-
Task
-
Resolution: Unresolved
-
Undefined
-
None
-
None
-
3
-
False
-
-
False
-
RHIDP-4048 - Konflux build pipelines 1.4
-
-
OOTB Konflux expects us to use Snyk:
[validate] ✕ [Violation] test.no_skipped_tests [validate] ImageRef: quay.io/redhat-user-workloads/rhdh-tenant/rhdh/rhdh-hub@sha256:8c337498831e933003cc9f06c29a7ee20cf212b6e8f915dfb77a9f1370ac0d26 [validate] Reason: The Task "sast-snyk-check-oci-ta" from the build Pipeline reports a test was skipped [validate] Title: No tests were skipped [validate] Description: Produce a violation if any tests have their result set to "SKIPPED". A skipped result means a pre-requirement for [validate] executing the test was not met, e.g. a license key for executing a scanner was not provided. The result type is configurable by [validate] the "skipped_tests_results" key in the rule data. To exclude this rule add "test.no_skipped_tests:sast-snyk-check-oci-ta" to the [validate] `exclude` section of the policy configuration. [validate] Solution: There is a test that was skipped. Make sure that each task with a result named 'TEST_OUTPUT' was not skipped. You can [validate] find which test was skipped by examining the 'result' key in the 'TEST_OUTPUT'. More information about the test should be [validate] available in the logs for the build Pipeline.
Since the instructions for enabling this and getting a secret involve someone first granting me access to the RH org within Snyk ... I'm opening a JIRA for this so we can temporarily skip this step.
See: