1
1
apiVersion : tekton.dev/v1
2
2
kind : Pipeline
3
3
metadata :
4
- creationTimestamp : null
4
+ creationTimestamp :
5
5
labels :
6
6
pipelines.openshift.io/runtime : generic
7
7
pipelines.openshift.io/strategy : docker
@@ -33,21 +33,19 @@ spec:
33
33
- linux/arm64
34
34
- linux/ppc64le
35
35
- linux/s390x
36
- description : List of platforms to build the container images on. The available
37
- set of values is determined by the configuration of the multi-platform-controller.
36
+ description : List of platforms to build the container images on. The available set of values is determined by the configuration of the multi-platform-controller.
38
37
name : build-platforms
39
38
type : array
40
39
- default : --all-projects --org=3e1a4cca-ebfb-495f-b64c-3cc960d566b4 --exclude=test*,vendor,third_party
41
40
description : Append arguments to Snyk code command.
42
41
name : snyk-args
43
42
type : string
44
- - default : " true"
43
+ - default : ' true'
45
44
description : Build a source image.
46
45
name : build-source-image
47
46
type : string
48
- - default : " false"
49
- description : ' Enable in-development package managers. WARNING: the behavior may
50
- change at any time without notice. Use at your own risk.'
47
+ - default : ' false'
48
+ description : ' Enable in-development package managers. WARNING: the behavior may change at any time without notice. Use at your own risk.'
51
49
name : prefetch-input-dev-package-managers
52
50
- default : []
53
51
description : Additional image tags
@@ -56,71 +54,67 @@ spec:
56
54
- description : Source Repository URL
57
55
name : git-url
58
56
type : string
59
- - default : " "
57
+ - default : ' '
60
58
description : Revision of the Source Repository
61
59
name : revision
62
60
type : string
63
61
- description : Fully Qualified Output Image
64
62
name : output-image
65
63
type : string
66
64
- default : .
67
- description : Path to the source code of an application's component from where
68
- to build image.
65
+ description : Path to the source code of an application's component from where to build image.
69
66
name : path-context
70
67
type : string
71
68
- default : Dockerfile
72
- description : Path to the Dockerfile inside the context specified by parameter
73
- path-context
69
+ description : Path to the Dockerfile inside the context specified by parameter path-context
74
70
name : dockerfile
75
71
type : string
76
- - default : " false"
72
+ - default : ' false'
77
73
description : Force rebuild image
78
74
name : rebuild
79
75
type : string
80
- - default : " false"
76
+ - default : ' false'
81
77
description : Skip checks against built image
82
78
name : skip-checks
83
79
type : string
84
- - default : " false"
80
+ - default : ' false'
85
81
description : Execute the build with network isolation
86
82
name : hermetic
87
83
type : string
88
- - default : " "
84
+ - default : ' '
89
85
description : Build dependencies to be prefetched by Cachi2
90
86
name : prefetch-input
91
87
type : string
92
- - default : " "
93
- description : Image tag expiration time, time values could be something like 1h,
94
- 2d, 3w for hours, days, and weeks, respectively.
88
+ - default : ' '
89
+ description : Image tag expiration time, time values could be something like 1h, 2d, 3w for hours, days, and weeks, respectively.
