Skip to content

Instantly share code, notes, and snippets.

@dhellmann
Created September 10, 2026 21:36
Show Gist options
  • Select an option

  • Save dhellmann/1e37b7af3cf4d50c623bee1061e7ea7e to your computer and use it in GitHub Desktop.

Select an option

Save dhellmann/1e37b7af3cf4d50c623bee1061e7ea7e to your computer and use it in GitHub Desktop.
{"_type":"https://in-toto.io/Statement/v0.1","subject":[{"name":"quay.io/rhoai/odh-kserve-agent-rhel9","digest":{"sha256":"740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b"}},{"name":"quay.io/rhoai/odh-kserve-agent-rhel9","digest":{"sha256":"6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75"}},{"name":"quay.io/rhoai/odh-kserve-agent-rhel9","digest":{"sha256":"7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f"}},{"name":"quay.io/rhoai/odh-kserve-agent-rhel9","digest":{"sha256":"cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35"}},{"name":"quay.io/rhoai/odh-kserve-agent-rhel9","digest":{"sha256":"c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532"}},{"name":"quay.io/rhoai/odh-kserve-agent-rhel9","digest":{"sha256":"3ffa8b0b17d1b3849c2beb64d31469bd872c42a05e78385f834b753b71a8eb9e"}}],"predicateType":"https://slsa.dev/provenance/v0.2","predicate":{"buildConfig":{"tasks":[{"finishedOn":"2026-09-08T21:21:16Z","invocation":{"configSource":{"digest":{"sha1":"c6e2c970f62d8ed9cc3960aa1ad3f6d72dadd68b"},"entryPoint":"konflux-tekton-tasks/rhoai-init/0.1/rhoai-init.yaml","uri":"git+https://github.com/red-hat-data-services/rhoai-konflux-tasks.git"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/761d776f-7312-419c-ae4c-7a37b7f1a316","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-adf7ef40e18f1aa2-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"rhoai-init","tekton.dev/task":"rhoai-init"}},"parameters":{"build-type":"","expected-cluster":"","image-output":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","rhoai-version":"2.25.11"}},"name":"rhoai-init","ref":{"params":[{"name":"url","value":"https://github.com/red-hat-data-services/rhoai-konflux-tasks.git"},{"name":"revision","value":"c6e2c970f62d8ed9cc3960aa1ad3f6d72dadd68b"},{"name":"pathInRepo","value":"konflux-tekton-tasks/rhoai-init/0.1/rhoai-init.yaml"}],"resolver":"git"},"results":[{"name":"cpe-id","type":"string","value":""},{"name":"display-name","type":"string","value":"ODH Kserve Agent"},{"name":"image-name","type":"string","value":"odh-kserve-agent-rhel9"},{"name":"image-name-without-rhel-suffix","type":"string","value":"odh-kserve-agent"},{"name":"image-namespace","type":"string","value":"rhoai"},{"name":"image-registry","type":"string","value":"quay.io"},{"name":"image-tag","type":"string","value":"rhoai-2.25"},{"name":"konflux-component-name","type":"string","value":"odh-kserve-agent-v2-25"},{"name":"skip-slack-message","type":"string","value":"true"},{"name":"slack-message-failure-text","type":"string","value":":alert: <https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp|odh-kserve-agent-v2-25-on-push-xwfsp> - 2026-09-08T21:21:16\nStatus: Failed :failed: (cluster: stone-prod-p02)\nCC - <!subteam^S0ABFF86BNE|openshift-ai-devops-build-guardian>"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:21:11Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"echo \"----- DEBUG INFORMATION -----\"\necho \"Build URL: $BUILD_URL\"\necho \"SHA URL: $SHA_URL\"\necho \"Target Branch: $target_branch\"\necho \"Summary Annotations: $SUMMARY_ANNOTATIONS\"\necho \"Build Type: $BUILD_TYPE\"\necho \"RHOAI Version: $RHOAI_VERSION\"\necho \"Image Output: $IMAGE_OUTPUT\"\necho \"Expected Cluster: $EXPECTED_CLUSTER\"\necho \"Konflux Component Name: $KONFLUX_COMPONENT_NAME\"\n\n# Check if this is a pull request pipeline\nis_pull_request=false\nif [[ \"$SUMMARY_ANNOTATIONS\" =~ '\"eventType\":\"pull_request\"' || \"$SUMMARY_ANNOTATIONS\" =~ '\"eventType\":\"pull_request_labeled\"' || \"$SUMMARY_ANNOTATIONS\" =~ \"pull_request-id\" ]]; then\n is_pull_request=true\n echo \"Pull request pipeline detected\"\nfi\n\n# Fail if required parameters are not provided\n# rhoai-version is optional for PR pipelines\nif [[ -z \"$RHOAI_VERSION\" && \"$is_pull_request\" == \"false\" ]]; then\n echo \"ERROR: RHOAI version is required but was not provided\"\n exit 1\nfi\n\nif [[ -z \"$IMAGE_OUTPUT\" ]]; then\n echo \"ERROR: Image output is required but was not provided\"\n exit 1\nfi\n\npipelinerun_name=$(echo $BUILD_URL | sed 's|http.*/||')\necho \"Pipelinerun Name: $pipelinerun_name\"\n\n# Function to compare semantic versions\n# returns true (0) if $1 >= $2\nsemver_ge() {\n # Strip pre-release suffix (e.g., \"3.4.0-ea.1\" becomes \"3.4.0\")\n local v1=\"${1%%-*}\"\n local v2=\"${2%%-*}\"\n\n # We append \".0.0\" to ensure at least three components (x.y.z) exist.\n # This normalizes both versions ($1 and $2) to x.y.z format for comparison.\n # We read four variables (x1, y1, z1, extra) to ensure x1, y1 and z1 only captures the x, y and z,\n # and the dummy variable (extra) captures the extra trailing \".0\" parts.\n IFS='.' read -r x1 y1 z1 extra <<< \"${v1}.0.0\"\n IFS='.' read -r x2 y2 z2 extra <<< \"${v2}.0.0\"\n\n echo \"Comparing versions: $1 (normalized to x1=$x1, y1=$y1, z1=$z1) and $2 (normalized to x2=$x2, y2=$y2, z2=$z2)\"\n\n if (( x1 > x2 )); then return 0; fi\n if (( x1 < x2 )); then return 1; fi\n\n if (( y1 > y2 )); then return 0; fi\n if (( y1 < y2 )); then return 1; fi\n\n if (( z1 >= z2 )); then return 0; fi\n\n return 1\n}\n\n# No need to set CPE ID for pull request builds\nif [[ \"$is_pull_request\" == \"false\" ]]; then\n\n # All RHOAI versions 2.20 and above use RHEL 9\n # Determine rhel_version based on semantic comparison with 2.20\n if semver_ge \"$RHOAI_VERSION\" \"2.20\"; then\n rhel_version=9\n else\n rhel_version=8\n fi\n\n # Parse RHOAI version into x, y, z components for CPE ID\n # Strip pre-release suffix first (e.g., \"3.4.0-ea.1\" becomes \"3.4.0\")\n clean_version=\"${RHOAI_VERSION%%-*}\"\n IFS='.' read -r x y z extra <<< \"${clean_version}.0.0\"\n\n # Form the CPE identifier\n cpe_id=\"cpe:/a:redhat:openshift_ai:${x}.${y}::el${rhel_version}\"\nelse\n cpe_id=\"\"\nfi\n\necho \"CPE ID: $cpe_id\"\necho -n \"${cpe_id}\" > \"/tekton/results/cpe-id\"\n\n# Extract image registry, namespace, name and tag from the image-output parameter\n# Supports both 2-level and 3-level paths:\n# quay.io/rhoai/image-name:tag -> registry=quay.io, namespace=rhoai, name=image-name\n# quay.io/redhat-user-workloads/rhoai-tenant/image-name:tag -> registry=quay.io, namespace=redhat-user-workloads/rhoai-tenant, name=image-name\necho \"----- PARSING IMAGE OUTPUT -----\"\n\n# Extract registry (first part before the first /)\nimage_registry=$(echo \"$IMAGE_OUTPUT\" | cut -d'/' -f1)\n\n# Remove registry to get the rest (namespace/path/image:tag)\nimage_path_with_tag=\"${IMAGE_OUTPUT#*/}\"\n\n# Split off the tag first (everything after the last :)\nif [[ \"$image_path_with_tag\" == *\":\"* ]]; then\n image_path=$(echo \"$image_path_with_tag\" | rev | cut -d':' -f2- | rev)\n image_tag=$(echo \"$image_path_with_tag\" | rev | cut -d':' -f1 | rev)\nelse\n image_path=\"$image_path_with_tag\"\n image_tag=\"\"\nfi\n\n# Extract image name (last component of the path)\nimage_name=$(echo \"$image_path\" | rev | cut -d'/' -f1 | rev)\n\n# Extract namespace (everything before the image name)\nimage_namespace=$(echo \"$image_path\" | rev | cut -d'/' -f2- | rev)\n\necho \"Image Registry: $image_registry\"\necho \"Image Namespace: $image_namespace\"\necho \"Image Name: $image_name\"\necho \"Image Tag: $image_tag\"\n\n# Derive additional values from image_name\n# image_name_without_rhel_suffix: Remove -rhel{N} suffix from anywhere in image_name\nimage_name_without_rhel_suffix=$(echo \"$image_name\" | sed 's/-rhel[0-9]*//g')\n\n# display_name: Convert image_name_without_rhel_suffix to human-readable display name\n# Replace hyphens with spaces, capitalize first letter of each word, keep ODH uppercase\ndisplay_name=$(echo \"$image_name_without_rhel_suffix\" | tr '-' ' ' | awk '{for(i=1;i<=NF;i++) $i=toupper(substr($i,1,1)) tolower(substr($i,2)); print}' | sed 's/\\bOdh\\b/ODH/g')\n\necho \"Image Name Without RHEL Suffix: $image_name_without_rhel_suffix\"\necho \"Display Name: $display_name\"\n\necho -n \"${image_registry}\" > \"/tekton/results/image-registry\"\necho -n \"${image_namespace}\" > \"/tekton/results/image-namespace\"\necho -n \"${image_name}\" > \"/tekton/results/image-name\"\necho -n \"${image_tag}\" > \"/tekton/results/image-tag\"\necho -n \"${image_name_without_rhel_suffix}\" > \"/tekton/results/image-name-without-rhel-suffix\"\necho -n \"${KONFLUX_COMPONENT_NAME}\" > \"/tekton/results/konflux-component-name\"\necho -n \"${display_name}\" > \"/tekton/results/display-name\"\n\n# Skip slack message if expected cluster does not match\nCLUSTER=$( echo \"$BUILD_URL\" | grep -oE 'stone-pro?d-[a-z0-9]+')\necho \"Expected Cluster: $EXPECTED_CLUSTER\"\necho \"Actual Cluster: $CLUSTER\"\nif [[ -n \"$EXPECTED_CLUSTER\" && \"$EXPECTED_CLUSTER\" != \"$CLUSTER\" ]]; then\n echo \"Build URL does not match expected cluster $CLUSTER.\"\n echo -n \"true\" > \"/tekton/results/skip-slack-message\"\nelse\n echo -n \"false\" > \"/tekton/results/skip-slack-message\"\nfi\n\nbuild_time=\"$(date +%Y-%m-%dT%H:%M:%S)\"\n\nslack_message=${slack_message/__BUILD__URL__/$BUILD_URL}\nslack_message=${slack_message/__PIPELINERUN__NAME__/$pipelinerun_name}\nslack_message=${slack_message/__BUILD__TIME__/$build_time}\n\n# Don't send a slack message for pull request pipelines\nif [[ \"$is_pull_request\" == \"true\" ]]; then\n echo \"pull request pipeline detected, skipping slack message\"\n echo -n \"true\" > \"/tekton/results/skip-slack-message\"\nfi\n\n# Tag @rhoai-releng for stage FBCF build failures\nif [[ \"$BUILD_TYPE\" == \"stage\" ]]; then\n alertEmoji=\":actual_rotating_light:\"\n slack_message=${slack_message/:alert:/$alertEmoji}\n # The \"!