Skip to content

Commit edf5324

Browse files
feat(konflux): add new mandatory RPM signature scan task to tekton (#1217)
1 parent f275140 commit edf5324

2 files changed

Lines changed: 38 additions & 0 deletions

File tree

.tekton/patchman-ui-pull-request.yaml

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -413,6 +413,25 @@ spec:
413413
operator: in
414414
values:
415415
- "true"
416+
- name: rpms-signature-scan
417+
params:
418+
- name: image-digest
419+
value: $(tasks.build-container.results.IMAGE_DIGEST)
420+
- name: image-url
421+
value: $(tasks.build-container.results.IMAGE_URL)
422+
- name: fail-unsigned
423+
value: true
424+
runAfter:
425+
- build-container
426+
taskRef:
427+
params:
428+
- name: name
429+
value: rpms-signature-scan
430+
- name: bundle
431+
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8
432+
- name: kind
433+
value: task
434+
resolver: bundles
416435
- name: build-source-image
417436
params:
418437
- name: BINARY_IMAGE

.tekton/patchman-ui-push.yaml

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -410,6 +410,25 @@ spec:
410410
operator: in
411411
values:
412412
- "true"
413+
- name: rpms-signature-scan
414+
params:
415+
- name: image-digest
416+
value: $(tasks.build-container.results.IMAGE_DIGEST)
417+
- name: image-url
418+
value: $(tasks.build-container.results.IMAGE_URL)
419+
- name: fail-unsigned
420+
value: true
421+
runAfter:
422+
- build-container
423+
taskRef:
424+
params:
425+
- name: name
426+
value: rpms-signature-scan
427+
- name: bundle
428+
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8
429+
- name: kind
430+
value: task
431+
resolver: bundles
413432
- name: build-source-image
414433
params:
415434
- name: BINARY_IMAGE

0 commit comments

Comments
 (0)