From 39a21695b55617d37de79ba84eebcd9cf0d0cfbf Mon Sep 17 00:00:00 2001 From: Gal Ben Haim Date: Wed, 20 Nov 2024 20:59:38 +0200 Subject: [PATCH 1/2] chore: remove unsupported task sbom-json-check remove unsupported task sbom-json-check Signed-off-by: Gal Ben Haim --- .tekton/konflux-ui-pull-request.yaml | 22 ---------------------- .tekton/konflux-ui-push.yaml | 22 ---------------------- 2 files changed, 44 deletions(-) diff --git a/.tekton/konflux-ui-pull-request.yaml b/.tekton/konflux-ui-pull-request.yaml index 7ff65ad..2def556 100644 --- a/.tekton/konflux-ui-pull-request.yaml +++ b/.tekton/konflux-ui-pull-request.yaml @@ -390,28 +390,6 @@ spec: operator: in values: - "false" - - name: sbom-json-check - params: - - name: IMAGE_URL - value: $(tasks.build-container.results.IMAGE_URL) - - name: IMAGE_DIGEST - value: $(tasks.build-container.results.IMAGE_DIGEST) - runAfter: - - build-container - taskRef: - params: - - name: name - value: sbom-json-check - - name: bundle - value: quay.io/konflux-ci/tekton-catalog/task-sbom-json-check:0.2@sha256:f3f441de3002c5654acdff0553fd54cb1409e6bef6ff68e514d1731c9688b5cc - - name: kind - value: task - resolver: bundles - when: - - input: $(params.skip-checks) - operator: in - values: - - "false" - name: apply-tags params: - name: IMAGE diff --git a/.tekton/konflux-ui-push.yaml b/.tekton/konflux-ui-push.yaml index 1c32099..56669f9 100644 --- a/.tekton/konflux-ui-push.yaml +++ b/.tekton/konflux-ui-push.yaml @@ -387,28 +387,6 @@ spec: operator: in values: - "false" - - name: sbom-json-check - params: - - name: IMAGE_URL - value: $(tasks.build-container.results.IMAGE_URL) - - name: IMAGE_DIGEST - value: $(tasks.build-container.results.IMAGE_DIGEST) - runAfter: - - build-container - taskRef: - params: - - name: name - value: sbom-json-check - - name: bundle - value: quay.io/konflux-ci/tekton-catalog/task-sbom-json-check:0.2@sha256:f3f441de3002c5654acdff0553fd54cb1409e6bef6ff68e514d1731c9688b5cc - - name: kind - value: task - resolver: bundles - when: - - input: $(params.skip-checks) - operator: in - values: - - "false" - name: apply-tags params: - name: IMAGE From 4a5f47b8dcc6ec57aca837e7fe65a7a07ad1c2d7 Mon Sep 17 00:00:00 2001 From: Gal Ben Haim Date: Wed, 20 Nov 2024 21:03:36 +0200 Subject: [PATCH 2/2] chore: add rpms-signature-scan add rpms-signature-scan Signed-off-by: Gal Ben Haim --- .tekton/konflux-ui-pull-request.yaml | 17 +++++++++++++++++ .tekton/konflux-ui-push.yaml | 17 +++++++++++++++++ 2 files changed, 34 insertions(+) diff --git a/.tekton/konflux-ui-pull-request.yaml b/.tekton/konflux-ui-pull-request.yaml index 2def556..d92facc 100644 --- a/.tekton/konflux-ui-pull-request.yaml +++ b/.tekton/konflux-ui-pull-request.yaml @@ -405,6 +405,23 @@ spec: - name: kind value: task resolver: bundles + - name: rpms-signature-scan + params: + - name: image-digest + value: $(tasks.build-container.results.IMAGE_DIGEST) + - name: image-url + value: $(tasks.build-container.results.IMAGE_URL) + runAfter: + - build-container + taskRef: + params: + - name: name + value: rpms-signature-scan + - name: bundle + value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8 + - name: kind + value: task + resolver: bundles - name: push-dockerfile params: - name: IMAGE diff --git a/.tekton/konflux-ui-push.yaml b/.tekton/konflux-ui-push.yaml index 56669f9..9cde796 100644 --- a/.tekton/konflux-ui-push.yaml +++ b/.tekton/konflux-ui-push.yaml @@ -402,6 +402,23 @@ spec: - name: kind value: task resolver: bundles + - name: rpms-signature-scan + params: + - name: image-digest + value: $(tasks.build-container.results.IMAGE_DIGEST) + - name: image-url + value: $(tasks.build-container.results.IMAGE_URL) + runAfter: + - build-container + taskRef: + params: + - name: name + value: rpms-signature-scan + - name: bundle + value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8 + - name: kind + value: task + resolver: bundles - name: push-dockerfile params: - name: IMAGE