95
90
name : image-expires-after
96
- - default : " true"
91
+ - default : ' true'
97
92
description : Add built image into an OCI image index
98
93
name : build-image-index
99
94
type : string
100
95
- default : []
101
96
description : Array of --build-arg values ("arg=value" strings) for buildah
102
97
name : build-args
103
98
type : array
104
- - default : " "
99
+ - default : ' '
105
100
description : Path to a file with build arguments for buildah, see https://www.mankier.com/1/buildah-build#--build-arg-file
106
101
name : build-args-file
107
102
type : string
108
- - default : " false"
109
- description : Whether to enable privileged mode, should be used only with remote
110
- VMs
103
+ - default : ' false'
104
+ description : Whether to enable privileged mode, should be used only with remote VMs
111
105
name : privileged-nested
112
106
type : string
113
107
results :
114
- - description : " "
108
+ - description : ' '
115
109
name : IMAGE_URL
116
110
value : $(tasks.build-image-index.results.IMAGE_URL)
117
- - description : " "
111
+ - description : ' '
118
112
name : IMAGE_DIGEST
119
113
value : $(tasks.build-image-index.results.IMAGE_DIGEST)
120
- - description : " "
114
+ - description : ' '
121
115
name : CHAINS-GIT_URL
122
116
value : $(tasks.clone-repository.results.url)
123
- - description : " "
117
+ - description : ' '
124
118
name : CHAINS-GIT_COMMIT
125
119
value : $(tasks.clone-repository.results.commit)
126
120
tasks :
@@ -143,15 +137,15 @@ spec:
143
137
- name : name
144
138
value : sast-snyk-check-oci-ta
145
139
- name : bundle
146
- value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4@sha256:9a6ec5575f80668552d861e64414e736c85af772c272ca653a6fd1ec841d2627
140
+ value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4@sha256:e61f541189b30d14292ef8df36ccaf13f7feb2378fed5f74cb6293b3e79eb687
147
141
- name : kind
148
142
value : task
149
143
resolver : bundles
150
144
when :
151
145
- input : $(params.skip-checks)
152
146
operator : in
153
147
values :
154
- - " false"
148
+ - ' false'
155
149
- name : prefetch-dependencies
156
150
params :
157
151
- name : dev-package-managers
@@ -171,7 +165,7 @@ spec:
171
165
- name : name
172
166
value : prefetch-dependencies-oci-ta
173
167
- name : bundle
174
- value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.2@sha256:1f6e2c9beba52d21c562ba1dea55f579f67e33b80099615bfd2043864896284d
168
+ value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.2@sha256:d0cbc492da865be336d09926eb6e3494403dccaa4a212bbdf472d8adbf80ab08
175
169
- name : kind
176
170
value : task
177
171
resolver : bundles
@@ -184,16 +178,18 @@ spec:
184
178
params :
185
179
- name : ADDITIONAL_TAGS
186
180
value : $(params.additional-tags[*])
187
- - name : IMAGE
181
+ - name : IMAGE_URL
188
182
value : $(tasks.build-image-index.results.IMAGE_URL)
183
+ - name : IMAGE_DIGEST
184
+ value : $(tasks.build-image-index.results.IMAGE_DIGEST)
189
185
runAfter :
190
186
- build-image-index
191
187
taskRef :
192
188
params :
193
189
- name : name
194
190
value : apply-tags
195
191
- name : bundle
196
- value : quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.1 @sha256:1c6f673fe100a49f58aaef62580c8adf0c397790964f4e7bac7fcd3f4d07c92e
192
+ value : quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.2 @sha256:517a51e260c0b59654a9d7b842e1ab07d76bce15ca7ce9c8fd2489a19be6463d
197
193
- name : kind
198
194
value : task
199
195
resolver : bundles
@@ -231,15 +227,15 @@ spec:
231
227
- name : name
232
228
value : git-clone-oci-ta
233
229
- name : bundle
234
- value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:0fea1e4bd2fdde46c5b7786629f423a51e357f681c32ceddd744a6e3d48b8327
230
+ value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:0e512b12775b2bcc4eb47bb34b7a2db2e91c3ceef04b2f2487fa421032d8859a
235
231
- name : kind
236
232
value : task
237
233
