@@ -100,6 +100,10 @@ spec:
100100 default : ' true'
101101 description : Use the package registry proxy when prefetching dependencies
102102 type : string
103+ - name : sast-target-dirs
104+ type : string
105+ default : .
106+ description : Target directories to scan with SAST tools. Multiple values should be separated with commas.
103107 results :
104108 - description : " "
105109 name : IMAGE_URL
@@ -123,7 +127,7 @@ spec:
123127 - name : name
124128 value : init
125129 - name : bundle
126- value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:b797dd453ddad669365de6de4649e3a9e37e77aa26eb9862ca079a36cbfe64a4
130+ value : quay.io/konflux-ci/tekton-catalog/task-init:0.4@sha256:5a423246792ac501ea279229b42ee57da9927da441c04b5c9ff86817b0856b08
127131 - name : kind
128132 value : task
129133 resolver : bundles
@@ -170,7 +174,7 @@ spec:
170174 - name : name
171175 value : prefetch-dependencies-oci-ta
172176 - name : bundle
173- value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:1b209c0d93e52e418f3e6cd4b4fd915a84e4bd7f68e1cfd0d6446133540d7f43
177+ value : quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.3@sha256:a2efbcdcecfa5293a622eb356a18f5c88e5714046b214fe8730b43b1a7dbb77d
174178 - name : kind
175179 value : task
176180 resolver : bundles
@@ -288,7 +292,7 @@ spec:
288292 - name : name
289293 value : deprecated-image-check
290294 - name : bundle
291- value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:57d1f556982115311f603dd9a728c52a7a1d092f022e1db4560da01eca9e5d17
295+ value : quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:e78d0d3baf3c8cfc1a5ad278196b74032d9568b143a87c7a79ab780fedfb296e
292296 - name : kind
293297 value : task
294298 resolver : bundles
@@ -310,7 +314,7 @@ spec:
310314 - name : name
311315 value : clair-scan
312316 - name : bundle
313- value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:cd49cdea7e5403a87c4774bd8ea10bc4e6aeb83841ff490cbe42b782779513a7
317+ value : quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:8fad4c2e2f470f82ee43d6b2ac72327b4d9c6e9cb514a678911c1c9359c29894
314318 - name : kind
315319 value : task
316320 resolver : bundles
@@ -330,7 +334,7 @@ spec:
330334 - name : name
331335 value : ecosystem-cert-preflight-checks
332336 - name : bundle
333- value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:25dcef1d9270b2e03fe6710a733171f7c7208e341fc627dac3a579088f44af34
337+ value : quay.io/konflux-ci/tekton-catalog/task-ecosystem-cert-preflight-checks:0.2@sha256:e2bcf1174a6dae9969b8f12e94babe2a5881bc77a509f10823b6a9eac6392850
334338 - name : kind
335339 value : task
336340 resolver : bundles
@@ -349,6 +353,8 @@ spec:
349353 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
350354 - name : CACHI2_ARTIFACT
351355 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
356+ - name : TARGET_DIRS
357+ value : $(params.sast-target-dirs)
352358 runAfter :
353359 - build-image-index
354360 taskRef :
@@ -416,6 +422,8 @@ spec:
416422 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
417423 - name : CACHI2_ARTIFACT
418424 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
425+ - name : TARGET_DIRS
426+ value : $(params.sast-target-dirs)
419427 runAfter :
420428 - coverity-availability-check
421429 taskRef :
@@ -463,6 +471,8 @@ spec:
463471 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
464472 - name : CACHI2_ARTIFACT
465473 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
474+ - name : TARGET_DIRS
475+ value : $(params.sast-target-dirs)
466476 runAfter :
467477 - build-image-index
468478 taskRef :
@@ -489,6 +499,8 @@ spec:
489499 value : $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
490500 - name : CACHI2_ARTIFACT
491501 value : $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
502+ - name : TARGET_DIRS
503+ value : $(params.sast-target-dirs)
492504 runAfter :
493505 - build-image-index
494506 taskRef :
@@ -566,7 +578,7 @@ spec:
566578 - name : name
567579 value : rpms-signature-scan
568580 - name : bundle
569- value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:1d807f6be3be2bd8bff76321e9599bbafce8196dcd9597eeffd9df65466682af
581+ value : quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:cfdb76c67f27bc498132431f5a24fbc17dac1981d6f6e3da5cf5964ac5abdd20
570582 - name : kind
571583 value : task
572584 resolver : bundles
0 commit comments