\" in <!subteam^S09SZP9J34M|rhoai-releng> causes Bash history expansion errors\n set +H # disable history expansion\n slack_message=$(echo -e \"${slack_message}\\nCC - <!subteam^S09SZP9J34M|rhoai-releng>\")\n set -H # re-enable history expansion\nfi\n\nif [[ \"$image_namespace\" == \"rhoai-private\" ]]; then\n echo \"Embargoed build target detected. Not sending slack message\"\n # Prod delivery repo is \"rhoai\" for both embargoed and non-embargoed builds\n echo -n \"rhoai\" > \"/tekton/results/image-namespace\"\n echo -n \"true\" > \"/tekton/results/skip-slack-message\"\n exit 0\nfi\n\necho -en \"${slack_message}\" > \"/tekton/results/slack-message-failure-text\"\necho \"Slack Message: ${slack_message}\"\n","environment":{"container":"rhoai-init","image":"oci://registry.access.redhat.com/ubi9/ubi@sha256:25a147defd01e19674714f55d17538c8dbe55d8c305fa157ecc3f9c8977b05b6"}}]},{"after":["rhoai-init"],"finishedOn":"2026-09-08T21:21:21Z","invocation":{"configSource":{"digest":{"sha256":"4be9343579d91c7b501cafe966cff59a601dfeca903c476e3763dd8d7599b900"},"entryPoint":"init","uri":"quay.io/konflux-ci/tekton-catalog/task-init"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/8bd92c5d-9fdc-4098-8218-7d2605697743","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-b156e251d6b8c497-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"init","tekton.dev/task":"init"}},"parameters":{"enable-cache-proxy":"true"}},"name":"init","ref":{"params":[{"name":"name","value":"init"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-init:0.4.3@sha256:4be9343579d91c7b501cafe966cff59a601dfeca903c476e3763dd8d7599b900"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"http-proxy","type":"string","value":"squid.caching.svc.cluster.local:3128"},{"name":"no-proxy","type":"string","value":""}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:21:17Z","status":"Succeeded","steps":[{"annotations":null,"arguments":["--enable","true"],"entryPoint":"konflux-build-cli config cache-proxy","environment":{"container":"init","image":"oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f"}}]},{"after":["init"],"finishedOn":"2026-09-08T21:21:40Z","invocation":{"configSource":{"digest":{"sha256":"2e8fe30b6d5c8a8a3e6bbc0ea5a55e05b6170d4a399830f25ea43e17881ce544"},"entryPoint":"git-clone-oci-ta","uri":"quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/4a7736e0-ad0b-4ade-81e1-5fafc8dc7866","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/categories":"Git","tekton.dev/displayName":"git clone oci trusted artifacts","tekton.dev/pipelines.minVersion":"0.21.0","tekton.dev/platforms":"linux/amd64,linux/s390x,linux/ppc64le,linux/arm64","tekton.dev/tags":"git","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-784110e1636ca9cd-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"clone-repository","tekton.dev/task":"git-clone-oci-ta"}},"parameters":{"caTrustConfigMapKey":"ca-bundle.crt","caTrustConfigMapName":"trusted-ca","depth":"1","enableSymlinkCheck":"true","fetchTags":"false","httpProxy":"","httpsProxy":"","logLevel":"info","mergeSourceDepth":"","mergeSourceRepoUrl":"","mergeTargetBranch":"false","noProxy":"","ociArtifactExpiresAfter":"","ociStorage":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25.git","refspec":"","revision":"58e7f0f6d889933345394152903c95c62e6bd9c3","shortCommitLength":"7","sparseCheckoutDirectories":"","sslVerify":"true","submodulePaths":"","submodules":"true","symlinkCheckIgnorePattern":"","targetBranch":"main","url":"https://github.com/red-hat-data-services/kserve"}},"name":"clone-repository","ref":{"params":[{"name":"name","value":"git-clone-oci-ta"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.2.6@sha256:2e8fe30b6d5c8a8a3e6bbc0ea5a55e05b6170d4a399830f25ea43e17881ce544"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"CHAINS-GIT_COMMIT","type":"string","value":"58e7f0f6d889933345394152903c95c62e6bd9c3"},{"name":"CHAINS-GIT_URL","type":"string","value":"https://github.com/red-hat-data-services/kserve"},{"name":"commit","type":"string","value":"58e7f0f6d889933345394152903c95c62e6bd9c3"},{"name":"commit-timestamp","type":"string","value":"1788902446"},{"name":"short-commit","type":"string","value":"58e7f0f"},{"name":"url","type":"string","value":"https://github.com/red-hat-data-services/kserve"},{"name":"SOURCE_ARTIFACT","type":"string","value":"oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:21:23Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -euo pipefail\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf \"$ca_bundle\" /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\ntest -z \"${PARAM_HTTP_PROXY}\" || export HTTP_PROXY=\"${PARAM_HTTP_PROXY}\"\ntest -z \"${PARAM_HTTPS_PROXY}\" || export HTTPS_PROXY=\"${PARAM_HTTPS_PROXY}\"\ntest -z \"${PARAM_NO_PROXY}\" || export NO_PROXY=\"${PARAM_NO_PROXY}\"\n\nRESULT_FILE=\"$(mktemp)\"\nkonflux-build-cli git-clone >\"${RESULT_FILE}\"\n\nprintf \"%s\" \"$(jq -r '.commit' \"${RESULT_FILE}\")\" >\"/tekton/results/commit\"\nprintf \"%s\" \"$(jq -r '.shortCommit' \"${RESULT_FILE}\")\" >\"/tekton/results/short-commit\"\nprintf \"%s\" \"$(jq -r '.url' \"${RESULT_FILE}\")\" >\"/tekton/results/url\"\nprintf \"%s\" \"$(jq -r '.commitTimestamp' \"${RESULT_FILE}\")\" >\"/tekton/results/commit-timestamp\"\nprintf \"%s\" \"$(jq -r '.\"CHAINS-GIT_URL\"' \"${RESULT_FILE}\")\" >\"/tekton/results/CHAINS-GIT_URL\"\nprintf \"%s\" \"$(jq -r '.\"CHAINS-GIT_COMMIT\"' \"${RESULT_FILE}\")\" >\"/tekton/results/CHAINS-GIT_COMMIT\"\n\nMERGED_SHA=$(jq -r '.mergedSha // empty' \"${RESULT_FILE}\")\nif [ -n \"${MERGED_SHA}\" ]; then\n printf \"%s\" \"${MERGED_SHA}\" >\"/tekton/results/merged_sha\"\nfi\n","environment":{"container":"clone","image":"oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f"}},{"annotations":null,"arguments":["create","--store","quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25.git","/tekton/results/SOURCE_ARTIFACT=/var/workdir/source"],"entryPoint":"","environment":{"container":"create-trusted-artifact","image":"oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c"}}]},{"after":["clone-repository"],"finishedOn":"2026-09-08T21:21:48Z","invocation":{"configSource":{"digest":{"sha256":"374f776bcb2048c3adeaf4dbb460c52d001bc6020320df5e878c2d05391302da"},"entryPoint":"prefetch-dependencies-oci-ta","uri":"quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/648b0bdf-9cf1-4148-bc06-ecdcddf7881a","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"image-build, konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-737a60358dade829-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"prefetch-dependencies","tekton.dev/task":"prefetch-dependencies-oci-ta"}},"parameters":{"ACTIVATION_KEY":"custom-activation-key","SERVICE_CA_TRUST_CONFIG_MAP_KEY":"service-ca.crt","SERVICE_CA_TRUST_CONFIG_MAP_NAME":"openshift-service-ca.crt","SOURCE_ARTIFACT":"oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735","caTrustConfigMapKey":"ca-bundle.crt","caTrustConfigMapName":"trusted-ca","config-file-content":"","enable-package-registry-proxy":"true","input":"","log-level":"info","mode":"strict","ociArtifactExpiresAfter":"","ociStorage":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25.prefetch","pip-index-url":"","sbom-type":"spdx"}},"name":"prefetch-dependencies","ref":{"params":[{"name":"name","value":"prefetch-dependencies-oci-ta"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.10.2@sha256:374f776bcb2048c3adeaf4dbb460c52d001bc6020320df5e878c2d05391302da"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"CACHI2_ARTIFACT","type":"string","value":""},{"name":"SOURCE_ARTIFACT","type":"string","value":"oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:21:41Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"#!/bin/bash\n\necho -n \"${SOURCE_ARTIFACT}\" >\"/tekton/results/SOURCE_ARTIFACT\"\necho -n \"\" >\"/tekton/results/CACHI2_ARTIFACT\"\n","environment":{"container":"skip-ta","image":"oci://quay.io/konflux-ci/task-runner@sha256:4b01fbf98fa7155f5c21443c285f88853864ae7cc66981cf6b543fc6ba16b81b"}},{"annotations":null,"arguments":["use","oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source"],"entryPoint":"","environment":{"container":"use-trusted-artifact","image":"oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c"}},{"annotations":null,"arguments":null,"entryPoint":"#!/bin/bash\n\nif [ -n \"${WORKSPACE_NETRC_PATH}\" ]; then\n export NETRC=\"${WORKSPACE_NETRC_PATH}/.netrc\"\nfi\n\nCA_BUNDLE_PATH=/mnt/trusted-ca/ca-bundle.crt\nSERVICE_CA_BUNDLE_PATH=/mnt/service-ca/ca-bundle.crt\nUPDATE_CA_TRUST=false\n\nif [ -f \"$CA_BUNDLE_PATH\" ]; then\n echo \"Using mounted CA bundle: $CA_BUNDLE_PATH\"\n cp -vf \"$CA_BUNDLE_PATH\" /etc/pki/ca-trust/source/anchors/ca-bundle.crt\n UPDATE_CA_TRUST=true\nfi\n\nif [ -f \"$SERVICE_CA_BUNDLE_PATH\" ]; then\n echo \"Using mounted service CA bundle: $SERVICE_CA_BUNDLE_PATH\"\n cp -vf \"$SERVICE_CA_BUNDLE_PATH\" /etc/pki/ca-trust/source/anchors/service-ca.crt\n UPDATE_CA_TRUST=true\nfi\n\nif [ \"$UPDATE_CA_TRUST\" = \"true\" ]; then\n update-ca-trust\n # requests ignores the system CA store. Set REQUESTS_CA_BUNDLE explicitly.\n export REQUESTS_CA_BUNDLE=/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem\nfi\n\nif [ -e /activation-key/org ] && [ -e /activation-key/activationkey ]; then\n export KBC_PD_RHSM_ORG=/activation-key/org\n export KBC_PD_RHSM_ACTIVATION_KEY=/activation-key/activationkey\nfi\n\nif [ -n \"${CONFIG_FILE_CONTENT}\" ]; then\n echo \"${CONFIG_FILE_CONTENT}\" >/mnt/config/config.yaml\n export KBC_PD_CONFIG_FILE=/mnt/config/config.yaml\nfi\n\nif [ -z \"${PIP_INDEX_URL}\" ]; then\n unset PIP_INDEX_URL\nfi\n\nkonflux-build-cli prefetch-dependencies\n","environment":{"container":"prefetch-dependencies","image":"oci://quay.io/konflux-ci/hermeto@sha256:887e4fabf1707fc4018275b53fe89c0962ccb61d80d695cce49127096792edae"}},{"annotations":null,"arguments":["create","--store","quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25.prefetch","/tekton/results/SOURCE_ARTIFACT=/var/workdir/source","/tekton/results/CACHI2_ARTIFACT=/var/workdir/cachi2"],"entryPoint":"","environment":{"container":"create-trusted-artifact","image":"oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c"}}]},{"after":["prefetch-dependencies","clone-repository","rhoai-init"],"finishedOn":"2026-09-08T21:24:50Z","invocation":{"configSource":{"digest":{"sha256":"ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344"},"entryPoint":"buildah-remote-oci-ta","uri":"quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/80cee560-7c4c-49f4-9ea2-ee43519e59e7","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"image-build, konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-eb4ab01f52fcc444-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","build.appstudio.redhat.com/build_type":"docker","build.appstudio.redhat.com/target-platform":"linux-x86_64","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"build-images","tekton.dev/task":"buildah-remote-oci-ta"}},"parameters":{"ACTIVATION_KEY":"custom-activation-key","ADDITIONAL_BASE_IMAGES":[],"ADDITIONAL_SECRET":"does-not-exist","ADD_CAPABILITIES":"","ALLOW_CROSS_PLATFORM_IMAGES":"false","ANNOTATIONS":[],"ANNOTATIONS_FILE":"","BUILDAH_FORMAT":"docker","BUILD_ARGS":[],"BUILD_ARGS_FILE":"","BUILD_TIMESTAMP":"","CACHI2_ARTIFACT":"","COMMIT_SHA":"58e7f0f6d889933345394152903c95c62e6bd9c3","CONTEXT":".","CONTEXTUALIZE_SBOM":"false","DOCKERFILE":"Dockerfiles/agent.Dockerfile.konflux","ENTITLEMENT_SECRET":"etc-pki-entitlement","ENV_VARS":[],"HERMETIC":"false","HTTP_PROXY":"","ICM_KEEP_COMPAT_LOCATION":"true","IMAGE":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","IMAGE_APPEND_PLATFORM":"true","IMAGE_EXPIRES_AFTER":"","INHERIT_BASE_IMAGE_LABELS":"true","LABELS":["version=v2.25.11","url=https://github.com/red-hat-data-services/kserve","release=1788902446","git.url=https://github.com/red-hat-data-services/kserve","git.commit=58e7f0f6d889933345394152903c95c62e6bd9c3","cpe=","name=rhoai/odh-kserve-agent-rhel9","io.openshift.tags=odh-kserve-agent","com.redhat.component=odh-kserve-agent-rhel9","summary=ODH Kserve Agent","description=ODH Kserve Agent","io.k8s.display-name=ODH Kserve Agent","io.k8s.description=ODH Kserve Agent","vendor=Red Hat, Inc.","maintainer=RHOAI DevTestOps Team [openshift-ai-devtestops@redhat.com]"],"LOG_LEVEL":"info","NO_PROXY":"","OMIT_HISTORY":"false","PLATFORM":"linux/x86_64","PREFETCH_INPUT":"","PRIVILEGED_NESTED":"false","PROXY_CA_TRUST_CONFIG_MAP_KEY":"ca-bundle.crt","PROXY_CA_TRUST_CONFIG_MAP_NAME":"caching-ca-bundle","REWRITE_TIMESTAMP":"false","RHSM_MOUNT_CA_CERTS":"auto","SBOM_SKIP_VALIDATION":"true","SBOM_SOURCE_SCAN_ENABLED":"true","SBOM_SYFT_SELECT_CATALOGERS":"","SBOM_TYPE":"spdx","SKIP_INJECTIONS":"false","SKIP_SBOM_GENERATION":"false","SKIP_UNUSED_STAGES":"true","SOURCE_ARTIFACT":"oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735","SOURCE_DATE_EPOCH":"","SOURCE_URL":"","SQUASH":"false","STORAGE_DRIVER":"overlay","TARGET_STAGE":"","TLSVERIFY":"true","WORKINGDIR_MOUNT":"","YUM_REPOS_D_FETCHED":"fetched.repos.d","YUM_REPOS_D_SRC":"repos.d","YUM_REPOS_D_TARGET":"/etc/yum.repos.d","caTrustConfigMapKey":"ca-bundle.crt","caTrustConfigMapName":"trusted-ca"}},"name":"build-images","ref":{"params":[{"name":"name","value":"buildah-remote-oci-ta"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.12.1@sha256:ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"IMAGE_DIGEST","type":"string","value":"sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b"},{"name":"IMAGE_REF","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-x86-64@sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b"},{"name":"IMAGE_URL","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-x86-64"},{"name":"SBOM_BLOB_URL","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9@sha256:e388c05e79f53dc430eba6a7676e8cbff0b9ce15edcd6986559f04a84fadf8f9"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:21:49Z","status":"Succeeded","steps":[{"annotations":null,"arguments":["use","oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source","=/var/workdir/cachi2"],"entryPoint":"","environment":{"container":"use-trusted-artifact","image":"oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c"}},{"annotations":null,"arguments":["--build-args","--envs","--labels","version=v2.25.11","url=https://github.com/red-hat-data-services/kserve","release=1788902446","git.url=https://github.com/red-hat-data-services/kserve","git.commit=58e7f0f6d889933345394152903c95c62e6bd9c3","cpe=","name=rhoai/odh-kserve-agent-rhel9","io.openshift.tags=odh-kserve-agent","com.redhat.component=odh-kserve-agent-rhel9","summary=ODH Kserve Agent","description=ODH Kserve Agent","io.k8s.display-name=ODH Kserve Agent","io.k8s.description=ODH Kserve Agent","vendor=Red Hat, Inc.","maintainer=RHOAI DevTestOps Team [openshift-ai-devtestops@redhat.com]","--annotations"],"entryPoint":"#!/bin/bash\nset -e\nset -o verbose\n\necho \"[$(date --utc -Ins)] Prepare connection\"\n\nmkdir -p ~/.ssh\nif [ -e \"/ssh/error\" ]; then\n #no server could be provisioned\n cat /ssh/error\n exit 1\nfi\n\nSSH_HOST=$(cat /ssh/host)\nexport SSH_HOST\n\nif [ \"$SSH_HOST\" == \"localhost\" ] ; then\n IS_LOCALHOST=true\n echo \"Localhost detected; running build in cluster\"\nelif [ -e \"/ssh/otp\" ]; then\n if ! curl --fail --cacert /ssh/otp-ca -XPOST -d @/ssh/otp \"$(cat /ssh/otp-server)\" >~/.ssh/id_rsa; then\n echo \"Failed to retrieve SSH key from the OTP server. This can happen when the PipelineRun retry option re-runs a task whose one-time credential was already consumed. Please, start a new build, and if problem persists, please report it as an MPC bug.\" >&2\n exit 1\n fi\n echo \"\" >> ~/.ssh/id_rsa\nelse\n cp /ssh/id_rsa ~/.ssh\nfi\n\nmkdir -p scripts\n\nif ! [[ $IS_LOCALHOST ]]; then\n echo \"[$(date --utc -Ins)] Setup VM\"\n\n if [[ \"$BUILDAH_HTTP_PROXY\" =~ .+\\.cluster\\.local ]]; then\n echo \"[$(date --utc -Ins)] Ignoring cluster local proxy for remote build\"\n unset BUILDAH_HTTP_PROXY BUILDAH_NO_PROXY\n fi\n\n chmod 0400 ~/.ssh/id_rsa\n BUILD_DIR=$(cat /ssh/user-dir)\n export BUILD_DIR\n export SSH_ARGS=\"-o StrictHostKeyChecking=no -o ServerAliveInterval=60 -o ServerAliveCountMax=10\"\n echo \"$BUILD_DIR\"\n # shellcheck disable=SC2086\n ssh $SSH_ARGS \"$SSH_HOST\" mkdir -p \"${BUILD_DIR@Q}/workspaces\" \"${BUILD_DIR@Q}/scripts\" \"${BUILD_DIR@Q}/volumes\"\n\n PORT_FORWARD=\"\"\n PODMAN_PORT_FORWARD=\"\"\n if [ -n \"$JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR\" ] ; then\n PORT_FORWARD=\" -L 80:$JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR:80\"\n PODMAN_PORT_FORWARD=\" -e JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR=localhost\"\n fi\n\n echo \"[$(date --utc -Ins)] Rsync data\"\n\n rsync --timeout=300 -razW /shared/ \"$SSH_HOST:$BUILD_DIR/volumes/shared/\"\n rsync --timeout=300 -razW /var/workdir/ \"$SSH_HOST:$BUILD_DIR/volumes/workdir/\"\n rsync --timeout=300 -razW /entitlement/ \"$SSH_HOST:$BUILD_DIR/volumes/etc-pki-entitlement/\"\n rsync --timeout=300 -razW /activation-key/ \"$SSH_HOST:$BUILD_DIR/volumes/activation-key/\"\n rsync --timeout=300 -razW /additional-secret/ \"$SSH_HOST:$BUILD_DIR/volumes/additional-secret/\"\n rsync --timeout=300 -razW /mnt/trusted-ca/ \"$SSH_HOST:$BUILD_DIR/volumes/trusted-ca/\"\n rsync --timeout=300 -razW /mnt/proxy-ca-bundle/ \"$SSH_HOST:$BUILD_DIR/volumes/proxy-ca-bundle/\"\n rsync --timeout=300 -razW \"$HOME/.docker/\" \"$SSH_HOST:$BUILD_DIR/.docker/\"\n rsync --timeout=300 -razW \"/tekton/results/\" \"$SSH_HOST:$BUILD_DIR/results/\"\nfi\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\ncat >scripts/script-build.sh <<'REMOTESSHEOF'\n#!/bin/bash\nset -euo pipefail\ncd /var/workdir\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nproxy_ca_bundle=/mnt/proxy-ca-bundle/ca-bundle.crt\nupdate_ca_trust=false\n\nif [ -f \"$ca_bundle\" ]; then\n echo \"[$(date --utc -Ins)] Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors/ca-bundle.crt\n update_ca_trust=true\nfi\n\nif [ -f \"$proxy_ca_bundle\" ] && [ -n \"${BUILDAH_HTTP_PROXY}\" ]; then\n echo \"[$(date --utc -Ins)] Using mounted proxy CA bundle: $proxy_ca_bundle\"\n cp -vf $proxy_ca_bundle /etc/pki/ca-trust/source/anchors/proxy-ca-bundle.crt\n update_ca_trust=true\nfi\n\nif [ \"$update_ca_trust\" = \"true\" ]; then\n echo \"[$(date --utc -Ins)] Update CA trust\"\n update-ca-trust\nfi\n\necho \"[$(date --utc -Ins)] Prepare system (architecture: $(uname -m))\"\n\n# Fixing group permission on /var/lib/containers\nchown root:root /var/lib/containers\n\nsed -i 's/^\\s*short-name-mode\\s*=\\s*.*/short-name-mode = \"disabled\"/' /etc/containers/registries.conf\n\n# Delete policy settings for Red Hat registries to disable signature verification.\n# TODO: don't do this?\ncontainer_policy=$(\n jq '.transports |= (\n del(.docker.[\"registry.access.redhat.com\"]) |\n del(.docker.[\"registry.redhat.io\"]) |\n if (.docker == {}) then del(.docker) else . end\n )' /etc/containers/policy.json\n)\necho \"Effective container policy:\"\nprintf '%s\\n' \"$container_policy\" | tee /etc/containers/policy.json\n\n# Setting new namespace to run buildah - 2^32-2\necho 'root:1:4294967294' | tee -a /etc/subuid >>/etc/subgid\n\necho \"[$(date --utc -Ins)] Run the build\"\n\nif [ -e \"$SOURCE_CODE_DIR/$CONTEXT/$DOCKERFILE\" ]; then\n dockerfile_path=\"$(pwd)/$SOURCE_CODE_DIR/$CONTEXT/$DOCKERFILE\"\nelif [ -e \"$SOURCE_CODE_DIR/$DOCKERFILE\" ]; then\n dockerfile_path=\"$(pwd)/$SOURCE_CODE_DIR/$DOCKERFILE\"\nelse\n echo \"Cannot find Dockerfile $DOCKERFILE\"\n exit 1\nfi\n\nif [ -n \"${ANNOTATIONS_FILE}\" ] && [ -f \"${SOURCE_CODE_DIR}/${ANNOTATIONS_FILE}\" ]; then\n ANNOTATIONS_FILE=$(realpath \"${SOURCE_CODE_DIR}/${ANNOTATIONS_FILE}\")\nfi\n\nif [ -n \"${BUILD_ARGS_FILE}\" ]; then\n BUILD_ARGS_FILE=$(realpath \"${SOURCE_CODE_DIR}/${BUILD_ARGS_FILE}\")\nfi\n\n# Necessary for newer version of buildah if the host system does not contain up to date version of container-selinux\n# TODO remove the option once all hosts were updated\nsecurity_args=(--security-opts unmask=/proc/interrupts)\n\nif [ \"${PRIVILEGED_NESTED}\" == \"true\" ]; then\n security_args+=(--security-opts label=disable)\n security_args+=(--cap-add all)\n security_args+=(--devices /dev/fuse)\nfi\nif [ -n \"${ADD_CAPABILITIES}\" ]; then\n security_args+=(--cap-add \"${ADD_CAPABILITIES}\")\nfi\n\nif [ -f \"/var/workdir/cachi2/cachi2.env\" ]; then\n prefetch_dir=\"/var/workdir/cachi2\"\n # KBC defaults to ${prefetch_dir}/copy-*\n # Copy to a sibling dir instead in case we don't have write permissions to the prefetch_dir.\n # It's still on the same filesystem, so copying via reflinks should be possible.\n prefetch_dir_copy=\"/var/workdir/prefetch-copy\"\n # Save the build machine's architecture to pass to Mobster later\n uname -m >/shared/prefetch-arch\nelse\n prefetch_dir=\"\"\n prefetch_dir_copy=\"\"\nfi\n\nyum_repos_d_sources=()\nif [ -d \"${YUM_REPOS_D_FETCHED}\" ]; then\n yum_repos_d_sources+=(\"${YUM_REPOS_D_FETCHED}\")\nfi\nif [ -d \"${SOURCE_CODE_DIR}/${YUM_REPOS_D_SRC}\" ]; then\n yum_repos_d_sources+=(\"${SOURCE_CODE_DIR}/${YUM_REPOS_D_SRC}\")\nfi\n\n# 0. if hermetic=true, skip all subscription related stuff\n# 1. do not enable activation key and entitlement at same time. If both are provided, prefer activation key.\n# 2. Activation-keys will be used when the key 'org' exists in the activation key secret.\n# 3. try to pre-register and mount files to the correct location so that users do no need to modify Dockerfiles.\n# 4. If the Dockerfile contains the string \"subcription-manager register\", add the activation-keys volume\n# to buildah but don't pre-register for backwards compatibility. Mount an empty directory on\n# to \"/etc/pki/entitlement\" to prevent certificates from being included\nrhsm_args=()\nif [ \"${HERMETIC}\" != \"true\" ]; then\n if [ -e /activation-key/org ]; then\n rhsm_args+=(--rhsm-activation-key=/activation-key/activationkey\n --rhsm-org=/activation-key/org\n --rhsm-activation-mount=/activation-key)\n\n if ! grep -E \"^[^#]*subscription-manager.[^#]*register\" \"$dockerfile_path\"; then\n # user is not running registration in the Containerfile: pre-register.\n rhsm_args+=(--rhsm-activation-preregister)\n fi\n elif find /entitlement -name \"*.pem\" >/dev/null; then\n rhsm_args+=(--rhsm-entitlements=/entitlement)\n fi\nfi\nif [ \"${RHSM_MOUNT_CA_CERTS}\" != \"auto\" ]; then\n rhsm_args+=(--rhsm-mount-ca-certs=\"$RHSM_MOUNT_CA_CERTS\")\nfi\n\nsbom_args=()\nif [[ \"$SKIP_SBOM_GENERATION\" != true ]]; then\n sbom_args+=(\n --sbom-format \"$SBOM_TYPE\"\n --syft-select-catalogers \"$SBOM_SYFT_SELECT_CATALOGERS\"\n --syft-image-output /shared/sbom-image.json\n )\n if [[ \"${HERMETIC}\" == \"false\" && \"${SBOM_SOURCE_SCAN_ENABLED}\" == \"true\" ]]; then\n sbom_args+=(--syft-source-output /shared/sbom-source.json)\n fi\n if [ \"${CONTEXTUALIZE_SBOM}\" == \"true\" ]; then\n sbom_args+=(\n --builder-metadata-output=/shared/builder-metadata.json\n --buildprobe-output=/shared/buildprobe-metadata.yaml\n )\n fi\nfi\n\n# Prevent ShellCheck from giving a warning because 'image' is defined and 'IMAGE' is not.