@@ -121,6 +121,10 @@ spec:
121121 default : ' true'
122122 description : Use the package registry proxy when prefetching dependencies
123123 type : string
124+ - name : sast-target-dirs
125+ type : string
126+ default : .
127+ description : Target directories to scan with SAST tools. Multiple values should be separated with commas.
124128 results :
125129 - description : " "
126130 name : IMAGE_URL
@@ -144,7 +148,7 @@ spec:
144148 - name : name
145149 value : init
146150 - name : bundle
147- value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:b797dd453ddad669365de6de4649e3a9e37e77aa26eb9862ca079a36cbfe64a4
151+ value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:5a423246792ac501ea279229b42ee57da9927da441c04b5c9ff86817b0856b08
148152 - name : kind
149153 value : task
150154 resolver : bundles
@@ -165,7 +169,7 @@ spec:
165169 - name : name
166170 value : git-clone-oci-ta
167171 - name : bundle
168- value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:13d49df7dc9ae301627e45f95a236011422996152f1bea46cd60217b0f057407
172+ value : quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.1@sha256:d30f13dd15daf89dd6dc645243b3444d35570d13f7840c3fd65e366022515205
169173 - name : kind
170174 value : task
171175 resolver : bundles
@@ -193,7 +197,7 @@ spec:
193197 - name : name
194198 value : prefetch-dependencies-oci-ta
195199 - name : bundle
196- value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:1b209c0d93e52e418f3e6cd4b4fd915a84e4bd7f68e1cfd0d6446133540d7f43
200+ value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:3dc78afbf3a441e0280067433cb28ea3d2d0088ec214c73bf063f145b4f273ef
197201 - name : kind
198202 value : task
199203 resolver : bundles
@@ -242,7 +246,7 @@ spec:
242246 - name : name
243247 value : buildah-oci-ta
244248 - name : bundle
245- value : quay.io/konflux-ci/tekton-catalog/task-buildah-oci-ta:0.9@sha256:681d9f65a7f50cb260ee576ccab551e11d63c549f1e1ef3d201da3c112855bd6
249+ value : quay.io/konflux-ci/tekton-catalog/task-buildah-oci-ta:0.9@sha256:75ecb662f343f6f34e553c5b37734d28d9b53ce218c2321a19b96c39bf769357
246250 - name : kind
247251 value : task
248252 resolver : bundles
@@ -264,7 +268,7 @@ spec:
264268 - name : name
265269 value : build-image-index
266270 - name : bundle
267- value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.3@sha256:550afde50349e22ec11191ea0db9a49395ab46fef4e8317d820b6e946677ebeb
271+ value : quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.3@sha256:b33bfa8dc27dbf459f0779598ba45dcaa490bcc9f8efe1652bcf360ec8cb5582
268272 - name : kind
269273 value : task
270274 resolver : bundles
@@ -285,7 +289,7 @@ spec:
285289 - name : name
286290 value : source-build-oci-ta
287291 - name : bundle
288- value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.3@sha256:0917cfc7772e82cb8e74743c2104f43bcf2596aceafe87eec6fce69a8cac5f06
292+ value : quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.3@sha256:8567bb7bf8fa9147c96b297533336fa7079ecf972cb86c09ccdd6bddedb25711
289293 - name : kind
290294 value : task
291295 resolver : bundles
@@ -307,7 +311,7 @@ spec:
307311 - name : name
308312 value : deprecated-image-check
309313 - name : bundle
310- value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:57d1f556982115311f603dd9a728c52a7a1d092f022e1db4560da01eca9e5d17
314+ value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:e78d0d3baf3c8cfc1a5ad278196b74032d9568b143a87c7a79ab780fedfb296e
311315 - name : kind
312316 value : task
313317 resolver : bundles
@@ -329,7 +333,7 @@ spec:
329333 - name : name
330334 value : clair-scan
331335 - name : bundle
332- value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:cd49cdea7e5403a87c4774bd8ea10bc4e6aeb83841ff490cbe42b782779513a7
336+ value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:8fad4c2e2f470f82ee43d6b2ac72327b4d9c6e9cb514a678911c1c9359c29894
333337 - name : kind
334338 value : task
335339 resolver : bundles
@@ -349,7 +353,7 @@ spec:
349353 - name : name
350354 value : ecosystem-cert-preflight-checks
351355 - name : bundle
352- value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:25dcef1d9270b2e03fe6710a733171f7c7208e341fc627dac3a579088f44af34
356+ value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:88f4fd6d7812a3c46f120f3035974f5fb8cb06b5e3e927badf6e8370f1516a88
353357 - name : kind
354358 value : task
355359 resolver : bundles
@@ -370,14 +374,16 @@ spec:
370374 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
371375 - name : ARGS
372376 value : " --project-name=openshift/file-integrity-operator --report --org=86a5b6bf-8aad-4842-ab41-e5c7358c202e"
377+ - name : TARGET_DIRS
378+ value : $(params.sast-target-dirs)
373379 runAfter :
374380 - build-image-index
375381 taskRef :
376382 params :
377383 - name : name
378384 value : sast-snyk-check-oci-ta
379385 - name : bundle
380- value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4@sha256:8f3ecbeaff579e41b8278f82d7fabac27845db17a8e687ea6c510c0c9aceabbb
386+ value : quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.4@sha256:0ebf28a0abd5a167438d4628938a74ade6f00a44a4b7ed1cfa9cfc57a5b24748
381387 - name : kind
382388 value : task
383389 resolver : bundles
@@ -437,6 +443,8 @@ spec:
437443 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
438444 - name : CACHI2_ARTIFACT
439445 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
446+ - name : TARGET_DIRS
447+ value : $(params.sast-target-dirs)
440448 runAfter :
441449 - coverity-availability-check
442450 taskRef :
@@ -484,14 +492,16 @@ spec:
484492 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
485493 - name : CACHI2_ARTIFACT
486494 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
495+ - name : TARGET_DIRS
496+ value : $(params.sast-target-dirs)
487497 runAfter :
488498 - build-image-index
489499 taskRef :
490500 params :
491501 - name : name
492502 value : sast-shell-check-oci-ta
493503 - name : bundle
494- value : quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:c4ef47e3b4e0508572d266fb745be7e374c29dc02580328cbe9f4d472a8aca57
504+ value : quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:3cbb3535af6e7d4396858179a6427caaffb2e68775594795692fc01f28ae313f
495505 - name : kind
496506 value : task
497507 resolver : bundles
@@ -510,14 +520,16 @@ spec:
510520 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
511521 - name : CACHI2_ARTIFACT
512522 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
523+ - name : TARGET_DIRS
524+ value : $(params.sast-target-dirs)
513525 runAfter :
514526 - build-image-index
515527 taskRef :
516528 params :
517529 - name : name
518530 value : sast-unicode-check-oci-ta
519531 - name : bundle
520- value : quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.4@sha256:90efa582de7770d55102b74014a765cd16a25a56f2cf644b56a788c70c4dc749
532+ value : quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.4@sha256:223812001607b07f0e07d56bef7b7d619144e660c0c57f21ddd44ce0c8c4785b
521533 - name : kind
522534 value : task
523535 resolver : bundles
@@ -579,7 +591,7 @@ spec:
579591 - name : name
580592 value : rpms-signature-scan
581593 - name : bundle
582- value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:1d807f6be3be2bd8bff76321e9599bbafce8196dcd9597eeffd9df65466682af
594+ value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:237c54b069d16c3785d1302f19be309aa6c0ae2313d446e30cb74671e07ca676
583595 - name : kind
584596 value : task
585597 resolver : bundles
0 commit comments