@@ -134,6 +134,10 @@ spec:
134134 default : ' true'
135135 description : Use the package registry proxy when prefetching dependencies
136136 type : string
137+ - name : sast-target-dirs
138+ type : string
139+ default : .
140+ description : Target directories to scan with SAST tools. Multiple values should be separated with commas.
137141 results :
138142 - description : " "
139143 name : IMAGE_URL
@@ -157,7 +161,7 @@ spec:
157161 - name : name
158162 value : init
159163 - name : bundle
160- value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:b797dd453ddad669365de6de4649e3a9e37e77aa26eb9862ca079a36cbfe64a4
164+ value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:5a423246792ac501ea279229b42ee57da9927da441c04b5c9ff86817b0856b08
161165 - name : kind
162166 value : task
163167 resolver : bundles
@@ -204,7 +208,7 @@ spec:
204208 - name : name
205209 value : prefetch-dependencies-oci-ta
206210 - name : bundle
207- value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:1b209c0d93e52e418f3e6cd4b4fd915a84e4bd7f68e1cfd0d6446133540d7f43
211+ value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:a2efbcdcecfa5293a622eb356a18f5c88e5714046b214fe8730b43b1a7dbb77d
208212 - name : kind
209213 value : task
210214 resolver : bundles
@@ -318,7 +322,7 @@ spec:
318322 - name : name
319323 value : deprecated-image-check
320324 - name : bundle
321- value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:57d1f556982115311f603dd9a728c52a7a1d092f022e1db4560da01eca9e5d17
325+ value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:e78d0d3baf3c8cfc1a5ad278196b74032d9568b143a87c7a79ab780fedfb296e
322326 - name : kind
323327 value : task
324328 resolver : bundles
@@ -340,7 +344,7 @@ spec:
340344 - name : name
341345 value : clair-scan
342346 - name : bundle
343- value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:cd49cdea7e5403a87c4774bd8ea10bc4e6aeb83841ff490cbe42b782779513a7
347+ value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:8fad4c2e2f470f82ee43d6b2ac72327b4d9c6e9cb514a678911c1c9359c29894
344348 - name : kind
345349 value : task
346350 resolver : bundles
@@ -360,7 +364,7 @@ spec:
360364 - name : name
361365 value : ecosystem-cert-preflight-checks
362366 - name : bundle
363- value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:25dcef1d9270b2e03fe6710a733171f7c7208e341fc627dac3a579088f44af34
367+ value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:e2bcf1174a6dae9969b8f12e94babe2a5881bc77a509f10823b6a9eac6392850
364368 - name : kind
365369 value : task
366370 resolver : bundles
@@ -379,6 +383,8 @@ spec:
379383 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
380384 - name : CACHI2_ARTIFACT
381385 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
386+ - name : TARGET_DIRS
387+ value : $(params.sast-target-dirs)
382388 runAfter :
383389 - build-image-index
384390 taskRef :
@@ -446,6 +452,8 @@ spec:
446452 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
447453 - name : CACHI2_ARTIFACT
448454 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
455+ - name : TARGET_DIRS
456+ value : $(params.sast-target-dirs)
449457 runAfter :
450458 - coverity-availability-check
451459 taskRef :
@@ -493,6 +501,8 @@ spec:
493501 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
494502 - name : CACHI2_ARTIFACT
495503 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
504+ - name : TARGET_DIRS
505+ value : $(params.sast-target-dirs)
496506 runAfter :
497507 - build-image-index
498508 taskRef :
@@ -519,6 +529,8 @@ spec:
519529 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
520530 - name : CACHI2_ARTIFACT
521531 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
532+ - name : TARGET_DIRS
533+ value : $(params.sast-target-dirs)
522534 runAfter :
523535 - build-image-index
524536 taskRef :
@@ -588,7 +600,7 @@ spec:
588600 - name : name
589601 value : rpms-signature-scan
590602 - name : bundle
591- value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:1d807f6be3be2bd8bff76321e9599bbafce8196dcd9597eeffd9df65466682af
603+ value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:cfdb76c67f27bc498132431f5a24fbc17dac1981d6f6e3da5cf5964ac5abdd20
592604 - name : kind
593605 value : task
594606 resolver : bundles
0 commit comments