\ndeclare IMAGE\n\ncmd=(\n konflux-build-cli image build\n -f \"$dockerfile_path\" -t \"$IMAGE\" --source \"$SOURCE_CODE_DIR\" --context \"$CONTEXT\"\n # use the taskRun name as a unique tag to prevent the $IMAGE from being garbage collected\n # if another build pushes to the same $IMAGE output ref\n --additional-tags \"$TASKRUN_NAME\"\n --push\n --push-format \"$PUSH_FORMAT\"\n --secret-dirs \"src=/additional-secret,name=$ADDITIONAL_SECRET,optional=true\"\n --workdir-mount \"$WORKINGDIR_MOUNT\"\n --target \"$TARGET_STAGE\"\n --inherit-labels=\"$INHERIT_BASE_IMAGE_LABELS\"\n --source-date-epoch \"$BUILDAH_SOURCE_DATE_EPOCH\"\n --rewrite-timestamp=\"$BUILDAH_REWRITE_TIMESTAMP\"\n --squash=\"$SQUASH\"\n --omit-history=\"$BUILDAH_OMIT_HISTORY\"\n --image-source \"$SOURCE_URL\"\n --image-revision \"$COMMIT_SHA\"\n --quay-image-expires-after \"$IMAGE_EXPIRES_AFTER\"\n --build-args-file \"$BUILD_ARGS_FILE\"\n --annotations-file \"$ANNOTATIONS_FILE\"\n --legacy-build-timestamp \"$BUILD_TIMESTAMP\"\n --add-legacy-labels\n --include-legacy-buildinfo-path=\"$ICM_KEEP_COMPAT_LOCATION\"\n --skip-injections=\"$SKIP_INJECTIONS\"\n --skip-unused-stages=\"$SKIP_UNUSED_STAGES\"\n --hermetic=\"$HERMETIC\"\n --image-pull-proxy \"$BUILDAH_HTTP_PROXY\"\n --image-pull-noproxy \"$BUILDAH_NO_PROXY\"\n --yum-repos-d-sources \"${yum_repos_d_sources[@]}\"\n --yum-repos-d-target \"$YUM_REPOS_D_TARGET\"\n --prefetch-dir \"$prefetch_dir\"\n --prefetch-dir-copy \"$prefetch_dir_copy\"\n --prefetch-env-mount /cachi2/cachi2.env\n --prefetch-output-mount /cachi2/output\n \"${security_args[@]}\"\n \"${rhsm_args[@]}\"\n \"${sbom_args[@]}\"\n --containerfile-json-output /shared/parsed_dockerfile.json\n --resolved-base-images-output /shared/base_images_digests\n --no-cache\n --ulimits nofile=4096:4096\n --src-tls-verify=\"$TLSVERIFY\"\n --dest-tls-verify=\"$TLSVERIFY\"\n --allow-cross-platform-images=\"$ALLOW_CROSS_PLATFORM_IMAGES\"\n \"$@\" # --annotations, --labels, --envs, --build-args\n)\n\necho \"[$(date --utc -Ins)] $(printf '%q ' \"${cmd[@]}\")\"\n\n\"${cmd[@]}\" | tee /tmp/results.json\n\njq -j .image_url /tmp/results.json >\"/tekton/results/IMAGE_URL\"\njq -j .digest /tmp/results.json >\"/tekton/results/IMAGE_DIGEST\"\njq -j '\"\\(.image_url)@\\(.digest)\"' /tmp/results.json >\"/tekton/results/IMAGE_REF\"\n\necho\necho \"[$(date --utc -Ins)] Add metadata\"\n\n# Save the SBOM produced in prefetch so it can be merged into the final SBOM later\nif [ -f \"${prefetch_dir}/output/bom.json\" ]; then\n echo \"Making copy of sbom-prefetch.json\"\n cp \"${prefetch_dir}/output/bom.json\" /shared/sbom-prefetch.json\nfi\n\necho \"[$(date --utc -Ins)] End build\"\n\nREMOTESSHEOF\nchmod +x scripts/script-build.sh\n\nPODMAN_NVIDIA_ARGS=()\nif [[ \"$PLATFORM\" == \"linux-g\"* ]]; then\n PODMAN_NVIDIA_ARGS+=(\"--device=nvidia.com/gpu=all\" \"--security-opt=label=disable\")\nfi\n\nif ! [[ $IS_LOCALHOST ]]; then\n PRIVILEGED_NESTED_FLAGS=()\n if [[ \"${PRIVILEGED_NESTED}\" == \"true\" ]]; then\n # This is a workaround for building bootc images because the cache filesystem (/var/tmp/ on the host) must be a real filesystem that supports setting SELinux security attributes.\n # https://github.com/coreos/rpm-ostree/discussions/4648\n # shellcheck disable=SC2086\n ssh $SSH_ARGS \"$SSH_HOST\" mkdir -p \"${BUILD_DIR@Q}/var/tmp\"\n PRIVILEGED_NESTED_FLAGS=(--privileged --mount \"type=bind,source=$BUILD_DIR/var/tmp,target=/var/tmp,relabel=shared\")\n fi\n rsync --timeout=300 -ra scripts \"$SSH_HOST:$BUILD_DIR\"\n echo \"[$(date --utc -Ins)] Build via ssh\"\n # shellcheck disable=SC2086\n # Please note: all variables below the first ssh line must be quoted with ${var@Q}!\n # See https://stackoverflow.com/questions/6592376/prevent-ssh-from-breaking-up-shell-script-parameters\n ssh $SSH_ARGS \"$SSH_HOST\" $PORT_FORWARD podman run $PODMAN_PORT_FORWARD \\\n --tmpfs /run/secrets \\\n -e ADDITIONAL_SECRET=\"${ADDITIONAL_SECRET@Q}\" \\\n -e ADD_CAPABILITIES=\"${ADD_CAPABILITIES@Q}\" \\\n -e ALLOW_CROSS_PLATFORM_IMAGES=\"${ALLOW_CROSS_PLATFORM_IMAGES@Q}\" \\\n -e ANNOTATIONS_FILE=\"${ANNOTATIONS_FILE@Q}\" \\\n -e BUILD_ARGS_FILE=\"${BUILD_ARGS_FILE@Q}\" \\\n -e BUILD_TIMESTAMP=\"${BUILD_TIMESTAMP@Q}\" \\\n -e CONTEXT=\"${CONTEXT@Q}\" \\\n -e CONTEXTUALIZE_SBOM=\"${CONTEXTUALIZE_SBOM@Q}\" \\\n -e HERMETIC=\"${HERMETIC@Q}\" \\\n -e IMAGE=\"${IMAGE@Q}\" \\\n -e IMAGE_EXPIRES_AFTER=\"${IMAGE_EXPIRES_AFTER@Q}\" \\\n -e INHERIT_BASE_IMAGE_LABELS=\"${INHERIT_BASE_IMAGE_LABELS@Q}\" \\\n -e KBC_LOG_LEVEL=\"${KBC_LOG_LEVEL@Q}\" \\\n -e PRIVILEGED_NESTED=\"${PRIVILEGED_NESTED@Q}\" \\\n -e PUSH_FORMAT=\"${PUSH_FORMAT@Q}\" \\\n -e RHSM_MOUNT_CA_CERTS=\"${RHSM_MOUNT_CA_CERTS@Q}\" \\\n -e SBOM_SKIP_VALIDATION=\"${SBOM_SKIP_VALIDATION@Q}\" \\\n -e SBOM_SOURCE_SCAN_ENABLED=\"${SBOM_SOURCE_SCAN_ENABLED@Q}\" \\\n -e SBOM_SYFT_SELECT_CATALOGERS=\"${SBOM_SYFT_SELECT_CATALOGERS@Q}\" \\\n -e SBOM_TYPE=\"${SBOM_TYPE@Q}\" \\\n -e SKIP_INJECTIONS=\"${SKIP_INJECTIONS@Q}\" \\\n -e SKIP_SBOM_GENERATION=\"${SKIP_SBOM_GENERATION@Q}\" \\\n -e SKIP_UNUSED_STAGES=\"${SKIP_UNUSED_STAGES@Q}\" \\\n -e SOURCE_CODE_DIR=\"${SOURCE_CODE_DIR@Q}\" \\\n -e SQUASH=\"${SQUASH@Q}\" \\\n -e STORAGE_DRIVER=\"${STORAGE_DRIVER@Q}\" \\\n -e TARGET_STAGE=\"${TARGET_STAGE@Q}\" \\\n -e TASKRUN_NAME=\"${TASKRUN_NAME@Q}\" \\\n -e TLSVERIFY=\"${TLSVERIFY@Q}\" \\\n -e WORKINGDIR_MOUNT=\"${WORKINGDIR_MOUNT@Q}\" \\\n -e YUM_REPOS_D_FETCHED=\"${YUM_REPOS_D_FETCHED@Q}\" \\\n -e YUM_REPOS_D_SRC=\"${YUM_REPOS_D_SRC@Q}\" \\\n -e YUM_REPOS_D_TARGET=\"${YUM_REPOS_D_TARGET@Q}\" \\\n -e HOME=\"${HOME@Q}\" \\\n -e COMMIT_SHA=\"${COMMIT_SHA@Q}\" \\\n -e SOURCE_URL=\"${SOURCE_URL@Q}\" \\\n -e DOCKERFILE=\"${DOCKERFILE@Q}\" \\\n -e BUILDAH_HTTP_PROXY=\"${BUILDAH_HTTP_PROXY@Q}\" \\\n -e BUILDAH_NO_PROXY=\"${BUILDAH_NO_PROXY@Q}\" \\\n -e ICM_KEEP_COMPAT_LOCATION=\"${ICM_KEEP_COMPAT_LOCATION@Q}\" \\\n -e BUILDAH_OMIT_HISTORY=\"${BUILDAH_OMIT_HISTORY@Q}\" \\\n -e BUILDAH_SOURCE_DATE_EPOCH=\"${BUILDAH_SOURCE_DATE_EPOCH@Q}\" \\\n -e BUILDAH_REWRITE_TIMESTAMP=\"${BUILDAH_REWRITE_TIMESTAMP@Q}\" \\\n -v \"${BUILD_DIR@Q}/volumes/shared:/shared:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/workdir:/var/workdir:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/etc-pki-entitlement:/entitlement:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/activation-key:/activation-key:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/additional-secret:/additional-secret:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/trusted-ca:/mnt/trusted-ca:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/proxy-ca-bundle:/mnt/proxy-ca-bundle:Z\" \\\n -v \"${BUILD_DIR@Q}/.docker/:/root/.docker:Z\" \\\n -v \"${BUILD_DIR@Q}/results/:/tekton/results:Z\" \\\n -v \"${BUILD_DIR@Q}/scripts:/scripts:Z\" \\\n -v /var/lib/containers \\\n \"${PRIVILEGED_NESTED_FLAGS[@]@Q}\" \\\n --user=0 \"${PODMAN_NVIDIA_ARGS[@]@Q}\" --rm --entrypoint='' \"${BUILDER_IMAGE@Q}\" /scripts/script-build.sh \"${@@Q}\"\n echo \"[$(date --utc -Ins)] Rsync back\"\n rsync --timeout=300 -razW --stats \"$SSH_HOST:$BUILD_DIR/volumes/shared/\" /shared/\n rsync --timeout=300 -razW --stats \"$SSH_HOST:$BUILD_DIR/results/\" \"/tekton/results/\"\nelse\n bash scripts/script-build.sh \"$@\"\nfi\necho \"Build on remote host $SSH_HOST finished\"\n\necho \"[$(date --utc -Ins)] Final touches\"\n\nbuildah images\necho \"[$(date --utc -Ins)] End remote\"","environment":{"container":"build","image":"oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f"}},{"annotations":null,"arguments":["--additional-base-images"],"entryPoint":"#!/bin/bash\nset -euo pipefail\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\necho \"[$(date --utc -Ins)] Prepare SBOM\"\n\nif [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM generation\"\n exit 0\nfi\n\n# Convert Tekton array params into Mobster params\nADDITIONAL_BASE_IMAGES=()\nwhile [[ $# -gt 0 ]]; do\n case $1 in\n --additional-base-images)\n shift\n while [[ $# -gt 0 && $1 != --* ]]; do\n ADDITIONAL_BASE_IMAGES+=(\"$1\")\n shift\n done\n ;;\n *)\n echo \"unexpected argument: $1\" >&2\n exit 2\n ;;\n esac\ndone\n\nIMAGE_URL=\"$(cat \"/tekton/results/IMAGE_URL\")\"\nIMAGE_DIGEST=\"$(cat \"/tekton/results/IMAGE_DIGEST\")\"\n\necho \"[$(date --utc -Ins)] Generate SBOM with mobster\"\n\nmobster_args=(\n generate\n --output sbom.json\n)\n\n# Validation is a flag for `generate`, not `oci-image`, so we need to\n# handle it before the oci-image arguments\nif [ \"${SBOM_SKIP_VALIDATION}\" == \"true\" ]; then\n echo \"Skipping SBOM validation\"\n mobster_args+=(--skip-validation)\nfi\n\nmobster_args+=(\n oci-image\n --from-syft /shared/sbom-image.json\n --image-pullspec \"$IMAGE_URL\"\n --image-digest \"$IMAGE_DIGEST\"\n --parsed-dockerfile-path \"/shared/parsed_dockerfile.json\"\n --base-image-digest-file \"/shared/base_images_digests\"\n)\n\n# Add metadata to the Mobster args if provided\nmetadata_path=\"/shared/buildprobe-metadata.yaml\"\nbuilder_metadata_path=\"/shared/builder-metadata.json\"\nif [ -f \"$metadata_path\" ]; then\n mobster_args+=(--metadata-path \"$metadata_path\")\nfi\nif [ -f \"$builder_metadata_path\" ]; then\n mobster_args+=(--build-metadata-path \"$builder_metadata_path\")\nfi\n\nif [ -f /shared/sbom-source.json ]; then\n mobster_args+=(--from-syft /shared/sbom-source.json)\nfi\n\nif [ -f /shared/sbom-prefetch.json ]; then\n mobster_args+=(--from-hermeto /shared/sbom-prefetch.json)\nfi\n\nif [ -n \"${TARGET_STAGE}\" ]; then\n mobster_args+=(--dockerfile-target \"${TARGET_STAGE}\")\nfi\n\nfor ADDITIONAL_BASE_IMAGE in \"${ADDITIONAL_BASE_IMAGES[@]}\"; do\n mobster_args+=(--additional-base-image \"$ADDITIONAL_BASE_IMAGE\")\ndone\n\nif [ \"${CONTEXTUALIZE_SBOM}\" == \"true\" ] && [ \"${HERMETIC}\" == \"false\" ]; then\n mobster_args+=(--contextualize)\nfi\n\nif [ -f \"/shared/prefetch-arch\" ]; then\n mobster_args+=(--arch \"$(cat /shared/prefetch-arch)\")\nfi\n\nmobster \"${mobster_args[@]}\"\n\necho \"[$(date --utc -Ins)] End prepare-sboms\"\n","environment":{"container":"prepare-sboms","image":"oci://quay.io/konflux-ci/mobster@sha256:3eee4ecf87d50cb073318ab96097b9ea2cb6e5e59dd296a212e57017a9059f61"}},{"annotations":null,"arguments":null,"entryPoint":"#!/bin/bash\nset -euo pipefail\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nIMAGE_REF=$(cat \"/tekton/results/IMAGE_REF\")\n\n# Pre-select the correct credentials to work around cosign not supporting the containers-auth.json spec\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_REF\" >/tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\n# --- SBOM upload ---\nif [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM push because SBOM generation is disabled\"\nelse\n echo \"[$(date --utc -Ins)] Upload SBOM\"\n echo \"Pushing sbom to registry\"\n if ! retry cosign attach sbom --sbom sbom.json --type \"$SBOM_TYPE\" \"$IMAGE_REF\"; then\n echo \"Failed to push sbom to registry\"\n exit 1\n fi\n\n # Remove tag from IMAGE while allowing registry to contain a port number.\n sbom_repo=\"${IMAGE%:*}\"\n sbom_digest=\"$(sha256sum sbom.json | cut -d' ' -f1)\"\n # The SBOM_BLOB_URL is created by `cosign attach sbom`.\n echo -n \"${sbom_repo}@sha256:${sbom_digest}\" | tee \"/tekton/results/SBOM_BLOB_URL\"\nfi\n\necho\necho \"[$(date --utc -Ins)] Handle keyless signing if enabled\"\n\n# --- keyless signing ---\n# detect if keyless signing is required\nSIGNING_CONFIG='{}'\nKFLX_CONFIG_PATH='/tmp/konflux_config.json'\nif ! RETRY_STOP_IF_STDERR_MATCHES='configmaps \"cluster-config\" not found' retry kubectl get configmap cluster-config -n konflux-info -o json >\"${KFLX_CONFIG_PATH}\"; then\n echo \"Failed to fetch konflux cluster-config, default values will be used\" >&2\nelse\n SIGNING_CONFIG=\"$(cat ${KFLX_CONFIG_PATH})\"\nfi\n\n# configmap key -> variable name mapping\ndeclare -A SIGNING_KEY_MAP=(\n [defaultOIDCIssuer]=SIGSTORE_OIDC_ISSUER\n [rekorInternalUrl]=REKOR_URL\n [fulcioInternalUrl]=SIGSTORE_FULCIO_URL\n [tufInternalUrl]=TUF_URL\n)\n\n# fallback keys when internal URL is not available\ndeclare -A SIGNING_FALLBACK_MAP=(\n [rekorInternalUrl]=rekorExternalUrl\n [fulcioInternalUrl]=fulcioExternalUrl\n [tufInternalUrl]=tufExternalUrl\n)\n\nmissing=\"\"\nconfigured=0\nfor key in \"${!SIGNING_KEY_MAP[@]}\"; do\n val=$(echo \"${SIGNING_CONFIG}\" | jq -r \".data.