Uploaded image for project: 'Red Hat Internal Developer Platform'
  1. Red Hat Internal Developer Platform
  2. RHIDP-3843

enable snyk in internal RH Konflux for RHDH

Prepare for Y ReleasePrepare for Z ReleaseRemove QuarterXMLWordPrintable

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • 1.4
    • None
    • Build, Dynamic plugins
    • None

      OOTB Konflux expects us to use Snyk:

      [validate] ✕ [Violation] test.no_skipped_tests
      [validate]   ImageRef: quay.io/redhat-user-workloads/rhdh-tenant/rhdh/rhdh-hub@sha256:8c337498831e933003cc9f06c29a7ee20cf212b6e8f915dfb77a9f1370ac0d26
      [validate]   Reason: The Task "sast-snyk-check-oci-ta" from the build Pipeline reports a test was skipped
      [validate]   Title: No tests were skipped
      [validate]   Description: Produce a violation if any tests have their result set to "SKIPPED". A skipped result means a pre-requirement for
      [validate]   executing the test was not met, e.g. a license key for executing a scanner was not provided. The result type is configurable by
      [validate]   the "skipped_tests_results" key in the rule data. To exclude this rule add "test.no_skipped_tests:sast-snyk-check-oci-ta" to the
      [validate]   `exclude` section of the policy configuration.
      [validate]   Solution: There is a test that was skipped. Make sure that each task with a result named 'TEST_OUTPUT' was not skipped. You can
      [validate]   find which test was skipped by examining the 'result' key in the 'TEST_OUTPUT'. More information about the test should be
      [validate]   available in the logs for the build Pipeline.
      

      Since the instructions for enabling this and getting a secret involve someone first granting me access to the RH org within Snyk ... I'm opening a JIRA for this so we can temporarily skip this step.

      See:

              nickboldt Nick Boldt
              nickboldt Nick Boldt
              RHIDP - Core Platform
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated: