@@ -113,6 +113,10 @@ spec:
113113 default : ' true'
114114 description : Use the package registry proxy when prefetching dependencies
115115 type : string
116+ - name : sast-target-dirs
117+ type : string
118+ default : .
119+ description : Target directories to scan with SAST tools. Multiple values should be separated with commas.
116120 results :
117121 - description : " "
118122 name : IMAGE_URL
@@ -136,7 +140,7 @@ spec:
136140 - name : name
137141 value : init
138142 - name : bundle
139- value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:b797dd453ddad669365de6de4649e3a9e37e77aa26eb9862ca079a36cbfe64a4
143+ value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:5a423246792ac501ea279229b42ee57da9927da441c04b5c9ff86817b0856b08
140144 - name : kind
141145 value : task
142146 resolver : bundles
@@ -183,7 +187,7 @@ spec:
183187 - name : name
184188 value : prefetch-dependencies-oci-ta
185189 - name : bundle
186- value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:1b209c0d93e52e418f3e6cd4b4fd915a84e4bd7f68e1cfd0d6446133540d7f43
190+ value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:a2efbcdcecfa5293a622eb356a18f5c88e5714046b214fe8730b43b1a7dbb77d
187191 - name : kind
188192 value : task
189193 resolver : bundles
@@ -295,7 +299,7 @@ spec:
295299 - name : name
296300 value : deprecated-image-check
297301 - name : bundle
298- value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:57d1f556982115311f603dd9a728c52a7a1d092f022e1db4560da01eca9e5d17
302+ value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:e78d0d3baf3c8cfc1a5ad278196b74032d9568b143a87c7a79ab780fedfb296e
299303 - name : kind
300304 value : task
301305 resolver : bundles
@@ -317,7 +321,7 @@ spec:
317321 - name : name
318322 value : clair-scan
319323 - name : bundle
320- value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:cd49cdea7e5403a87c4774bd8ea10bc4e6aeb83841ff490cbe42b782779513a7
324+ value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:8fad4c2e2f470f82ee43d6b2ac72327b4d9c6e9cb514a678911c1c9359c29894
321325 - name : kind
322326 value : task
323327 resolver : bundles
@@ -337,7 +341,7 @@ spec:
337341 - name : name
338342 value : ecosystem-cert-preflight-checks
339343 - name : bundle
340- value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:2468c01818fbaad2235e4fca438f28e847260e3e354cf5a441bbd671684af2db
344+ value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:9c300728a03f41beee9a689422d66513d32ab5f804664fe561b11cebacd07799
341345 - name : kind
342346 value : task
343347 resolver : bundles
@@ -356,6 +360,8 @@ spec:
356360 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
357361 - name : CACHI2_ARTIFACT
358362 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
363+ - name : TARGET_DIRS
364+ value : $(params.sast-target-dirs)
359365 runAfter :
360366 - build-image-index
361367 taskRef :
@@ -382,6 +388,8 @@ spec:
382388 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
383389 - name : CACHI2_ARTIFACT
384390 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
391+ - name : TARGET_DIRS
392+ value : $(params.sast-target-dirs)
385393 runAfter :
386394 - build-image-index
387395 taskRef :
@@ -408,6 +416,8 @@ spec:
408416 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
409417 - name : image-digest
410418 value : $(tasks.build-image-index.results.IMAGE_DIGEST)
419+ - name : TARGET_DIRS
420+ value : $(params.sast-target-dirs)
411421 runAfter :
412422 - build-image-index
413423 taskRef :
@@ -475,6 +485,8 @@ spec:
475485 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
476486 - name : CACHI2_ARTIFACT
477487 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
488+ - name : TARGET_DIRS
489+ value : $(params.sast-target-dirs)
478490 runAfter :
479491 - coverity-availability-check
480492 taskRef :
@@ -565,7 +577,7 @@ spec:
565577 - name : name
566578 value : rpms-signature-scan
567579 - name : bundle
568- value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:1d807f6be3be2bd8bff76321e9599bbafce8196dcd9597eeffd9df65466682af
580+ value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:d4e3499ad4af6869470233bef6faaa1bdd69ef56276841eeec93ce6e62deeb93
569581 - name : kind
570582 value : task
571583 resolver : bundles
0 commit comments