${key} // empty\")\n if [ -z \"${val}\" ] && [ -n \"${SIGNING_FALLBACK_MAP[$key]+x}\" ]; then\n fallback_key=\"${SIGNING_FALLBACK_MAP[$key]}\"\n val=$(echo \"${SIGNING_CONFIG}\" | jq -r \".data.${fallback_key} // empty\")\n if [ -n \"${val}\" ]; then\n echo \"Using fallback ${fallback_key} instead of ${key}\"\n fi\n fi\n if [ -z \"${val}\" ]; then\n missing=\"${missing:+${missing}, }${key}\"\n else\n declare \"${SIGNING_KEY_MAP[$key]}=${val}\"\n configured=$((configured + 1))\n fi\ndone\n\nif [ \"${configured}\" -eq 0 ]; then\n echo \"Keyless signing is disabled (none of ${missing} are configured in the konflux-info/cluster-config configmap)\"\nelif [ \"${configured}\" -ne \"${#SIGNING_KEY_MAP[@]}\" ]; then\n echo \"ERROR: Incomplete keyless signing configuration in konflux-info/cluster-config configmap. Missing: ${missing}\" >&2\n exit 1\nelse\n echo \"Keyless signing is enabled\"\n\n echo \"Using Rekor URL: ${REKOR_URL}\"\n echo \"Using Fulcio URL: ${SIGSTORE_FULCIO_URL}\"\n echo \"Using OIDC issuer: ${SIGSTORE_OIDC_ISSUER}\"\n\n echo \"Initializing TUF root from ${TUF_URL}\"\n if ! retry cosign initialize --root \"${TUF_URL}/root.json\" --mirror \"${TUF_URL}\"; then\n echo \"Failed to initialize TUF root\" >&2\n exit 1\n fi\n\n # env var consumed by cosign\n SIGSTORE_ID_TOKEN=\"$(cat /var/run/sigstore/cosign/oidc-token)\"\n export SIGSTORE_ID_TOKEN\n\n echo \"[$(date --utc -Ins)] Sign image\"\n echo \"Signing image ${IMAGE_REF} using keyless signing\"\n if ! retry cosign sign -y \\\n --use-signing-config=false \\\n --rekor-url=\"${REKOR_URL}\" \\\n --fulcio-url=\"${SIGSTORE_FULCIO_URL}\" \\\n --oidc-issuer=\"${SIGSTORE_OIDC_ISSUER}\" \\\n \"${IMAGE_REF}\"; then\n echo \"Failed to sign image\" >&2\n exit 1\n fi\n\n if [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM signing because SBOM generation is disabled\"\n else\n ATT_SBOM_TYPE=\"${SBOM_TYPE}\"\n if [ \"${ATT_SBOM_TYPE}\" = \"spdx\" ]; then\n # for format cossistency with cyclonedx format, we want to use spdxjson instad of spdx\n # spdx export data as rawstring, we want structured json as cyclonedx\n ATT_SBOM_TYPE=\"spdxjson\"\n fi\n\n echo \"[$(date --utc -Ins)] Sign SBOM\"\n echo \"Signing and attaching SBOM to ${IMAGE_REF} using keyless signing\"\n if ! retry cosign attest -y --type \"${ATT_SBOM_TYPE}\" --predicate sbom.json \\\n --use-signing-config=false \\\n --rekor-url=\"${REKOR_URL}\" \\\n --fulcio-url=\"${SIGSTORE_FULCIO_URL}\" \\\n --oidc-issuer=\"${SIGSTORE_OIDC_ISSUER}\" \\\n \"${IMAGE_REF}\"; then\n echo \"Failed to sign SBOM\" >&2\n exit 1\n fi\n fi\nfi\n\necho\necho \"[$(date --utc -Ins)] End upload-sbom\"\n","environment":{"container":"upload-sbom","image":"oci://quay.io/konflux-ci/task-runner@sha256:4b01fbf98fa7155f5c21443c285f88853864ae7cc66981cf6b543fc6ba16b81b"}}]},{"after":["prefetch-dependencies","clone-repository","rhoai-init"],"finishedOn":"2026-09-08T21:26:07Z","invocation":{"configSource":{"digest":{"sha256":"ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344"},"entryPoint":"buildah-remote-oci-ta","uri":"quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/ad5f5889-c13a-481e-8ab5-b8fdd0e29042","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"image-build, konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-569f583cd9c685eb-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","build.appstudio.redhat.com/build_type":"docker","build.appstudio.redhat.com/target-platform":"linux-ppc64le","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"build-images","tekton.dev/task":"buildah-remote-oci-ta"}},"parameters":{"ACTIVATION_KEY":"custom-activation-key","ADDITIONAL_BASE_IMAGES":[],"ADDITIONAL_SECRET":"does-not-exist","ADD_CAPABILITIES":"","ALLOW_CROSS_PLATFORM_IMAGES":"false","ANNOTATIONS":[],"ANNOTATIONS_FILE":"","BUILDAH_FORMAT":"docker","BUILD_ARGS":[],"BUILD_ARGS_FILE":"","BUILD_TIMESTAMP":"","CACHI2_ARTIFACT":"","COMMIT_SHA":"58e7f0f6d889933345394152903c95c62e6bd9c3","CONTEXT":".","CONTEXTUALIZE_SBOM":"false","DOCKERFILE":"Dockerfiles/agent.Dockerfile.konflux","ENTITLEMENT_SECRET":"etc-pki-entitlement","ENV_VARS":[],"HERMETIC":"false","HTTP_PROXY":"","ICM_KEEP_COMPAT_LOCATION":"true","IMAGE":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","IMAGE_APPEND_PLATFORM":"true","IMAGE_EXPIRES_AFTER":"","INHERIT_BASE_IMAGE_LABELS":"true","LABELS":["version=v2.25.11","url=https://github.com/red-hat-data-services/kserve","release=1788902446","git.url=https://github.com/red-hat-data-services/kserve","git.commit=58e7f0f6d889933345394152903c95c62e6bd9c3","cpe=","name=rhoai/odh-kserve-agent-rhel9","io.openshift.tags=odh-kserve-agent","com.redhat.component=odh-kserve-agent-rhel9","summary=ODH Kserve Agent","description=ODH Kserve Agent","io.k8s.display-name=ODH Kserve Agent","io.k8s.description=ODH Kserve Agent","vendor=Red Hat, Inc.","maintainer=RHOAI DevTestOps Team [openshift-ai-devtestops@redhat.com]"],"LOG_LEVEL":"info","NO_PROXY":"","OMIT_HISTORY":"false","PLATFORM":"linux/ppc64le","PREFETCH_INPUT":"","PRIVILEGED_NESTED":"false","PROXY_CA_TRUST_CONFIG_MAP_KEY":"ca-bundle.crt","PROXY_CA_TRUST_CONFIG_MAP_NAME":"caching-ca-bundle","REWRITE_TIMESTAMP":"false","RHSM_MOUNT_CA_CERTS":"auto","SBOM_SKIP_VALIDATION":"true","SBOM_SOURCE_SCAN_ENABLED":"true","SBOM_SYFT_SELECT_CATALOGERS":"","SBOM_TYPE":"spdx","SKIP_INJECTIONS":"false","SKIP_SBOM_GENERATION":"false","SKIP_UNUSED_STAGES":"true","SOURCE_ARTIFACT":"oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735","SOURCE_DATE_EPOCH":"","SOURCE_URL":"","SQUASH":"false","STORAGE_DRIVER":"overlay","TARGET_STAGE":"","TLSVERIFY":"true","WORKINGDIR_MOUNT":"","YUM_REPOS_D_FETCHED":"fetched.repos.d","YUM_REPOS_D_SRC":"repos.d","YUM_REPOS_D_TARGET":"/etc/yum.repos.d","caTrustConfigMapKey":"ca-bundle.crt","caTrustConfigMapName":"trusted-ca"}},"name":"build-images","ref":{"params":[{"name":"name","value":"buildah-remote-oci-ta"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.12.1@sha256:ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"IMAGE_DIGEST","type":"string","value":"sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75"},{"name":"IMAGE_REF","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-ppc64le@sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75"},{"name":"IMAGE_URL","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-ppc64le"},{"name":"SBOM_BLOB_URL","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9@sha256:c51e531b2d7512e3b085484bab77b06c07d3b40fbbb7fee1a562a7166e841b0b"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:21:49Z","status":"Succeeded","steps":[{"annotations":null,"arguments":["use","oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source","=/var/workdir/cachi2"],"entryPoint":"","environment":{"container":"use-trusted-artifact","image":"oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c"}},{"annotations":null,"arguments":["--build-args","--envs","--labels","version=v2.25.11","url=https://github.com/red-hat-data-services/kserve","release=1788902446","git.url=https://github.com/red-hat-data-services/kserve","git.commit=58e7f0f6d889933345394152903c95c62e6bd9c3","cpe=","name=rhoai/odh-kserve-agent-rhel9","io.openshift.tags=odh-kserve-agent","com.redhat.component=odh-kserve-agent-rhel9","summary=ODH Kserve Agent","description=ODH Kserve Agent","io.k8s.display-name=ODH Kserve Agent","io.k8s.description=ODH Kserve Agent","vendor=Red Hat, Inc.","maintainer=RHOAI DevTestOps Team [openshift-ai-devtestops@redhat.com]","--annotations"],"entryPoint":"#!/bin/bash\nset -e\nset -o verbose\n\necho \"[$(date --utc -Ins)] Prepare connection\"\n\nmkdir -p ~/.ssh\nif [ -e \"/ssh/error\" ]; then\n #no server could be provisioned\n cat /ssh/error\n exit 1\nfi\n\nSSH_HOST=$(cat /ssh/host)\nexport SSH_HOST\n\nif [ \"$SSH_HOST\" == \"localhost\" ] ; then\n IS_LOCALHOST=true\n echo \"Localhost detected; running build in cluster\"\nelif [ -e \"/ssh/otp\" ]; then\n if ! curl --fail --cacert /ssh/otp-ca -XPOST -d @/ssh/otp \"$(cat /ssh/otp-server)\" >~/.ssh/id_rsa; then\n echo \"Failed to retrieve SSH key from the OTP server. This can happen when the PipelineRun retry option re-runs a task whose one-time credential was already consumed. Please, start a new build, and if problem persists, please report it as an MPC bug.\" >&2\n exit 1\n fi\n echo \"\" >> ~/.ssh/id_rsa\nelse\n cp /ssh/id_rsa ~/.ssh\nfi\n\nmkdir -p scripts\n\nif ! [[ $IS_LOCALHOST ]]; then\n echo \"[$(date --utc -Ins)] Setup VM\"\n\n if [[ \"$BUILDAH_HTTP_PROXY\" =~ .+\\.cluster\\.local ]]; then\n echo \"[$(date --utc -Ins)] Ignoring cluster local proxy for remote build\"\n unset BUILDAH_HTTP_PROXY BUILDAH_NO_PROXY\n fi\n\n chmod 0400 ~/.ssh/id_rsa\n BUILD_DIR=$(cat /ssh/user-dir)\n export BUILD_DIR\n export SSH_ARGS=\"-o StrictHostKeyChecking=no -o ServerAliveInterval=60 -o ServerAliveCountMax=10\"\n echo \"$BUILD_DIR\"\n # shellcheck disable=SC2086\n ssh $SSH_ARGS \"$SSH_HOST\" mkdir -p \"${BUILD_DIR@Q}/workspaces\" \"${BUILD_DIR@Q}/scripts\" \"${BUILD_DIR@Q}/volumes\"\n\n PORT_FORWARD=\"\"\n PODMAN_PORT_FORWARD=\"\"\n if [ -n \"$JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR\" ] ; then\n PORT_FORWARD=\" -L 80:$JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR:80\"\n PODMAN_PORT_FORWARD=\" -e JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR=localhost\"\n fi\n\n echo \"[$(date --utc -Ins)] Rsync data\"\n\n rsync --timeout=300 -razW /shared/ \"$SSH_HOST:$BUILD_DIR/volumes/shared/\"\n rsync --timeout=300 -razW /var/workdir/ \"$SSH_HOST:$BUILD_DIR/volumes/workdir/\"\n rsync --timeout=300 -razW /entitlement/ \"$SSH_HOST:$BUILD_DIR/volumes/etc-pki-entitlement/\"\n rsync --timeout=300 -razW /activation-key/ \"$SSH_HOST:$BUILD_DIR/volumes/activation-key/\"\n rsync --timeout=300 -razW /additional-secret/ \"$SSH_HOST:$BUILD_DIR/volumes/additional-secret/\"\n rsync --timeout=300 -razW /mnt/trusted-ca/ \"$SSH_HOST:$BUILD_DIR/volumes/trusted-ca/\"\n rsync --timeout=300 -razW /mnt/proxy-ca-bundle/ \"$SSH_HOST:$BUILD_DIR/volumes/proxy-ca-bundle/\"\n rsync --timeout=300 -razW \"$HOME/.docker/\" \"$SSH_HOST:$BUILD_DIR/.docker/\"\n rsync --timeout=300 -razW \"/tekton/results/\" \"$SSH_HOST:$BUILD_DIR/results/\"\nfi\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\ncat >scripts/script-build.sh <<'REMOTESSHEOF'\n#!/bin/bash\nset -euo pipefail\ncd /var/workdir\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nproxy_ca_bundle=/mnt/proxy-ca-bundle/ca-bundle.crt\nupdate_ca_trust=false\n\nif [ -f \"$ca_bundle\" ]; then\n echo \"[$(date --utc -Ins)] Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors/ca-bundle.crt\n update_ca_trust=true\nfi\n\nif [ -f \"$proxy_ca_bundle\" ] && [ -n \"${BUILDAH_HTTP_PROXY}\" ]; then\n echo \"[$(date --utc -Ins)] Using mounted proxy CA bundle: $proxy_ca_bundle\"\n cp -vf $proxy_ca_bundle /etc/pki/ca-trust/source/anchors/proxy-ca-bundle.crt\n update_ca_trust=true\nfi\n\nif [ \"$update_ca_trust\" = \"true\" ]; then\n echo \"[$(date --utc -Ins)] Update CA trust\"\n update-ca-trust\nfi\n\necho \"[$(date --utc -Ins)] Prepare system (architecture: $(uname -m))\"\n\n# Fixing group permission on /var/lib/containers\nchown root:root /var/lib/containers\n\nsed -i 's/^\\s*short-name-mode\\s*=\\s*.*/short-name-mode = \"disabled\"/' /etc/containers/registries.conf\n\n# Delete policy settings for Red Hat registries to disable signature verification.\n# TODO: don't do this?\ncontainer_policy=$(\n jq '.transports |= (\n del(.docker.[\"registry.access.redhat.com\"]) |\n del(.docker.[\"registry.redhat.io\"]) |\n if (.docker == {}) then del(.docker) else . end\n )' /etc/containers/policy.json\n)\necho \"Effective container policy:\"\nprintf '%s\\n' \"$container_policy\" | tee /etc/containers/policy.json\n\n# Setting new namespace to run buildah - 2^32-2\necho 'root:1:4294967294' | tee -a /etc/subuid >>/etc/subgid\n\necho \"[$(date --utc -Ins)] Run the build\"\n\nif [ -e \"$SOURCE_CODE_DIR/$CONTEXT/$DOCKERFILE\" ]; then\n dockerfile_path=\"$(pwd)/$SOURCE_CODE_DIR/$CONTEXT/$DOCKERFILE\"\nelif [ -e \"$SOURCE_CODE_DIR/$DOCKERFILE\" ]; then\n dockerfile_path=\"$(pwd)/$SOURCE_CODE_DIR/$DOCKERFILE\"\nelse\n echo \"Cannot find Dockerfile $DOCKERFILE\"\n exit 1\nfi\n\nif [ -n \"${ANNOTATIONS_FILE}\" ] && [ -f \"${SOURCE_CODE_DIR}/${ANNOTATIONS_FILE}\" ]; then\n ANNOTATIONS_FILE=$(realpath \"${SOURCE_CODE_DIR}/${ANNOTATIONS_FILE}\")\nfi\n\nif [ -n \"${BUILD_ARGS_FILE}\" ]; then\n BUILD_ARGS_FILE=$(realpath \"${SOURCE_CODE_DIR}/${BUILD_ARGS_FILE}\")\nfi\n\n# Necessary for newer version of buildah if the host system does not contain up to date version of container-selinux\n# TODO remove the option once all hosts were updated\nsecurity_args=(--security-opts unmask=/proc/interrupts)\n\nif [ \"${PRIVILEGED_NESTED}\" == \"true\" ]; then\n security_args+=(--security-opts label=disable)\n security_args+=(--cap-add all)\n security_args+=(--devices /dev/fuse)\nfi\nif [ -n \"${ADD_CAPABILITIES}\" ]; then\n security_args+=(--cap-add \"${ADD_CAPABILITIES}\")\nfi\n\nif [ -f \"/var/workdir/cachi2/cachi2.env\" ]; then\n prefetch_dir=\"/var/workdir/cachi2\"\n # KBC defaults to ${prefetch_dir}/copy-*\n # Copy to a sibling dir instead in case we don't have write permissions to the prefetch_dir.\n # It's still on the same filesystem, so copying via reflinks should be possible.\n prefetch_dir_copy=\"/var/workdir/prefetch-copy\"\n # Save the build machine's architecture to pass to Mobster later\n uname -m >/shared/prefetch-arch\nelse\n prefetch_dir=\"\"\n prefetch_dir_copy=\"\"\nfi\n\nyum_repos_d_sources=()\nif [ -d \"${YUM_REPOS_D_FETCHED}\" ]; then\n yum_repos_d_sources+=(\"${YUM_REPOS_D_FETCHED}\")\nfi\nif [ -d \"${SOURCE_CODE_DIR}/${YUM_REPOS_D_SRC}\" ]; then\n yum_repos_d_sources+=(\"${SOURCE_CODE_DIR}/${YUM_REPOS_D_SRC}\")\nfi\n\n# 0. if hermetic=true, skip all subscription related stuff\n# 1. do not enable activation key and entitlement at same time. If both are provided, prefer activation key.\n# 2. Activation-keys will be used when the key 'org' exists in the activation key secret.\n# 3. try to pre-register and mount files to the correct location so that users do no need to modify Dockerfiles.\n# 4. If the Dockerfile contains the string \"subcription-manager register\", add the activation-keys volume\n# to buildah but don't pre-register for backwards compatibility. Mount an empty directory on\n# to \"/etc/pki/entitlement\" to prevent certificates from being included\nrhsm_args=()\nif [ \"${HERMETIC}\" != \"true\" ]; then\n if [ -e /activation-key/org ]; then\n rhsm_args+=(--rhsm-activation-key=/activation-key/activationkey\n --rhsm-org=/activation-key/org\n --rhsm-activation-mount=/activation-key)\n\n if ! grep -E \"^[^#]*subscription-manager.[^#]*register\" \"$dockerfile_path\"; then\n # user is not running registration in the Containerfile: pre-register.\n rhsm_args+=(--rhsm-activation-preregister)\n fi\n elif find /entitlement -name \"*.pem\" >/dev/null; then\n rhsm_args+=(--rhsm-entitlements=/entitlement)\n fi\nfi\nif [ \"${RHSM_MOUNT_CA_CERTS}\" != \"auto\" ]; then\n rhsm_args+=(--rhsm-mount-ca-certs=\"$RHSM_MOUNT_CA_CERTS\")\nfi\n\nsbom_args=()\nif [[ \"$SKIP_SBOM_GENERATION\" != true ]]; then\n sbom_args+=(\n --sbom-format \"$SBOM_TYPE\"\n --syft-select-catalogers \"$SBOM_SYFT_SELECT_CATALOGERS\"\n --syft-image-output /shared/sbom-image.json\n )\n if [[ \"${HERMETIC}\" == \"false\" && \"${SBOM_SOURCE_SCAN_ENABLED}\" == \"true\" ]]; then\n sbom_args+=(--syft-source-output /shared/sbom-source.json)\n fi\n if [ \"${CONTEXTUALIZE_SBOM}\" == \"true\" ]; then\n sbom_args+=(\n --builder-metadata-output=/shared/builder-metadata.json\n --buildprobe-output=/shared/buildprobe-metadata.yaml\n )\n fi\nfi\n\n# Prevent ShellCheck from giving a warning because 'image' is defined and 'IMAGE' is not.\ndeclare IMAGE\n\ncmd=(\n konflux-build-cli image build\n -f \"$dockerfile_path\" -t \"$IMAGE\" --source \"$SOURCE_CODE_DIR\" --context \"$CONTEXT\"\n # use the taskRun name as a unique tag to prevent the $IMAGE from being garbage collected\n # if another build pushes to the same $IMAGE output ref\n --additional-tags \"$TASKRUN_NAME\"\n --push\n --push-format \"$PUSH_FORMAT\"\n --secret-dirs \"src=/additional-secret,name=$ADDITIONAL_SECRET,optional=true\"\n --workdir-mount \"$WORKINGDIR_MOUNT\"\n --target \"$TARGET_STAGE\"\n --inherit-labels=\"$INHERIT_BASE_IMAGE_LABELS\"\n --source-date-epoch \"$BUILDAH_SOURCE_DATE_EPOCH\"\n --rewrite-timestamp=\"$BUILDAH_REWRITE_TIMESTAMP\"\n --squash=\"$SQUASH\"\n --omit-history=\"$BUILDAH_OMIT_HISTORY\"\n --image-source \"$SOURCE_URL\"\n --image-revision \"$COMMIT_SHA\"\n --quay-image-expires-after \"$IMAGE_EXPIRES_AFTER\"\n --build-args-file \"$BUILD_ARGS_FILE\"\n --annotations-file \"$ANNOTATIONS_FILE\"\n --legacy-build-timestamp \"$BUILD_TIMESTAMP\"\n --add-legacy-labels\n --include-legacy-buildinfo-path=\"$ICM_KEEP_COMPAT_LOCATION\"\n --skip-injections=\"$SKIP_INJECTIONS\"\n --skip-unused-stages=\"$SKIP_UNUSED_STAGES\"\n --hermetic=\"$HERMETIC\"\n --image-pull-proxy \"$BUILDAH_HTTP_PROXY\"\n --image-pull-noproxy \"$BUILDAH_NO_PROXY\"\n --yum-repos-d-sources \"${yum_repos_d_sources[@]}\"\n --yum-repos-d-target \"$YUM_REPOS_D_TARGET\"\n --prefetch-dir \"$prefetch_dir\"\n --prefetch-dir-copy \"$prefetch_dir_copy\"\n --prefetch-env-mount /cachi2/cachi2.env\n --prefetch-output-mount /cachi2/output\n \"${security_args[@]}\"\n \"${rhsm_args[@]}\"\n \"${sbom_args[@]}\"\n --containerfile-json-output /shared/parsed_dockerfile.json\n --resolved-base-images-output /shared/base_images_digests\n --no-cache\n --ulimits nofile=4096:4096\n --src-tls-verify=\"$TLSVERIFY\"\n --dest-tls-verify=\"$TLSVERIFY\"\n --allow-cross-platform-images=\"$ALLOW_CROSS_PLATFORM_IMAGES\"\n \"$@\" # --annotations, --labels, --envs, --build-args\n)\n\necho \"[$(date --utc -Ins)] $(printf '%q ' \"${cmd[@]}\")\"\n\n\"${cmd[@]}\" | tee /tmp/results.json\n\njq -j .image_url /tmp/results.json >\"/tekton/results/IMAGE_URL\"\njq -j .digest /tmp/results.json >\"/tekton/results/IMAGE_DIGEST\"\njq -j '\"\\(.image_url)@\\(.digest)\"' /tmp/results.json >\"/tekton/results/IMAGE_REF\"\n\necho\necho \"[$(date --utc -Ins)] Add metadata\"\n\n# Save the SBOM produced in prefetch so it can be merged into the final SBOM later\nif [ -f \"${prefetch_dir}/output/bom.json\" ]; then\n echo \"Making copy of sbom-prefetch.json\"\n cp \"${prefetch_dir}/output/bom.json\" /shared/sbom-prefetch.json\nfi\n\necho \"[$(date --utc -Ins)] End build\"\n\nREMOTESSHEOF\nchmod +x scripts/script-build.sh\n\nPODMAN_NVIDIA_ARGS=()\nif [[ \"$PLATFORM\" == \"linux-g\"* ]]; then\n PODMAN_NVIDIA_ARGS+=(\"--device=nvidia.com/gpu=all\" \"--security-opt=label=disable\")\nfi\n\nif ! [[ $IS_LOCALHOST ]]; then\n PRIVILEGED_NESTED_FLAGS=()\n if [[ \"${PRIVILEGED_NESTED}\" == \"true\" ]]; then\n # This is a workaround for building bootc images because the cache filesystem (/var/tmp/ on the host) must be a real filesystem that supports setting SELinux security attributes.\n # https://github.com/coreos/rpm-ostree/discussions/4648\n # shellcheck disable=SC2086\n ssh $SSH_ARGS \"$SSH_HOST\" mkdir -p \"${BUILD_DIR@Q}/var/tmp\"\n PRIVILEGED_NESTED_FLAGS=(--privileged --mount \"type=bind,source=$BUILD_DIR/var/tmp,target=/var/tmp,relabel=shared\")\n fi\n rsync --timeout=300 -ra scripts \"$SSH_HOST:$BUILD_DIR\"\n echo \"[$(date --utc -Ins)] Build via ssh\"\n # shellcheck disable=SC2086\n # Please note: all variables below the first ssh line must be quoted with ${var@Q}!\n # See https://stackoverflow.com/questions/6592376/prevent-ssh-from-breaking-up-shell-script-parameters\n ssh $SSH_ARGS \"$SSH_HOST\" $PORT_FORWARD podman run $PODMAN_PORT_FORWARD \\\n --tmpfs /run/secrets \\\n -e ADDITIONAL_SECRET=\"${ADDITIONAL_SECRET@Q}\" \\\n -e ADD_CAPABILITIES=\"${ADD_CAPABILITIES@Q}\" \\\n -e ALLOW_CROSS_PLATFORM_IMAGES=\"${ALLOW_CROSS_PLATFORM_IMAGES@Q}\" \\\n -e ANNOTATIONS_FILE=\"${ANNOTATIONS_FILE@Q}\" \\\n -e BUILD_ARGS_FILE=\"${BUILD_ARGS_FILE@Q}\" \\\n -e BUILD_TIMESTAMP=\"${BUILD_TIMESTAMP@Q}\" \\\n -e CONTEXT=\"${CONTEXT@Q}\" \\\n -e CONTEXTUALIZE_SBOM=\"${CONTEXTUALIZE_SBOM@Q}\" \\\n -e HERMETIC=\"${HERMETIC@Q}\" \\\n -e IMAGE=\"${IMAGE@Q}\" \\\n -e IMAGE_EXPIRES_AFTER=\"${IMAGE_EXPIRES_AFTER@Q}\" \\\n -e INHERIT_BASE_IMAGE_LABELS=\"${INHERIT_BASE_IMAGE_LABELS@Q}\" \\\n -e KBC_LOG_LEVEL=\"${KBC_LOG_LEVEL@Q}\" \\\n -e PRIVILEGED_NESTED=\"${PRIVILEGED_NESTED@Q}\" \\\n -e PUSH_FORMAT=\"${PUSH_FORMAT@Q}\" \\\n -e RHSM_MOUNT_CA_CERTS=\"${RHSM_MOUNT_CA_CERTS@Q}\" \\\n -e SBOM_SKIP_VALIDATION=\"${SBOM_SKIP_VALIDATION@Q}\" \\\n -e SBOM_SOURCE_SCAN_ENABLED=\"${SBOM_SOURCE_SCAN_ENABLED@Q}\" \\\n -e SBOM_SYFT_SELECT_CATALOGERS=\"${SBOM_SYFT_SELECT_CATALOGERS@Q}\" \\\n -e SBOM_TYPE=\"${SBOM_TYPE@Q}\" \\\n -e SKIP_INJECTIONS=\"${SKIP_INJECTIONS@Q}\" \\\n -e SKIP_SBOM_GENERATION=\"${SKIP_SBOM_GENERATION@Q}\" \\\n -e SKIP_UNUSED_STAGES=\"${SKIP_UNUSED_STAGES@Q}\" \\\n -e SOURCE_CODE_DIR=\"${SOURCE_CODE_DIR@Q}\" \\\n -e SQUASH=\"${SQUASH@Q}\" \\\n -e STORAGE_DRIVER=\"${STORAGE_DRIVER@Q}\" \\\n -e TARGET_STAGE=\"${TARGET_STAGE@Q}\" \\\n -e TASKRUN_NAME=\"${TASKRUN_NAME@Q}\" \\\n -e TLSVERIFY=\"${TLSVERIFY@Q}\" \\\n -e WORKINGDIR_MOUNT=\"${WORKINGDIR_MOUNT@Q}\" \\\n -e YUM_REPOS_D_FETCHED=\"${YUM_REPOS_D_FETCHED@Q}\" \\\n -e YUM_REPOS_D_SRC=\"${YUM_REPOS_D_SRC@Q}\" \\\n -e YUM_REPOS_D_TARGET=\"${YUM_REPOS_D_TARGET@Q}\" \\\n -e HOME=\"${HOME@Q}\" \\\n -e COMMIT_SHA=\"${COMMIT_SHA@Q}\" \\\n -e SOURCE_URL=\"${SOURCE_URL@Q}\" \\\n -e DOCKERFILE=\"${DOCKERFILE@Q}\" \\\n -e BUILDAH_HTTP_PROXY=\"${BUILDAH_HTTP_PROXY@Q}\" \\\n -e BUILDAH_NO_PROXY=\"${BUILDAH_NO_PROXY@Q}\" \\\n -e ICM_KEEP_COMPAT_LOCATION=\"${ICM_KEEP_COMPAT_LOCATION@Q}\" \\\n -e BUILDAH_OMIT_HISTORY=\"${BUILDAH_OMIT_HISTORY@Q}\" \\\n -e BUILDAH_SOURCE_DATE_EPOCH=\"${BUILDAH_SOURCE_DATE_EPOCH@Q}\" \\\n -e BUILDAH_REWRITE_TIMESTAMP=\"${BUILDAH_REWRITE_TIMESTAMP@Q}\" \\\n -v \"${BUILD_DIR@Q}/volumes/shared:/shared:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/workdir:/var/workdir:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/etc-pki-entitlement:/entitlement:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/activation-key:/activation-key:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/additional-secret:/additional-secret:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/trusted-ca:/mnt/trusted-ca:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/proxy-ca-bundle:/mnt/proxy-ca-bundle:Z\" \\\n -v \"${BUILD_DIR@Q}/.docker/:/root/.docker:Z\" \\\n -v \"${BUILD_DIR@Q}/results/:/tekton/results:Z\" \\\n -v \"${BUILD_DIR@Q}/scripts:/scripts:Z\" \\\n -v /var/lib/containers \\\n \"${PRIVILEGED_NESTED_FLAGS[@]@Q}\" \\\n --user=0 \"${PODMAN_NVIDIA_ARGS[@]@Q}\" --rm --entrypoint='' \"${BUILDER_IMAGE@Q}\" /scripts/script-build.sh \"${@@Q}\"\n echo \"[$(date --utc -Ins)] Rsync back\"\n rsync --timeout=300 -razW --stats \"$SSH_HOST:$BUILD_DIR/volumes/shared/\" /shared/\n rsync --timeout=300 -razW --stats \"$SSH_HOST:$BUILD_DIR/results/\" \"/tekton/results/\"\nelse\n bash scripts/script-build.sh \"$@\"\nfi\necho \"Build on remote host $SSH_HOST finished\"\n\necho \"[$(date --utc -Ins)] Final touches\"\n\nbuildah images\necho \"[$(date --utc -Ins)] End remote\"","environment":{"container":"build","image":"oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f"}},{"annotations":null,"arguments":["--additional-base-images"],"entryPoint":"#!