@@ -113,6 +113,10 @@ spec:
113113 default : ' true'
114114 description : Use the package registry proxy when prefetching dependencies
115115 type : string
116+ - name : sast-target-dirs
117+ type : string
118+ default : .
119+ description : Target directories to scan with SAST tools. Multiple values should be separated with commas.
116120 results :
117121 - description : " "
118122 name : IMAGE_URL
@@ -136,7 +140,7 @@ spec:
136140 - name : name
137141 value : init
138142 - name : bundle
139- value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:b797dd453ddad669365de6de4649e3a9e37e77aa26eb9862ca079a36cbfe64a4
143+ value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:5a423246792ac501ea279229b42ee57da9927da441c04b5c9ff86817b0856b08
140144 - name : kind
141145 value : task
142146 resolver : bundles
@@ -157,7 +161,7 @@ spec:
157161 - name : name
158162 value : git-clone-oci-ta
159163 - name : bundle
160- value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:13d49df7dc9ae301627e45f95a236011422996152f1bea46cd60217b0f057407
164+ value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:d30f13dd15daf89dd6dc645243b3444d35570d13f7840c3fd65e366022515205
161165 - name : kind
162166 value : task
163167 resolver : bundles
@@ -183,7 +187,7 @@ spec:
183187 - name : name
184188 value : prefetch-dependencies-oci-ta
185189 - name : bundle
186- value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:1b209c0d93e52e418f3e6cd4b4fd915a84e4bd7f68e1cfd0d6446133540d7f43
190+ value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:3dc78afbf3a441e0280067433cb28ea3d2d0088ec214c73bf063f145b4f273ef
187191 - name : kind
188192 value : task
189193 resolver : bundles
@@ -230,7 +234,7 @@ spec:
230234 - name : name
231235 value : buildah-oci-ta
232236 - name : bundle
233- value : quay.io/konflux-ci/tekton-catalog/task-buildah-oci-ta:0.9@sha256:681d9f65a7f50cb260ee576ccab551e11d63c549f1e1ef3d201da3c112855bd6
237+ value : quay.io/konflux-ci/tekton-catalog/task-buildah-oci-ta:0.9@sha256:75ecb662f343f6f34e553c5b37734d28d9b53ce218c2321a19b96c39bf769357
234238 - name : kind
235239 value : task
236240 resolver : bundles
@@ -252,7 +256,7 @@ spec:
252256 - name : name
253257 value : build-image-index
254258 - name : bundle
255- value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.3@sha256:550afde50349e22ec11191ea0db9a49395ab46fef4e8317d820b6e946677ebeb
259+ value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.3@sha256:b33bfa8dc27dbf459f0779598ba45dcaa490bcc9f8efe1652bcf360ec8cb5582
256260 - name : kind
257261 value : task
258262 resolver : bundles
@@ -273,7 +277,7 @@ spec:
273277 - name : name
274278 value : source-build-oci-ta
275279 - name : bundle
276- value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.3@sha256:0917cfc7772e82cb8e74743c2104f43bcf2596aceafe87eec6fce69a8cac5f06
280+ value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.3@sha256:8567bb7bf8fa9147c96b297533336fa7079ecf972cb86c09ccdd6bddedb25711
277281 - name : kind
278282 value : task
279283 resolver : bundles
@@ -295,7 +299,7 @@ spec:
295299 - name : name
296300 value : deprecated-image-check
297301 - name : bundle
298- value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:57d1f556982115311f603dd9a728c52a7a1d092f022e1db4560da01eca9e5d17
302+ value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:e78d0d3baf3c8cfc1a5ad278196b74032d9568b143a87c7a79ab780fedfb296e
299303 - name : kind
300304 value : task
301305 resolver : bundles
@@ -317,7 +321,7 @@ spec:
317321 - name : name
318322 value : clair-scan
319323 - name : bundle
320- value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:cd49cdea7e5403a87c4774bd8ea10bc4e6aeb83841ff490cbe42b782779513a7
324+ value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:8fad4c2e2f470f82ee43d6b2ac72327b4d9c6e9cb514a678911c1c9359c29894
321325 - name : kind
322326 value : task
323327 resolver : bundles
@@ -337,7 +341,7 @@ spec:
337341 - name : name
338342 value : ecosystem-cert-preflight-checks
339343 - name : bundle
340- value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:2468c01818fbaad2235e4fca438f28e847260e3e354cf5a441bbd671684af2db
344+ value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:88f4fd6d7812a3c46f120f3035974f5fb8cb06b5e3e927badf6e8370f1516a88
341345 - name : kind
342346 value : task
343347 resolver : bundles
@@ -356,14 +360,16 @@ spec:
356360 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
357361 - name : CACHI2_ARTIFACT
358362 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
363+ - name : TARGET_DIRS
364+ value : $(params.sast-target-dirs)
359365 runAfter :
360366 - build-image-index
361367 taskRef :
362368 params :
363369 - name : name
364370 value : sast-snyk-check-oci-ta
365371 - name : bundle
366- value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4@sha256:8f3ecbeaff579e41b8278f82d7fabac27845db17a8e687ea6c510c0c9aceabbb
372+ value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4@sha256:0ebf28a0abd5a167438d4628938a74ade6f00a44a4b7ed1cfa9cfc57a5b24748
367373 - name : kind
368374 value : task
369375 resolver : bundles
@@ -382,14 +388,16 @@ spec:
382388 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
383389 - name : CACHI2_ARTIFACT
384390 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
391+ - name : TARGET_DIRS
392+ value : $(params.sast-target-dirs)
385393 runAfter :
386394 - build-image-index
387395 taskRef :
388396 params :
389397 - name : name
390398 value : sast-shell-check-oci-ta
391399 - name : bundle
392- value : quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:c4ef47e3b4e0508572d266fb745be7e374c29dc02580328cbe9f4d472a8aca57
400+ value : quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:3cbb3535af6e7d4396858179a6427caaffb2e68775594795692fc01f28ae313f
393401 - name : kind
394402 value : task
395403 resolver : bundles
@@ -408,14 +416,16 @@ spec:
408416 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
409417 - name : image-digest
410418 value : $(tasks.build-image-index.results.IMAGE_DIGEST)
419+ - name : TARGET_DIRS
420+ value : $(params.sast-target-dirs)
411421 runAfter :
412422 - build-image-index
413423 taskRef :
414424 params :
415425 - name : name
416426 value : sast-unicode-check-oci-ta
417427 - name : bundle
418- value : quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.4@sha256:90efa582de7770d55102b74014a765cd16a25a56f2cf644b56a788c70c4dc749
428+ value : quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.4@sha256:223812001607b07f0e07d56bef7b7d619144e660c0c57f21ddd44ce0c8c4785b
419429 - name : kind
420430 value : task
421431 resolver : bundles
@@ -475,6 +485,8 @@ spec:
475485 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
476486 - name : CACHI2_ARTIFACT
477487 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
488+ - name : TARGET_DIRS
489+ value : $(params.sast-target-dirs)
478490 runAfter :
479491 - coverity-availability-check
480492 taskRef :
@@ -565,7 +577,7 @@ spec:
565577 - name : name
566578 value : rpms-signature-scan
567579 - name : bundle
568- value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:1d807f6be3be2bd8bff76321e9599bbafce8196dcd9597eeffd9df65466682af
580+ value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:237c54b069d16c3785d1302f19be309aa6c0ae2313d446e30cb74671e07ca676
569581 - name : kind
570582 value : task
571583 resolver : bundles
0 commit comments