resolver : bundles
238
234
when :
239
235
- input : $(tasks.init.results.build)
240
236
operator : in
241
237
values :
242
- - " true"
238
+ - ' true'
243
239
workspaces :
244
240
- name : basic-auth
245
241
workspace : git-auth
@@ -276,23 +272,23 @@ spec:
276
272
- name : CACHI2_ARTIFACT
277
273
value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
278
274
- name : IMAGE_APPEND_PLATFORM
279
- value : " true"
275
+ value : ' true'
280
276
runAfter :
281
277
- prefetch-dependencies
282
278
taskRef :
283
279
params :
284
280
- name : name
285
281
value : buildah-remote-oci-ta
286
282
- name : bundle
287
- value : quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.4@sha256:cfeeef2f4ab25b121afdf44eecc394ed67f3534a1bd14bef9e7beef2ee654b8e
283
+ value : quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.4@sha256:28d8a4f7c1ff6e8bb09d89b06c7c8769093ac7e9325ad9edfe7b2d766f643b87
288
284
- name : kind
289
285
value : task
290
286
resolver : bundles
291
287
when :
292
288
- input : $(tasks.init.results.build)
293
289
operator : in
294
290
values :
295
- - " true"
291
+ - ' true'
296
292
- name : build-image-index
297
293
params :
298
294
- name : IMAGE
@@ -313,15 +309,15 @@ spec:
313
309
- name : name
314
310
value : build-image-index
315
311
- name : bundle
316
- value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.1@sha256:9c95b1fe17db091ae364344ba2006af46648e08486eef1f6fe1b9e3f10866875
312
+ value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.1@sha256:3cf3dcc0bf7b674b940063b4d55e41fe7d43636a1d82572e3850228aa5350fa8
317
313
- name : kind
318
314
value : task
319
315
resolver : bundles
320
316
when :
321
317
- input : $(tasks.init.results.build)
322
318
operator : in
323
319
values :
324
- - " true"
320
+ - ' true'
325
321
- name : build-source-image
326
322
params :
327
323
- name : BINARY_IMAGE
@@ -337,19 +333,19 @@ spec:
337
333
- name : name
338
334
value : source-build-oci-ta
339
335
- name : bundle
340
- value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.2@sha256:c5e56643c0f5e19409e86c8fd4de4348413b6f10456aa0875498d5c63bf6ef0e
336
+ value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.2@sha256:f0784e8e0e396f40a6523693825b5966c3c615ba3d342350165e83cb72a24ef7
341
337
- name : kind
342
338
value : task
343
339
resolver : bundles
344
340
when :
345
341
- input : $(tasks.init.results.build)
346
342
operator : in
347
343
values :
348
- - " true"
344
+ - ' true'
349
345
- input : $(params.build-source-image)
350
346
operator : in
351
347
values :
352
- - " true"
348
+ - ' true'
353
349
- name : deprecated-base-image-check
354
350
params :
355
351
- name : IMAGE_URL
@@ -363,15 +359,15 @@ spec:
363
359
- name : name
364
360
value : deprecated-image-check
365
361
- name : bundle
366
- value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:ecd33669676b3a193ff4c2c6223cb912cc1b0cf5cc36e080eaec7718500272cf
362
+ value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:270a79138a98e43c366d3722978cb5940d2bcb822ba6b60377330f863b7a1e62
367
363
- name : kind
368
364
value : task
369
365
resolver : bundles
370
366
when :
371
367
- input : $(params.skip-checks)
372
368
operator : in
373
369
values :
374
- - " false"
370
+ - ' false'
375
371
- name : clair-scan
376
372
params :
377
373
- name : image-digest
@@ -385,15 +381,15 @@ spec:
385
381
- name : name
386
382
value : clair-scan
387
383
- name : bundle
388
- value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.2@sha256:68a8fe28527c4469243119a449e2b3a6655f2acac589c069ea6433242da8ed4d
384
+ value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.2@sha256:d354939892f3a904223ec080cc3771bd11931085a5d202323ea491ee8e8c5e43
389
385
- name : kind
390
386
value : task
391
387
resolver : bundles
392
388
when :
393
389
- input : $(params.skip-checks)
394
390
operator : in
395
391
values :
396
- - " false"
392
+ - ' false'
397
393
