Skip to content

Commit

Permalink
RHINENG-14115: add new mandatory RPM signature scan task to tekton
Browse files Browse the repository at this point in the history
  • Loading branch information
marleystipich2 authored and vkrizan committed Nov 7, 2024
1 parent 002120b commit 3af6ff0
Show file tree
Hide file tree
Showing 2 changed files with 38 additions and 0 deletions.
19 changes: 19 additions & 0 deletions .tekton/policies-backend-pull-request.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -283,6 +283,25 @@ spec:
operator: in
values:
- "true"
- name: rpms-signature-scan
params:
- name: image-digest
value: $(tasks.build-container.results.IMAGE_DIGEST)
- name: image-url
value: $(tasks.build-container.results.IMAGE_URL)
- name: fail-unsigned
value: true
runAfter:
- build-container
taskRef:
params:
- name: name
value: rpms-signature-scan
- name: bundle
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8
- name: kind
value: task
resolver: bundles
- name: build-source-image
params:
- name: BINARY_IMAGE
Expand Down
19 changes: 19 additions & 0 deletions .tekton/policies-backend-push.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -280,6 +280,25 @@ spec:
operator: in
values:
- "true"
- name: rpms-signature-scan
params:
- name: image-digest
value: $(tasks.build-container.results.IMAGE_DIGEST)
- name: image-url
value: $(tasks.build-container.results.IMAGE_URL)
- name: fail-unsigned
value: true
runAfter:
- build-container
taskRef:
params:
- name: name
value: rpms-signature-scan
- name: bundle
value: quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2@sha256:7aa4d3c95e2b963e82fdda392f7cb3d61e3dab035416cf4a3a34e43cf3c9c9b8
- name: kind
value: task
resolver: bundles
- name: build-source-image
params:
- name: BINARY_IMAGE
Expand Down

0 comments on commit 3af6ff0

Please sign in to comment.