diff --git a/.tekton/scanner-component-pipeline.yaml b/.tekton/scanner-component-pipeline.yaml index f79c3d15f..787a242ca 100644 --- a/.tekton/scanner-component-pipeline.yaml +++ b/.tekton/scanner-component-pipeline.yaml @@ -17,7 +17,7 @@ spec: # Run when any task has Failed - input: $(tasks.status) operator: in - values: [ "Failed" ] + values: ["Failed"] taskRef: params: - name: name @@ -114,7 +114,7 @@ spec: description: Build stage to target in container build name: build-target-stage type: string - - default: [ ] + - default: [] description: List of scanner-data file names to fetch to include in the container build. name: blobs-to-fetch type: array @@ -185,7 +185,7 @@ spec: - name: name value: init - name: bundle - value: quay.io/konflux-ci/tekton-catalog/task-init:0.2@sha256:a558472b2ff44c4179ae97e90b35098dc2ca1456caf8c16c76f38c6863042c81 + value: quay.io/konflux-ci/tekton-catalog/task-init:0.2@sha256:b349d24cb896573695802d6913d311640b44675ec082b3ad167721946a6a0a71 - name: kind value: task resolver: bundles @@ -216,7 +216,7 @@ spec: when: - input: $(tasks.init.results.build) operator: in - values: [ "true" ] + values: ["true"] workspaces: - name: basic-auth workspace: git-auth @@ -256,7 +256,7 @@ spec: - name: fetch-scanner-data params: - name: BLOBS_TO_FETCH - value: [ "$(params.blobs-to-fetch[*])" ] + value: ["$(params.blobs-to-fetch[*])"] - name: TARGET_DIR value: .konflux/scanner-data - name: SOURCE_ARTIFACT @@ -295,7 +295,7 @@ spec: - name: name value: prefetch-dependencies-oci-ta - name: bundle - value: quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.2@sha256:3fa0204a481044b21f0e784ce39cbd25e8fb49c664a5458f3eef351fff1c906e + value: quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.2@sha256:3e5e834290a1ed57fd14c0082e5a10789c8fe382ed682ef7f981475a7b316b49 - name: kind value: task resolver: bundles @@ -338,22 +338,26 @@ spec: - name: BUILDAH_FORMAT value: $(params.buildah-format) - name: LABELS - value: [ "$(params.extra-labels[*])" ] + value: ["$(params.extra-labels[*])"] - name: BUILD_TIMESTAMP value: "$(tasks.clone-repository.results.commit-timestamp)" + - name: HTTP_PROXY + value: $(tasks.init.results.http-proxy) + - name: NO_PROXY + value: $(tasks.init.results.no-proxy) taskRef: params: - name: name value: buildah-remote-oci-ta - name: bundle - value: quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.7@sha256:ee5e01eb59a3f70bb1012950fbc4081bac96d3f3517e6d204314484cd2e0059b + value: quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.7@sha256:ef1c062b10c9fb17951350de76bce6bb54a4ea75fca4f37ea136d626c444bf78 - name: kind value: task resolver: bundles when: - input: $(tasks.init.results.build) operator: in - values: [ "true" ] + values: ["true"] - name: build-image-index params: @@ -368,20 +372,20 @@ spec: value: $(tasks.determine-image-expiration.results.IMAGE_EXPIRES_AFTER) - name: BUILDAH_FORMAT value: $(params.buildah-format) - runAfter: [ build-images ] + runAfter: [build-images] taskRef: params: - name: name value: build-image-index - name: bundle - value: quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.2@sha256:803ae1ecf35bc5d22be9882819e942e4b699cb17655055afc6bb6b02d34cfab8 + value: quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.2@sha256:39561ac43e325159497c10c0284cf61dfddf39e39100ca5e3df6b73c5d96db8b - name: kind value: task resolver: bundles when: - input: $(tasks.init.results.build) operator: in - values: [ "true" ] + values: ["true"] - name: apply-index-image-tag params: @@ -397,14 +401,14 @@ spec: - name: name value: apply-tags - name: bundle - value: quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.2@sha256:a61d8a6d0ba804869e8fe57a9289161817afad379ef2d7433d75ae40a148e2ec + value: quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.2@sha256:e4017ec351a0891ef95989f35bd20b8c3f091fa1a3da364c4d4e975e99f3063c - name: kind value: task resolver: bundles when: - input: $(tasks.init.results.build) operator: in - values: [ "true" ] + values: ["true"] - name: build-source-image params: @@ -428,10 +432,10 @@ spec: when: - input: $(tasks.init.results.build) operator: in - values: [ "true" ] + values: ["true"] - input: $(params.build-source-image) operator: in - values: [ "true" ] + values: ["true"] - name: deprecated-base-image-check params: @@ -451,7 +455,7 @@ spec: when: - input: $(params.skip-checks) operator: in - values: [ "false" ] + values: ["false"] - name: clair-scan matrix: @@ -469,14 +473,14 @@ spec: - name: name value: clair-scan - name: bundle - value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:ee558db6af779ab162163ec88f288a5c1b2d5f70c3361f3690a474866e3bdc74 + value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:a5fa66ed5b8c107e7bc29cb084edcc07e394f818cc59ef2db2f9dcb0cd1fa3dc - name: kind value: task resolver: bundles when: - input: $(params.skip-checks) operator: in - values: [ "false" ] + values: ["false"] - name: ecosystem-cert-preflight-checks matrix: @@ -499,7 +503,7 @@ spec: when: - input: $(params.skip-checks) operator: in - values: [ "false" ] + values: ["false"] - name: sast-shell-check params: @@ -523,7 +527,7 @@ spec: when: - input: $(params.skip-checks) operator: in - values: [ "false" ] + values: ["false"] - name: sast-unicode-check params: @@ -547,7 +551,7 @@ spec: when: - input: $(params.skip-checks) operator: in - values: [ "false" ] + values: ["false"] - name: sast-snyk-check params: @@ -564,14 +568,14 @@ spec: - name: name value: sast-snyk-check-oci-ta - name: bundle - value: quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4@sha256:8ad28b7783837a24acbc9a8494c935e796e591ce476085ad5899bebd7e53f077 + value: quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4@sha256:0eca130f289a1a1069a1b92943479f79aa7324e4e68d6396fd777ccd97058f50 - name: kind value: task resolver: bundles when: - input: $(params.skip-checks) operator: in - values: [ "false" ] + values: ["false"] - name: clamav-scan matrix: @@ -596,7 +600,7 @@ spec: when: - input: $(params.skip-checks) operator: in - values: [ "false" ] + values: ["false"] - name: rpms-signature-scan params: @@ -609,14 +613,14 @@ spec: - name: name value: rpms-signature-scan - name: bundle - value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:90c2b32ebf0a00f42c0c1d1675feb75ba71793ad1a4c22ddea7cdc71ed997a04 + value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:0b10508c82ccb0f5a06a66ce7af56e9bfd40651ddefdf0f499988e897771ee28 - name: kind value: task resolver: bundles when: - input: $(params.skip-checks) operator: in - values: [ "false" ] + values: ["false"] - name: push-dockerfile params: