@@ -100,6 +100,14 @@ spec:
100100 VMs
101101 name : privileged-nested
102102 type : string
103+ - name : sast-target-dirs
104+ type : string
105+ default : .
106+ description : Target directories to scan with SAST tools. Multiple values should be separated with commas.
107+ - name : enable-package-registry-proxy
108+ default : ' true'
109+ description : Use the package registry proxy when prefetching dependencies
110+ type : string
103111 results :
104112 - description : " "
105113 name : IMAGE_URL
@@ -126,14 +134,16 @@ spec:
126134 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
127135 - name : CACHI2_ARTIFACT
128136 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
137+ - name : TARGET_DIRS
138+ value : $(params.sast-target-dirs)
129139 runAfter :
130140 - build-image-index
131141 taskRef :
132142 params :
133143 - name : name
134144 value : sast-snyk-check-oci-ta
135145 - name : bundle
136- value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4@sha256:2ad986f28d0b724dabcf76c4de649f058f0e66998c7d2f61b66de46533bdbcad
146+ value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4@sha256:8f3ecbeaff579e41b8278f82d7fabac27845db17a8e687ea6c510c0c9aceabbb
137147 - name : kind
138148 value : task
139149 resolver : bundles
@@ -154,14 +164,16 @@ spec:
154164 value : $(params.output-image).prefetch
155165 - name : ociArtifactExpiresAfter
156166 value : $(params.image-expires-after)
167+ - name : enable-package-registry-proxy
168+ value : $(params.enable-package-registry-proxy)
157169 runAfter :
158170 - clone-repository
159171 taskRef :
160172 params :
161173 - name : name
162174 value : prefetch-dependencies-oci-ta
163175 - name : bundle
164- value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:9917d11f0a38c844184042d504b3d5605c009e6e43785fa113caae8b4c99b75e
176+ value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:3dc78afbf3a441e0280067433cb28ea3d2d0088ec214c73bf063f145b4f273ef
165177 - name : kind
166178 value : task
167179 resolver : bundles
@@ -185,7 +197,7 @@ spec:
185197 - name : name
186198 value : apply-tags
187199 - name : bundle
188- value : quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.3@sha256:aa62b41861c09e2e59c69cc6e9a1f740bf0c81e6a1eb03f57f59dfda0f65840e
200+ value : quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.3@sha256:a291081de7fb27f832c6fc3c4b078acf7e6162ca4c085db38b118ca87e8b5b66
189201 - name : kind
190202 value : task
191203 resolver : bundles
@@ -198,7 +210,7 @@ spec:
198210 - name : name
199211 value : init
200212 - name : bundle
201- value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:288f3106118edc1d0f0c79a89c960abf5841a4dd8bc3f38feb10527253105b19
213+ value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:5a423246792ac501ea279229b42ee57da9927da441c04b5c9ff86817b0856b08
202214 - name : kind
203215 value : task
204216 resolver : bundles
@@ -219,7 +231,7 @@ spec:
219231 - name : name
220232 value : git-clone-oci-ta
221233 - name : bundle
222- value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:2c388d28651457db60bb90287e7d8c3680303197196e4476878d98d81e8b6dc9
234+ value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:d30f13dd15daf89dd6dc645243b3444d35570d13f7840c3fd65e366022515205
223235 - name : kind
224236 value : task
225237 resolver : bundles
@@ -275,7 +287,7 @@ spec:
275287 - name : name
276288 value : buildah-remote-oci-ta
277289 - name : bundle
278- value : quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.9@sha256:9a95e9fbbc405a4017c17c8c9f3acc92e603a693ebbb7e6e30331124dc03312a
290+ value : quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.9@sha256:f667d1146533b1d49829c08097e31faf27db24563da576434a707353de62099f
279291 - name : kind
280292 value : task
281293 resolver : bundles
@@ -297,7 +309,7 @@ spec:
297309 - name : name
298310 value : build-image-index
299311 - name : bundle
300- value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.3@sha256:ae3fa44f005054d4901d33413972227b5642d376968a67791535cdcc2e98473d
312+ value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.3@sha256:b33bfa8dc27dbf459f0779598ba45dcaa490bcc9f8efe1652bcf360ec8cb5582
301313 - name : kind
302314 value : task
303315 resolver : bundles