/bin/bash\nset -euo pipefail\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\necho \"[$(date --utc -Ins)] Prepare SBOM\"\n\nif [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM generation\"\n exit 0\nfi\n\n# Convert Tekton array params into Mobster params\nADDITIONAL_BASE_IMAGES=()\nwhile [[ $# -gt 0 ]]; do\n case $1 in\n --additional-base-images)\n shift\n while [[ $# -gt 0 && $1 != --* ]]; do\n ADDITIONAL_BASE_IMAGES+=(\"$1\")\n shift\n done\n ;;\n *)\n echo \"unexpected argument: $1\" >&2\n exit 2\n ;;\n esac\ndone\n\nIMAGE_URL=\"$(cat \"/tekton/results/IMAGE_URL\")\"\nIMAGE_DIGEST=\"$(cat \"/tekton/results/IMAGE_DIGEST\")\"\n\necho \"[$(date --utc -Ins)] Generate SBOM with mobster\"\n\nmobster_args=(\n generate\n --output sbom.json\n)\n\n# Validation is a flag for `generate`, not `oci-image`, so we need to\n# handle it before the oci-image arguments\nif [ \"${SBOM_SKIP_VALIDATION}\" == \"true\" ]; then\n echo \"Skipping SBOM validation\"\n mobster_args+=(--skip-validation)\nfi\n\nmobster_args+=(\n oci-image\n --from-syft /shared/sbom-image.json\n --image-pullspec \"$IMAGE_URL\"\n --image-digest \"$IMAGE_DIGEST\"\n --parsed-dockerfile-path \"/shared/parsed_dockerfile.json\"\n --base-image-digest-file \"/shared/base_images_digests\"\n)\n\n# Add metadata to the Mobster args if provided\nmetadata_path=\"/shared/buildprobe-metadata.yaml\"\nbuilder_metadata_path=\"/shared/builder-metadata.json\"\nif [ -f \"$metadata_path\" ]; then\n mobster_args+=(--metadata-path \"$metadata_path\")\nfi\nif [ -f \"$builder_metadata_path\" ]; then\n mobster_args+=(--build-metadata-path \"$builder_metadata_path\")\nfi\n\nif [ -f /shared/sbom-source.json ]; then\n mobster_args+=(--from-syft /shared/sbom-source.json)\nfi\n\nif [ -f /shared/sbom-prefetch.json ]; then\n mobster_args+=(--from-hermeto /shared/sbom-prefetch.json)\nfi\n\nif [ -n \"${TARGET_STAGE}\" ]; then\n mobster_args+=(--dockerfile-target \"${TARGET_STAGE}\")\nfi\n\nfor ADDITIONAL_BASE_IMAGE in \"${ADDITIONAL_BASE_IMAGES[@]}\"; do\n mobster_args+=(--additional-base-image \"$ADDITIONAL_BASE_IMAGE\")\ndone\n\nif [ \"${CONTEXTUALIZE_SBOM}\" == \"true\" ] && [ \"${HERMETIC}\" == \"false\" ]; then\n mobster_args+=(--contextualize)\nfi\n\nif [ -f \"/shared/prefetch-arch\" ]; then\n mobster_args+=(--arch \"$(cat /shared/prefetch-arch)\")\nfi\n\nmobster \"${mobster_args[@]}\"\n\necho \"[$(date --utc -Ins)] End prepare-sboms\"\n","environment":{"container":"prepare-sboms","image":"oci://quay.io/konflux-ci/mobster@sha256:3eee4ecf87d50cb073318ab96097b9ea2cb6e5e59dd296a212e57017a9059f61"}},{"annotations":null,"arguments":null,"entryPoint":"#!/bin/bash\nset -euo pipefail\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nIMAGE_REF=$(cat \"/tekton/results/IMAGE_REF\")\n\n# Pre-select the correct credentials to work around cosign not supporting the containers-auth.json spec\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_REF\" >/tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\n# --- SBOM upload ---\nif [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM push because SBOM generation is disabled\"\nelse\n echo \"[$(date --utc -Ins)] Upload SBOM\"\n echo \"Pushing sbom to registry\"\n if ! retry cosign attach sbom --sbom sbom.json --type \"$SBOM_TYPE\" \"$IMAGE_REF\"; then\n echo \"Failed to push sbom to registry\"\n exit 1\n fi\n\n # Remove tag from IMAGE while allowing registry to contain a port number.\n sbom_repo=\"${IMAGE%:*}\"\n sbom_digest=\"$(sha256sum sbom.json | cut -d' ' -f1)\"\n # The SBOM_BLOB_URL is created by `cosign attach sbom`.\n echo -n \"${sbom_repo}@sha256:${sbom_digest}\" | tee \"/tekton/results/SBOM_BLOB_URL\"\nfi\n\necho\necho \"[$(date --utc -Ins)] Handle keyless signing if enabled\"\n\n# --- keyless signing ---\n# detect if keyless signing is required\nSIGNING_CONFIG='{}'\nKFLX_CONFIG_PATH='/tmp/konflux_config.json'\nif ! RETRY_STOP_IF_STDERR_MATCHES='configmaps \"cluster-config\" not found' retry kubectl get configmap cluster-config -n konflux-info -o json >\"${KFLX_CONFIG_PATH}\"; then\n echo \"Failed to fetch konflux cluster-config, default values will be used\" >&2\nelse\n SIGNING_CONFIG=\"$(cat ${KFLX_CONFIG_PATH})\"\nfi\n\n# configmap key -> variable name mapping\ndeclare -A SIGNING_KEY_MAP=(\n [defaultOIDCIssuer]=SIGSTORE_OIDC_ISSUER\n [rekorInternalUrl]=REKOR_URL\n [fulcioInternalUrl]=SIGSTORE_FULCIO_URL\n [tufInternalUrl]=TUF_URL\n)\n\n# fallback keys when internal URL is not available\ndeclare -A SIGNING_FALLBACK_MAP=(\n [rekorInternalUrl]=rekorExternalUrl\n [fulcioInternalUrl]=fulcioExternalUrl\n [tufInternalUrl]=tufExternalUrl\n)\n\nmissing=\"\"\nconfigured=0\nfor key in \"${!SIGNING_KEY_MAP[@]}\"; do\n val=$(echo \"${SIGNING_CONFIG}\" | jq -r \".data.${key} // empty\")\n if [ -z \"${val}\" ] && [ -n \"${SIGNING_FALLBACK_MAP[$key]+x}\" ]; then\n fallback_key=\"${SIGNING_FALLBACK_MAP[$key]}\"\n val=$(echo \"${SIGNING_CONFIG}\" | jq -r \".data.${fallback_key} // empty\")\n if [ -n \"${val}\" ]; then\n echo \"Using fallback ${fallback_key} instead of ${key}\"\n fi\n fi\n if [ -z \"${val}\" ]; then\n missing=\"${missing:+${missing}, }${key}\"\n else\n declare \"${SIGNING_KEY_MAP[$key]}=${val}\"\n configured=$((configured + 1))\n fi\ndone\n\nif [ \"${configured}\" -eq 0 ]; then\n echo \"Keyless signing is disabled (none of ${missing} are configured in the konflux-info/cluster-config configmap)\"\nelif [ \"${configured}\" -ne \"${#SIGNING_KEY_MAP[@]}\" ]; then\n echo \"ERROR: Incomplete keyless signing configuration in konflux-info/cluster-config configmap. Missing: ${missing}\" >&2\n exit 1\nelse\n echo \"Keyless signing is enabled\"\n\n echo \"Using Rekor URL: ${REKOR_URL}\"\n echo \"Using Fulcio URL: ${SIGSTORE_FULCIO_URL}\"\n echo \"Using OIDC issuer: ${SIGSTORE_OIDC_ISSUER}\"\n\n echo \"Initializing TUF root from ${TUF_URL}\"\n if ! retry cosign initialize --root \"${TUF_URL}/root.json\" --mirror \"${TUF_URL}\"; then\n echo \"Failed to initialize TUF root\" >&2\n exit 1\n fi\n\n # env var consumed by cosign\n SIGSTORE_ID_TOKEN=\"$(cat /var/run/sigstore/cosign/oidc-token)\"\n export SIGSTORE_ID_TOKEN\n\n echo \"[$(date --utc -Ins)] Sign image\"\n echo \"Signing image ${IMAGE_REF} using keyless signing\"\n if ! retry cosign sign -y \\\n --use-signing-config=false \\\n --rekor-url=\"${REKOR_URL}\" \\\n --fulcio-url=\"${SIGSTORE_FULCIO_URL}\" \\\n --oidc-issuer=\"${SIGSTORE_OIDC_ISSUER}\" \\\n \"${IMAGE_REF}\"; then\n echo \"Failed to sign image\" >&2\n exit 1\n fi\n\n if [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM signing because SBOM generation is disabled\"\n else\n ATT_SBOM_TYPE=\"${SBOM_TYPE}\"\n if [ \"${ATT_SBOM_TYPE}\" = \"spdx\" ]; then\n # for format cossistency with cyclonedx format, we want to use spdxjson instad of spdx\n # spdx export data as rawstring, we want structured json as cyclonedx\n ATT_SBOM_TYPE=\"spdxjson\"\n fi\n\n echo \"[$(date --utc -Ins)] Sign SBOM\"\n echo \"Signing and attaching SBOM to ${IMAGE_REF} using keyless signing\"\n if ! retry cosign attest -y --type \"${ATT_SBOM_TYPE}\" --predicate sbom.json \\\n --use-signing-config=false \\\n --rekor-url=\"${REKOR_URL}\" \\\n --fulcio-url=\"${SIGSTORE_FULCIO_URL}\" \\\n --oidc-issuer=\"${SIGSTORE_OIDC_ISSUER}\" \\\n \"${IMAGE_REF}\"; then\n echo \"Failed to sign SBOM\" >&2\n exit 1\n fi\n fi\nfi\n\necho\necho \"[$(date --utc -Ins)] End upload-sbom\"\n","environment":{"container":"upload-sbom","image":"oci://quay.io/konflux-ci/task-runner@sha256:4b01fbf98fa7155f5c21443c285f88853864ae7cc66981cf6b543fc6ba16b81b"}}]},{"after":["prefetch-dependencies","clone-repository","rhoai-init"],"finishedOn":"2026-09-08T21:27:04Z","invocation":{"configSource":{"digest":{"sha256":"ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344"},"entryPoint":"buildah-remote-oci-ta","uri":"quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/7bac666d-84dc-4f8f-839f-86e62cefb9d3","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"image-build, konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-3ca78b5f78e8886d-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","build.appstudio.redhat.com/build_type":"docker","build.appstudio.redhat.com/target-platform":"linux-s390x","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"build-images","tekton.dev/task":"buildah-remote-oci-ta"}},"parameters":{"ACTIVATION_KEY":"custom-activation-key","ADDITIONAL_BASE_IMAGES":[],"ADDITIONAL_SECRET":"does-not-exist","ADD_CAPABILITIES":"","ALLOW_CROSS_PLATFORM_IMAGES":"false","ANNOTATIONS":[],"ANNOTATIONS_FILE":"","BUILDAH_FORMAT":"docker","BUILD_ARGS":[],"BUILD_ARGS_FILE":"","BUILD_TIMESTAMP":"","CACHI2_ARTIFACT":"","COMMIT_SHA":"58e7f0f6d889933345394152903c95c62e6bd9c3","CONTEXT":".","CONTEXTUALIZE_SBOM":"false","DOCKERFILE":"Dockerfiles/agent.Dockerfile.konflux","ENTITLEMENT_SECRET":"etc-pki-entitlement","ENV_VARS":[],"HERMETIC":"false","HTTP_PROXY":"","ICM_KEEP_COMPAT_LOCATION":"true","IMAGE":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","IMAGE_APPEND_PLATFORM":"true","IMAGE_EXPIRES_AFTER":"","INHERIT_BASE_IMAGE_LABELS":"true","LABELS":["version=v2.25.11","url=https://github.com/red-hat-data-services/kserve","release=1788902446","git.url=https://github.com/red-hat-data-services/kserve","git.commit=58e7f0f6d889933345394152903c95c62e6bd9c3","cpe=","name=rhoai/odh-kserve-agent-rhel9","io.openshift.tags=odh-kserve-agent","com.redhat.component=odh-kserve-agent-rhel9","summary=ODH Kserve Agent","description=ODH Kserve Agent","io.k8s.display-name=ODH Kserve Agent","io.k8s.description=ODH Kserve Agent","vendor=Red Hat, Inc.","maintainer=RHOAI DevTestOps Team [openshift-ai-devtestops@redhat.com]"],"LOG_LEVEL":"info","NO_PROXY":"","OMIT_HISTORY":"false","PLATFORM":"linux/s390x","PREFETCH_INPUT":"","PRIVILEGED_NESTED":"false","PROXY_CA_TRUST_CONFIG_MAP_KEY":"ca-bundle.crt","PROXY_CA_TRUST_CONFIG_MAP_NAME":"caching-ca-bundle","REWRITE_TIMESTAMP":"false","RHSM_MOUNT_CA_CERTS":"auto","SBOM_SKIP_VALIDATION":"true","SBOM_SOURCE_SCAN_ENABLED":"true","SBOM_SYFT_SELECT_CATALOGERS":"","SBOM_TYPE":"spdx","SKIP_INJECTIONS":"false","SKIP_SBOM_GENERATION":"false","SKIP_UNUSED_STAGES":"true","SOURCE_ARTIFACT":"oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735","SOURCE_DATE_EPOCH":"","SOURCE_URL":"","SQUASH":"false","STORAGE_DRIVER":"overlay","TARGET_STAGE":"","TLSVERIFY":"true","WORKINGDIR_MOUNT":"","YUM_REPOS_D_FETCHED":"fetched.repos.d","YUM_REPOS_D_SRC":"repos.d","YUM_REPOS_D_TARGET":"/etc/yum.repos.d","caTrustConfigMapKey":"ca-bundle.crt","caTrustConfigMapName":"trusted-ca"}},"name":"build-images","ref":{"params":[{"name":"name","value":"buildah-remote-oci-ta"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.12.1@sha256:ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"IMAGE_DIGEST","type":"string","value":"sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f"},{"name":"IMAGE_REF","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-s390x@sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f"},{"name":"IMAGE_URL","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-s390x"},{"name":"SBOM_BLOB_URL","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9@sha256:381d10a089a3dcfb625f58c3ff6f2a98bb4a3bca37f3fcd5800ae730d075ec7b"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:21:49Z","status":"Succeeded","steps":[{"annotations":null,"arguments":["use","oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source","=/var/workdir/cachi2"],"entryPoint":"","environment":{"container":"use-trusted-artifact","image":"oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c"}},{"annotations":null,"arguments":["--build-args","--envs","--labels","version=v2.25.11","url=https://github.com/red-hat-data-services/kserve","release=1788902446","git.url=https://github.com/red-hat-data-services/kserve","git.commit=58e7f0f6d889933345394152903c95c62e6bd9c3","cpe=","name=rhoai/odh-kserve-agent-rhel9","io.openshift.tags=odh-kserve-agent","com.redhat.component=odh-kserve-agent-rhel9","summary=ODH Kserve Agent","description=ODH Kserve Agent","io.k8s.display-name=ODH Kserve Agent","io.k8s.description=ODH Kserve Agent","vendor=Red Hat, Inc.","maintainer=RHOAI DevTestOps Team [openshift-ai-devtestops@redhat.com]","--annotations"],"entryPoint":"#!