Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
25 commits
Select commit Hold shift + click to select a range
657cc30
Test hermetic build
ncaak Mar 12, 2025
9853de7
Fix hermetic parameter
ncaak Mar 13, 2025
935e741
Fix prefetch-dependencies-oci-ta task on operator component
ncaak Mar 13, 2025
20fd56d
Fix clone-repository due to prefetch task changes
ncaak Mar 13, 2025
b65a75b
Fix clone-repository source
ncaak Mar 13, 2025
b49b24f
Revert "Fix clone-repository source"
ncaak Mar 13, 2025
c6e389c
Fix build-container task based on bundle tasks
ncaak Mar 13, 2025
4609cb6
Fix prefetch-input for hermetic builds
ncaak Mar 13, 2025
fbf268c
Fix yaml typo
ncaak Mar 13, 2025
fc2553b
Fix test gomod folder
ncaak Mar 13, 2025
90b0bbc
Add missing build-image-index task
ncaak Mar 13, 2025
d9ee276
Fix build-source-image task
ncaak Mar 13, 2025
eb6d9ae
Revert "Fix build-source-image task"
ncaak Mar 13, 2025
dae05f7
Revert "Add missing build-image-index task"
ncaak Mar 13, 2025
98b08c8
Test fixing build-source-image
ncaak Mar 13, 2025
eebf380
Fix update container image SHA
ncaak Mar 18, 2025
7c09a61
Test update tekton file for DVO operator image
ncaak Mar 19, 2025
d60260d
Merge branch 'master' into DVO-213/fix-ci-missing-elements
ncaak Apr 1, 2025
356d695
Fix merge conflcts leftovers and Update images SHAs
ncaak Apr 1, 2025
0f7d0bc
Add missing sast tasks
ncaak Apr 4, 2025
1484c57
Fix build-source-image missing error
ncaak Apr 4, 2025
3af3b68
Update Konflux references
ncaak Apr 9, 2025
ce45f7f
Remove problematic task on skipped scenario
ncaak Apr 9, 2025
32f93eb
Update push pipelines with last version
ncaak Apr 9, 2025
2cd8c4f
Merge branch 'master' into DVO-213/fix-ci-missing-elements
ncaak Apr 9, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
76 changes: 56 additions & 20 deletions .tekton/deployment-validation-operator-bundle-pull-request.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,10 @@ spec:
value: konflux-ci/bundle/bundle.Dockerfile
- name: path-context
value: konflux-ci/bundle
- name: hermetic
value: 'true'
- name: build-source-image
value: 'true'
pipelineSpec:
description: |
This pipeline is ideal for building container images from a Containerfile while maintaining trust after pipeline customization.
Expand Down Expand Up @@ -336,26 +340,6 @@ spec:
operator: in
values:
- "false"
- name: ecosystem-cert-preflight-checks
params:
- name: image-url
value: $(tasks.build-image-index.results.IMAGE_URL)
runAfter:
- build-image-index
taskRef:
params:
- name: name
value: ecosystem-cert-preflight-checks
- name: bundle
value: quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:00b13d06d17328e105b11619ee4db98b215ca6ac02314a4776aa5fc2a974f9c1
- name: kind
value: task
resolver: bundles
when:
- input: $(params.skip-checks)
operator: in
values:
- "false"
- name: sast-snyk-check
params:
- name: image-digest
Expand All @@ -382,6 +366,58 @@ spec:
operator: in
values:
- "false"
- name: sast-shell-check
params:
- name: image-digest
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
- name: image-url
value: $(tasks.build-image-index.results.IMAGE_URL)
- name: SOURCE_ARTIFACT
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
- name: CACHI2_ARTIFACT
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
runAfter:
- build-image-index
taskRef:
params:
- name: name
value: sast-shell-check-oci-ta
- name: bundle
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:a591675c72f06fb9c5b1a3d60e6e4c58e4df5f7da180c7a4691a692a6e7e6496
- name: kind
value: task
resolver: bundles
when:
- input: $(params.skip-checks)
operator: in
values:
- "false"
workspaces: []
- name: sast-unicode-check
params:
- name: image-url
value: $(tasks.build-image-index.results.IMAGE_URL)
- name: SOURCE_ARTIFACT
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
- name: CACHI2_ARTIFACT
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
runAfter:
- build-image-index
taskRef:
params:
- name: name
value: sast-unicode-check-oci-ta
- name: bundle
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.1@sha256:424f2f659c02998dc3a43e1ce869e3148982c59adb74f953f8fa91ff1c9ab86e
- name: kind
value: task
resolver: bundles
when:
- input: $(params.skip-checks)
operator: in
values:
- "false"
workspaces: []
- name: clamav-scan
params:
- name: image-digest
Expand Down
76 changes: 56 additions & 20 deletions .tekton/deployment-validation-operator-bundle-push.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,10 @@ spec:
value: konflux-ci/bundle/bundle.Dockerfile
- name: path-context
value: konflux-ci/bundle
- name: hermetic
value: 'true'
- name: build-source-image
value: 'true'
pipelineSpec:
description: |
This pipeline is ideal for building container images from a Containerfile while maintaining trust after pipeline customization.
Expand Down Expand Up @@ -332,26 +336,6 @@ spec:
operator: in
values:
- "false"
- name: ecosystem-cert-preflight-checks
params:
- name: image-url
value: $(tasks.build-image-index.results.IMAGE_URL)
runAfter:
- build-image-index
taskRef:
params:
- name: name
value: ecosystem-cert-preflight-checks
- name: bundle
value: quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:00b13d06d17328e105b11619ee4db98b215ca6ac02314a4776aa5fc2a974f9c1
- name: kind
value: task
resolver: bundles
when:
- input: $(params.skip-checks)
operator: in
values:
- "false"
- name: sast-snyk-check
params:
- name: image-digest
Expand All @@ -378,6 +362,58 @@ spec:
operator: in
values:
- "false"
- name: sast-shell-check
params:
- name: image-digest
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
- name: image-url
value: $(tasks.build-image-index.results.IMAGE_URL)
- name: SOURCE_ARTIFACT
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
- name: CACHI2_ARTIFACT
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
runAfter:
- build-image-index
taskRef:
params:
- name: name
value: sast-shell-check-oci-ta
- name: bundle
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:a591675c72f06fb9c5b1a3d60e6e4c58e4df5f7da180c7a4691a692a6e7e6496
- name: kind
value: task
resolver: bundles
when:
- input: $(params.skip-checks)
operator: in
values:
- "false"
workspaces: []
- name: sast-unicode-check
params:
- name: image-url
value: $(tasks.build-image-index.results.IMAGE_URL)
- name: SOURCE_ARTIFACT
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
- name: CACHI2_ARTIFACT
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
runAfter:
- build-image-index
taskRef:
params:
- name: name
value: sast-unicode-check-oci-ta
- name: bundle
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.1@sha256:424f2f659c02998dc3a43e1ce869e3148982c59adb74f953f8fa91ff1c9ab86e
- name: kind
value: task
resolver: bundles
when:
- input: $(params.skip-checks)
operator: in
values:
- "false"
workspaces: []
- name: clamav-scan
params:
- name: image-digest
Expand Down
Loading