3131 value :
3232 - PROJECT_NAME=registry-viewer
3333 - NEXT_PUBLIC_BASE_PATH=/viewer
34+ - name : sast-target-dirs
35+ type : string
36+ default : .
37+ description : Target directories to scan with SAST tools. Multiple values should be separated with commas.
3438 pipelineSpec :
3539 description : |
3640 This pipeline is ideal for building container images from a Containerfile while maintaining trust after pipeline customization.
@@ -113,6 +117,10 @@ spec:
113117 default : ' true'
114118 description : Use the package registry proxy when prefetching dependencies
115119 type : string
120+ - name : sast-target-dirs
121+ type : string
122+ default : .
123+ description : Target directories to scan with SAST tools. Multiple values should be separated with commas.
116124 results :
117125 - description : " "
118126 name : IMAGE_URL
@@ -136,7 +144,7 @@ spec:
136144 - name : name
137145 value : init
138146 - name : bundle
139- value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:b797dd453ddad669365de6de4649e3a9e37e77aa26eb9862ca079a36cbfe64a4
147+ value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:90f0e8e134c4bb919956bb095d62365907adeea4fbeb4cebbf5f3f94286bf967
140148 - name : kind
141149 value : task
142150 resolver : bundles
@@ -183,7 +191,7 @@ spec:
183191 - name : name
184192 value : prefetch-dependencies-oci-ta
185193 - name : bundle
186- value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:1b209c0d93e52e418f3e6cd4b4fd915a84e4bd7f68e1cfd0d6446133540d7f43
194+ value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:a2efbcdcecfa5293a622eb356a18f5c88e5714046b214fe8730b43b1a7dbb77d
187195 - name : kind
188196 value : task
189197 resolver : bundles
@@ -295,7 +303,7 @@ spec:
295303 - name : name
296304 value : deprecated-image-check
297305 - name : bundle
298- value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:57d1f556982115311f603dd9a728c52a7a1d092f022e1db4560da01eca9e5d17
306+ value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:e78d0d3baf3c8cfc1a5ad278196b74032d9568b143a87c7a79ab780fedfb296e
299307 - name : kind
300308 value : task
301309 resolver : bundles
@@ -317,7 +325,7 @@ spec:
317325 - name : name
318326 value : clair-scan
319327 - name : bundle
320- value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:cd49cdea7e5403a87c4774bd8ea10bc4e6aeb83841ff490cbe42b782779513a7
328+ value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:8fad4c2e2f470f82ee43d6b2ac72327b4d9c6e9cb514a678911c1c9359c29894
321329 - name : kind
322330 value : task
323331 resolver : bundles
@@ -337,7 +345,7 @@ spec:
337345 - name : name
338346 value : ecosystem-cert-preflight-checks
339347 - name : bundle
340- value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:2468c01818fbaad2235e4fca438f28e847260e3e354cf5a441bbd671684af2db
348+ value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:e2bcf1174a6dae9969b8f12e94babe2a5881bc77a509f10823b6a9eac6392850
341349 - name : kind
342350 value : task
343351 resolver : bundles
@@ -356,6 +364,8 @@ spec:
356364 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
357365 - name : CACHI2_ARTIFACT
358366 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
367+ - name : TARGET_DIRS
368+ value : $(params.sast-target-dirs)
359369 runAfter :
360370 - build-image-index
361371 taskRef :
@@ -382,6 +392,8 @@ spec:
382392 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
383393 - name : CACHI2_ARTIFACT
384394 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
395+ - name : TARGET_DIRS
396+ value : $(params.sast-target-dirs)
385397 runAfter :
386398 - build-image-index
387399 taskRef :
@@ -408,6 +420,8 @@ spec:
408420 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
409421 - name : image-digest
410422 value : $(tasks.build-image-index.results.IMAGE_DIGEST)
423+ - name : TARGET_DIRS
424+ value : $(params.sast-target-dirs)
411425 runAfter :
412426 - build-image-index
413427 taskRef :
@@ -475,6 +489,8 @@ spec:
475489 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
476490 - name : CACHI2_ARTIFACT
477491 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
492+ - name : TARGET_DIRS
493+ value : $(params.sast-target-dirs)
478494 runAfter :
479495 - coverity-availability-check
480496 taskRef :
@@ -565,7 +581,7 @@ spec:
565581 - name : name
566582 value : rpms-signature-scan
567583 - name : bundle
568- value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:1d807f6be3be2bd8bff76321e9599bbafce8196dcd9597eeffd9df65466682af
584+ value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:4ceea61b0fa81bc5da05afb26d51e06e4843378d739e4d003b062d5d04cc5e90
569585 - name : kind
570586 value : task
571587 resolver : bundles
0 commit comments