@@ -318,7 +330,7 @@ spec:
318330 - name : name
319331 value : source-build-oci-ta
320332 - name : bundle
321- value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.3@sha256:362f0475df00e7dfb5f15dea0481d1b68b287f60411718d70a23da3c059a5613
333+ value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.3@sha256:0917cfc7772e82cb8e74743c2104f43bcf2596aceafe87eec6fce69a8cac5f06
322334 - name : kind
323335 value : task
324336 resolver : bundles
@@ -340,7 +352,7 @@ spec:
340352 - name : name
341353 value : deprecated-image-check
342354 - name : bundle
343- value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:5ff16b7e6b4a8aa1adb352e74b9f831f77ff97bafd1b89ddb0038d63335f1a67
355+ value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:e78d0d3baf3c8cfc1a5ad278196b74032d9568b143a87c7a79ab780fedfb296e
344356 - name : kind
345357 value : task
346358 resolver : bundles
@@ -367,7 +379,7 @@ spec:
367379 - name : name
368380 value : clair-scan
369381 - name : bundle
370- value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:89924756c91ded746cf9ccc9f07907595e5b2454ddda0219132913a4875a5f59
382+ value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:8fad4c2e2f470f82ee43d6b2ac72327b4d9c6e9cb514a678911c1c9359c29894
371383 - name : kind
372384 value : task
373385 resolver : bundles
@@ -392,7 +404,7 @@ spec:
392404 - name : name
393405 value : ecosystem-cert-preflight-checks
394406 - name : bundle
395- value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:b4ac586edea81dcd25dfc17f1bd57899825be2b443e48d572cd05ce058f153bb
407+ value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:9c300728a03f41beee9a689422d66513d32ab5f804664fe561b11cebacd07799
396408 - name : kind
397409 value : task
398410 resolver : bundles
@@ -419,7 +431,7 @@ spec:
419431 - name : name
420432 value : clamav-scan
421433 - name : bundle
422- value : quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.3@sha256:9f18b216ce71a66909e7cb17d9b34526c02d73cf12884ba32d1f10614f7b9f5a
434+ value : quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.3@sha256:567cb66bd2e1f4b58b9d4d756f3317fc62479e0b40aa0de66094b1f12d296cfc
423435 - name : kind
424436 value : task
425437 resolver : bundles
@@ -438,6 +450,8 @@ spec:
438450 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
439451 - name : CACHI2_ARTIFACT
440452 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
453+ - name : TARGET_DIRS
454+ value : $(params.sast-target-dirs)
441455 runAfter :
442456 - build-image-index
443457 taskRef :
@@ -464,14 +478,16 @@ spec:
464478 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
465479 - name : CACHI2_ARTIFACT
466480 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
481+ - name : TARGET_DIRS
482+ value : $(params.sast-target-dirs)
467483 runAfter :
468484 - build-image-index
469485 taskRef :
470486 params :
471487 - name : name
472488 value : sast-unicode-check-oci-ta
473489 - name : bundle
474- value : quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.4@sha256:0854d9261760b2dc8f092569739685a5ab0a5c620e9cb8c1b78fef9e2d077a29
490+ value : quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.4@sha256:90efa582de7770d55102b74014a765cd16a25a56f2cf644b56a788c70c4dc749
475491 - name : kind
476492 value : task
477493 resolver : bundles
@@ -499,7 +515,7 @@ spec:
499515 - name : name
500516 value : push-dockerfile-oci-ta
501517 - name : bundle
502- value : quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.3@sha256:1bc2d0f26b89259db090a47bb38217c82c05e335d626653d184adf1d196ca131
518+ value : quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.3@sha256:7855471abfe87de080b914f2f3ca27c59e64f6448a7c2435e51435b764494c71
503519 - name : kind
504520 value : task
505521 resolver : bundles
@@ -516,7 +532,7 @@ spec:
516532 - name : name
517533 value : rpms-signature-scan
518534 - name : bundle
519- value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:89c2bfeb95062712a374192a379854526ae77f03296dd5f2f6ed8b24db0555d0
535+ value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:41720da9dfe26f33b0bdc46bbf8667a27dae4790d8e5c5f4412224658de7b213
520536 - name : kind
521537 value : task
522538 resolver : bundles
0 commit comments