- name : ecosystem-cert-preflight-checks
398
394
params :
399
395
- name : image-url
@@ -405,15 +401,15 @@ spec:
405
401
- name : name
406
402
value : ecosystem-cert-preflight-checks
407
403
- name : bundle
408
- value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:302828e9d7abc72b8a44fb2b9be068f86c982d8e5f4550b8bf654571d6361ee8
404
+ value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:95ca11d147ee97d98f495477e9f42afe94ba3f869fc81c4e7b241ebd21e7395f
409
405
- name : kind
410
406
value : task
411
407
resolver : bundles
412
408
when :
413
409
- input : $(params.skip-checks)
414
410
operator : in
415
411
values :
416
- - " false"
412
+ - ' false'
417
413
- name : clamav-scan
418
414
params :
419
415
- name : image-digest
@@ -427,15 +423,15 @@ spec:
427
423
- name : name
428
424
value : clamav-scan
429
425
- name : bundle
430
- value : quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.2@sha256:386c8c3395b44f6eb927dbad72382808b0ae42008f183064ca77cb4cad998442
426
+ value : quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.2@sha256:9cab95ac9e833d77a63c079893258b73b8d5a298d93aaf9bdd6722471bc2f338
431
427
- name : kind
432
428
value : task
433
429
resolver : bundles
434
430
when :
435
431
- input : $(params.skip-checks)
436
432
operator : in
437
433
values :
438
- - " false"
434
+ - ' false'
439
435
- name : sast-shell-check
440
436
params :
441
437
- name : image-digest
@@ -453,15 +449,15 @@ spec:
453
449
- name : name
454
450
value : sast-shell-check-oci-ta
455
451
- name : bundle
456
- value : quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:a7766190229785bc5db9c62af92d46a83ea580a111b4b64a4e27f6caecae9489
452
+ value : quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:1e8f18f892e16f5d0fc0f42ae8512e3c78251d43cd9d9f7cfd3f6667242bf619
457
453
- name : kind
458
454
value : task
459
455
resolver : bundles
460
456
when :
461
457
- input : $(params.skip-checks)
462
458
operator : in
463
459
values :
464
- - " false"
460
+ - ' false'
465
461
- name : sast-unicode-check
466
462
params :
467
463
- name : image-digest
@@ -479,15 +475,15 @@ spec:
479
475
- name : name
480
476
value : sast-unicode-check-oci-ta
481
477
- name : bundle
482
- value : quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.2@sha256:9613b9037e4199495800c2054c13d0479e3335ec94e0f15f031a5bce844003a9
478
+ value : quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.2@sha256:24ad71fde435fc25abba2c4c550beb088b1530f738d3c377e2f635b5f320d57b
483
479
- name : kind
484
480
value : task
485
481
resolver : bundles
486
482
when :
487
483
- input : $(params.skip-checks)
488
484
operator : in
489
485
values :
490
- - " false"
486
+ - ' false'
491
487
- name : push-dockerfile
492
488
params :
493
489
- name : IMAGE
@@ -507,7 +503,7 @@ spec:
507
503
- name : name
508
504
value : push-dockerfile-oci-ta
509
505
- name : bundle
510
- value : quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.1@sha256:d0ee13ab3d9564f7ee806a8ceaced934db493a3a40e11ff6db3a912b8bbace95
506
+ value : quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.1@sha256:5d8013b6a27bbc5e4ff261144616268f28417ed0950d583ef36349fcd59d3d3d
511
507
- name : kind
512
508
value : task
513
509
resolver : bundles
@@ -524,15 +520,15 @@ spec:
524
520
- name : name
525
521
value : rpms-signature-scan
526
522
- name : bundle
527
- value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:ec7f6de651458e4a5842b145e761b0d86b03b52bec1515d6d8a1b8cf107af95c
523
+ value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:1b6c20ab3dbfb0972803d3ebcb2fa72642e59400c77bd66dfd82028bdd09e120
528
524
- name : kind
529
525
value : task
530
526
resolver : bundles
531
527
when :
532
528
- input : $(params.skip-checks)
533
529
operator : in
534
530
values :
535
- - " false"
531
+ - ' false'
536
532
workspaces :
537
533
- name : git-auth
538
534
optional : true
0 commit comments