336,7 @@ spec:
330336 - name : name
331337 value : clair-scan
332338 - name : bundle
333- value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:3fa03be0280f33d7070ea53f26d53e727199737a7a2b9a59a95071ae40a999ac
339+ value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:8fad4c2e2f470f82ee43d6b2ac72327b4d9c6e9cb514a678911c1c9359c29894
334340 - name : kind
335341 value : task
336342 resolver : bundles
@@ -356,7 +362,7 @@ spec:
356362 - name : name
357363 value : ecosystem-cert-preflight-checks
358364 - name : bundle
359- value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:b4ac586edea81dcd25dfc17f1bd57899825be2b443e48d572cd05ce058f153bb
365+ value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:e2bcf1174a6dae9969b8f12e94babe2a5881bc77a509f10823b6a9eac6392850
360366 - name : kind
361367 value : task
362368 resolver : bundles
@@ -376,14 +382,16 @@ spec:
376382 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
377383 - name : CACHI2_ARTIFACT
378384 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
385+ - name : TARGET_DIRS
386+ value : $(params.sast-target-dirs)
379387 runAfter :
380388 - build-image-index
381389 taskRef :
382390 params :
383391 - name : name
384392 value : sast-snyk-check-oci-ta
385393 - name : bundle
386- value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4@sha256:ba3eff8f97a7cfc5341f3138c8a13e532238298d9a0fb94401c0971d30eb115a
394+ value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4@sha256:8f3ecbeaff579e41b8278f82d7fabac27845db17a8e687ea6c510c0c9aceabbb
387395 - name : kind
388396 value : task
389397 resolver : bundles
@@ -411,7 +419,7 @@ spec:
411419 - name : name
412420 value : clamav-scan
413421 - name : bundle
414- value : quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.3@sha256:9f18b216ce71a66909e7cb17d9b34526c02d73cf12884ba32d1f10614f7b9f5a
422+ value : quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.3@sha256:567cb66bd2e1f4b58b9d4d756f3317fc62479e0b40aa0de66094b1f12d296cfc
415423 - name : kind
416424 value : task
417425 resolver : bundles
@@ -429,7 +437,7 @@ spec:
429437 - name : name
430438 value : coverity-availability-check
431439 - name : bundle
432- value : quay.io/konflux-ci/tekton-catalog/task-coverity-availability-check:0.2@sha256:de35caf2f090e3275cfd1019ea50d9662422e904fb4aebd6ea29fb53a1ad57f5
440+ value : quay.io/konflux-ci/tekton-catalog/task-coverity-availability-check:0.2@sha256:8b501440a960aec446db2ebc6625a49d0317a9fc7bf0f7bd9b18cb63052db7de
433441 - name : kind
434442 value : task
435443 resolver : bundles
@@ -468,14 +476,16 @@ spec:
468476 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
469477 - name : CACHI2_ARTIFACT
470478 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
479+ - name : TARGET_DIRS
480+ value : $(params.sast-target-dirs)
471481 runAfter :
472482 - coverity-availability-check
473483 taskRef :
474484 params :
475485 - name : name
476486 value : sast-coverity-check-oci-ta
477487 - name : bundle
478- value : quay.io/konflux-ci/tekton-catalog/task-sast-coverity-check-oci-ta:0.3@sha256:47f4e2d0881ac8c43a1ea1e2375bb2591dff34b5aa8c7366a043652d1eed499c
488+ value : quay.io/konflux-ci/tekton-catalog/task-sast-coverity-check-oci-ta:0.3@sha256:e92d00ed858233d0096627861192d3e4fc013cf1559c0d0b0ea0657d3377ce75
479489 - name : kind
480490 value : task
481491 resolver : bundles
@@ -499,14 +509,16 @@ spec:
499509 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
500510 - name : CACHI2_ARTIFACT
501511 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
512+ - name : TARGET_DIRS
513+ value : $(params.sast-target-dirs)
502514 runAfter :
503515 - build-image-index
504516 taskRef :
505517 params :
506518 - name : name
507519 value : sast-shell-check-oci-ta
508520 - name : bundle
509- value : quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:c89a2bcf408ede50b161005859c76868f8007bb2a5daa06c1effe979b02145d7
521+ value : quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:c4ef47e3b4e0508572d266fb745be7e374c29dc02580328cbe9f4d472a8aca57
510522 - name : kind
511523 value : task
512524 resolver : bundles
@@ -526,14 +538,16 @@ spec:
526538 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
527539 - name : CACHI2_ARTIFACT
528540 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
541+ - name : TARGET_DIRS
542+ value : $(params.sast-target-dirs)
529543 runAfter :
530544 - build-image-index
531545 taskRef :
532546 params :
533547 - name : name
534548 value : sast-unicode-check-oci-ta
535549 - name : bundle
536- value : quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.4@sha256:92552dddd259cd4cc2ac9a19a02e6649cadfdbb8cd66b61b8c9748d94f2166a5
550+ value : quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.4@sha256:90efa582de7770d55102b74014a765cd16a25a56f2cf644b56a788c70c4dc749
537551 - name : kind
538552 value : task
539553 resolver : bundles
@@ -556,7 +570,7 @@ spec:
556570 - name : name
557571 value : apply-tags
558572 - name : bundle
559- value : quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.3@sha256:aa62b41861c09e2e59c69cc6e9a1f740bf0c81e6a1eb03f57f59dfda0f65840e
573+ value : quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.3@sha256:a291081de7fb27f832c6fc3c4b078acf7e6162ca4c085db38b118ca87e8b5b66
560574 - name : kind
561575 value : task
562576 resolver : bundles
@@ -580,7 +594,7 @@ spec:
580594 - name : name
581595 value : push-dockerfile-oci-ta
582596 - name : bundle
583- value : quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.3@sha256:1bc2d0f26b89259db090a47bb38217c82c05e335d626653d184adf1d196ca131
597+ value : quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.3@sha256:7855471abfe87de080b914f2f3ca27c59e64f6448a7c2435e51435b764494c71
584598 - name : kind
585599 value : task
586600 resolver : bundles
@@ -598,7 +612,7 @@ spec:
598612 - name : name
599613 value : rpms-signature-scan
600614 - name : bundle
601- value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:0eb4cfb41181a158b6761c990cc7a9f7f77c70f7ff19bf276009c6ef59c9da5e
615+ value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:cfdb76c67f27bc498132431f5a24fbc17dac1981d6f6e3da5cf5964ac5abdd20
602616 - name : kind
603617 value : task
604618 resolver : bundles
0 commit comments