/bin/bash\nset -e\nset -o verbose\n\necho \"[$(date --utc -Ins)] Prepare connection\"\n\nmkdir -p ~/.ssh\nif [ -e \"/ssh/error\" ]; then\n #no server could be provisioned\n cat /ssh/error\n exit 1\nfi\n\nSSH_HOST=$(cat /ssh/host)\nexport SSH_HOST\n\nif [ \"$SSH_HOST\" == \"localhost\" ] ; then\n IS_LOCALHOST=true\n echo \"Localhost detected; running build in cluster\"\nelif [ -e \"/ssh/otp\" ]; then\n if ! curl --fail --cacert /ssh/otp-ca -XPOST -d @/ssh/otp \"$(cat /ssh/otp-server)\" >~/.ssh/id_rsa; then\n echo \"Failed to retrieve SSH key from the OTP server. This can happen when the PipelineRun retry option re-runs a task whose one-time credential was already consumed. Please, start a new build, and if problem persists, please report it as an MPC bug.\" >&2\n exit 1\n fi\n echo \"\" >> ~/.ssh/id_rsa\nelse\n cp /ssh/id_rsa ~/.ssh\nfi\n\nmkdir -p scripts\n\nif ! [[ $IS_LOCALHOST ]]; then\n echo \"[$(date --utc -Ins)] Setup VM\"\n\n if [[ \"$BUILDAH_HTTP_PROXY\" =~ .+\\.cluster\\.local ]]; then\n echo \"[$(date --utc -Ins)] Ignoring cluster local proxy for remote build\"\n unset BUILDAH_HTTP_PROXY BUILDAH_NO_PROXY\n fi\n\n chmod 0400 ~/.ssh/id_rsa\n BUILD_DIR=$(cat /ssh/user-dir)\n export BUILD_DIR\n export SSH_ARGS=\"-o StrictHostKeyChecking=no -o ServerAliveInterval=60 -o ServerAliveCountMax=10\"\n echo \"$BUILD_DIR\"\n # shellcheck disable=SC2086\n ssh $SSH_ARGS \"$SSH_HOST\" mkdir -p \"${BUILD_DIR@Q}/workspaces\" \"${BUILD_DIR@Q}/scripts\" \"${BUILD_DIR@Q}/volumes\"\n\n PORT_FORWARD=\"\"\n PODMAN_PORT_FORWARD=\"\"\n if [ -n \"$JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR\" ] ; then\n PORT_FORWARD=\" -L 80:$JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR:80\"\n PODMAN_PORT_FORWARD=\" -e JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR=localhost\"\n fi\n\n echo \"[$(date --utc -Ins)] Rsync data\"\n\n rsync --timeout=300 -razW /shared/ \"$SSH_HOST:$BUILD_DIR/volumes/shared/\"\n rsync --timeout=300 -razW /var/workdir/ \"$SSH_HOST:$BUILD_DIR/volumes/workdir/\"\n rsync --timeout=300 -razW /entitlement/ \"$SSH_HOST:$BUILD_DIR/volumes/etc-pki-entitlement/\"\n rsync --timeout=300 -razW /activation-key/ \"$SSH_HOST:$BUILD_DIR/volumes/activation-key/\"\n rsync --timeout=300 -razW /additional-secret/ \"$SSH_HOST:$BUILD_DIR/volumes/additional-secret/\"\n rsync --timeout=300 -razW /mnt/trusted-ca/ \"$SSH_HOST:$BUILD_DIR/volumes/trusted-ca/\"\n rsync --timeout=300 -razW /mnt/proxy-ca-bundle/ \"$SSH_HOST:$BUILD_DIR/volumes/proxy-ca-bundle/\"\n rsync --timeout=300 -razW \"$HOME/.docker/\" \"$SSH_HOST:$BUILD_DIR/.docker/\"\n rsync --timeout=300 -razW \"/tekton/results/\" \"$SSH_HOST:$BUILD_DIR/results/\"\nfi\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\ncat >scripts/script-build.sh <<'REMOTESSHEOF'\n#!/bin/bash\nset -euo pipefail\ncd /var/workdir\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nproxy_ca_bundle=/mnt/proxy-ca-bundle/ca-bundle.crt\nupdate_ca_trust=false\n\nif [ -f \"$ca_bundle\" ]; then\n echo \"[$(date --utc -Ins)] Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors/ca-bundle.crt\n update_ca_trust=true\nfi\n\nif [ -f \"$proxy_ca_bundle\" ] && [ -n \"${BUILDAH_HTTP_PROXY}\" ]; then\n echo \"[$(date --utc -Ins)] Using mounted proxy CA bundle: $proxy_ca_bundle\"\n cp -vf $proxy_ca_bundle /etc/pki/ca-trust/source/anchors/proxy-ca-bundle.crt\n update_ca_trust=true\nfi\n\nif [ \"$update_ca_trust\" = \"true\" ]; then\n echo \"[$(date --utc -Ins)] Update CA trust\"\n update-ca-trust\nfi\n\necho \"[$(date --utc -Ins)] Prepare system (architecture: $(uname -m))\"\n\n# Fixing group permission on /var/lib/containers\nchown root:root /var/lib/containers\n\nsed -i 's/^\\s*short-name-mode\\s*=\\s*.*/short-name-mode = \"disabled\"/' /etc/containers/registries.conf\n\n# Delete policy settings for Red Hat registries to disable signature verification.\n# TODO: don't do this?\ncontainer_policy=$(\n jq '.transports |= (\n del(.docker.[\"registry.access.redhat.com\"]) |\n del(.docker.[\"registry.redhat.io\"]) |\n if (.docker == {}) then del(.docker) else . end\n )' /etc/containers/policy.json\n)\necho \"Effective container policy:\"\nprintf '%s\\n' \"$container_policy\" | tee /etc/containers/policy.json\n\n# Setting new namespace to run buildah - 2^32-2\necho 'root:1:4294967294' | tee -a /etc/subuid >>/etc/subgid\n\necho \"[$(date --utc -Ins)] Run the build\"\n\nif [ -e \"$SOURCE_CODE_DIR/$CONTEXT/$DOCKERFILE\" ]; then\n dockerfile_path=\"$(pwd)/$SOURCE_CODE_DIR/$CONTEXT/$DOCKERFILE\"\nelif [ -e \"$SOURCE_CODE_DIR/$DOCKERFILE\" ]; then\n dockerfile_path=\"$(pwd)/$SOURCE_CODE_DIR/$DOCKERFILE\"\nelse\n echo \"Cannot find Dockerfile $DOCKERFILE\"\n exit 1\nfi\n\nif [ -n \"${ANNOTATIONS_FILE}\" ] && [ -f \"${SOURCE_CODE_DIR}/${ANNOTATIONS_FILE}\" ]; then\n ANNOTATIONS_FILE=$(realpath \"${SOURCE_CODE_DIR}/${ANNOTATIONS_FILE}\")\nfi\n\nif [ -n \"${BUILD_ARGS_FILE}\" ]; then\n BUILD_ARGS_FILE=$(realpath \"${SOURCE_CODE_DIR}/${BUILD_ARGS_FILE}\")\nfi\n\n# Necessary for newer version of buildah if the host system does not contain up to date version of container-selinux\n# TODO remove the option once all hosts were updated\nsecurity_args=(--security-opts unmask=/proc/interrupts)\n\nif [ \"${PRIVILEGED_NESTED}\" == \"true\" ]; then\n security_args+=(--security-opts label=disable)\n security_args+=(--cap-add all)\n security_args+=(--devices /dev/fuse)\nfi\nif [ -n \"${ADD_CAPABILITIES}\" ]; then\n security_args+=(--cap-add \"${ADD_CAPABILITIES}\")\nfi\n\nif [ -f \"/var/workdir/cachi2/cachi2.env\" ]; then\n prefetch_dir=\"/var/workdir/cachi2\"\n # KBC defaults to ${prefetch_dir}/copy-*\n # Copy to a sibling dir instead in case we don't have write permissions to the prefetch_dir.\n # It's still on the same filesystem, so copying via reflinks should be possible.\n prefetch_dir_copy=\"/var/workdir/prefetch-copy\"\n # Save the build machine's architecture to pass to Mobster later\n uname -m >/shared/prefetch-arch\nelse\n prefetch_dir=\"\"\n prefetch_dir_copy=\"\"\nfi\n\nyum_repos_d_sources=()\nif [ -d \"${YUM_REPOS_D_FETCHED}\" ]; then\n yum_repos_d_sources+=(\"${YUM_REPOS_D_FETCHED}\")\nfi\nif [ -d \"${SOURCE_CODE_DIR}/${YUM_REPOS_D_SRC}\" ]; then\n yum_repos_d_sources+=(\"${SOURCE_CODE_DIR}/${YUM_REPOS_D_SRC}\")\nfi\n\n# 0. if hermetic=true, skip all subscription related stuff\n# 1. do not enable activation key and entitlement at same time. If both are provided, prefer activation key.\n# 2. Activation-keys will be used when the key 'org' exists in the activation key secret.\n# 3. try to pre-register and mount files to the correct location so that users do no need to modify Dockerfiles.\n# 4. If the Dockerfile contains the string \"subcription-manager register\", add the activation-keys volume\n# to buildah but don't pre-register for backwards compatibility. Mount an empty directory on\n# to \"/etc/pki/entitlement\" to prevent certificates from being included\nrhsm_args=()\nif [ \"${HERMETIC}\" != \"true\" ]; then\n if [ -e /activation-key/org ]; then\n rhsm_args+=(--rhsm-activation-key=/activation-key/activationkey\n --rhsm-org=/activation-key/org\n --rhsm-activation-mount=/activation-key)\n\n if ! grep -E \"^[^#]*subscription-manager.[^#]*register\" \"$dockerfile_path\"; then\n # user is not running registration in the Containerfile: pre-register.\n rhsm_args+=(--rhsm-activation-preregister)\n fi\n elif find /entitlement -name \"*.pem\" >/dev/null; then\n rhsm_args+=(--rhsm-entitlements=/entitlement)\n fi\nfi\nif [ \"${RHSM_MOUNT_CA_CERTS}\" != \"auto\" ]; then\n rhsm_args+=(--rhsm-mount-ca-certs=\"$RHSM_MOUNT_CA_CERTS\")\nfi\n\nsbom_args=()\nif [[ \"$SKIP_SBOM_GENERATION\" != true ]]; then\n sbom_args+=(\n --sbom-format \"$SBOM_TYPE\"\n --syft-select-catalogers \"$SBOM_SYFT_SELECT_CATALOGERS\"\n --syft-image-output /shared/sbom-image.json\n )\n if [[ \"${HERMETIC}\" == \"false\" && \"${SBOM_SOURCE_SCAN_ENABLED}\" == \"true\" ]]; then\n sbom_args+=(--syft-source-output /shared/sbom-source.json)\n fi\n if [ \"${CONTEXTUALIZE_SBOM}\" == \"true\" ]; then\n sbom_args+=(\n --builder-metadata-output=/shared/builder-metadata.json\n --buildprobe-output=/shared/buildprobe-metadata.yaml\n )\n fi\nfi\n\n# Prevent ShellCheck from giving a warning because 'image' is defined and 'IMAGE' is not.\ndeclare IMAGE\n\ncmd=(\n konflux-build-cli image build\n -f \"$dockerfile_path\" -t \"$IMAGE\" --source \"$SOURCE_CODE_DIR\" --context \"$CONTEXT\"\n # use the taskRun name as a unique tag to prevent the $IMAGE from being garbage collected\n # if another build pushes to the same $IMAGE output ref\n --additional-tags \"$TASKRUN_NAME\"\n --push\n --push-format \"$PUSH_FORMAT\"\n --secret-dirs \"src=/additional-secret,name=$ADDITIONAL_SECRET,optional=true\"\n --workdir-mount \"$WORKINGDIR_MOUNT\"\n --target \"$TARGET_STAGE\"\n --inherit-labels=\"$INHERIT_BASE_IMAGE_LABELS\"\n --source-date-epoch \"$BUILDAH_SOURCE_DATE_EPOCH\"\n --rewrite-timestamp=\"$BUILDAH_REWRITE_TIMESTAMP\"\n --squash=\"$SQUASH\"\n --omit-history=\"$BUILDAH_OMIT_HISTORY\"\n --image-source \"$SOURCE_URL\"\n --image-revision \"$COMMIT_SHA\"\n --quay-image-expires-after \"$IMAGE_EXPIRES_AFTER\"\n --build-args-file \"$BUILD_ARGS_FILE\"\n --annotations-file \"$ANNOTATIONS_FILE\"\n --legacy-build-timestamp \"$BUILD_TIMESTAMP\"\n --add-legacy-labels\n --include-legacy-buildinfo-path=\"$ICM_KEEP_COMPAT_LOCATION\"\n --skip-injections=\"$SKIP_INJECTIONS\"\n --skip-unused-stages=\"$SKIP_UNUSED_STAGES\"\n --hermetic=\"$HERMETIC\"\n --image-pull-proxy \"$BUILDAH_HTTP_PROXY\"\n --image-pull-noproxy \"$BUILDAH_NO_PROXY\"\n --yum-repos-d-sources \"${yum_repos_d_sources[@]}\"\n --yum-repos-d-target \"$YUM_REPOS_D_TARGET\"\n --prefetch-dir \"$prefetch_dir\"\n --prefetch-dir-copy \"$prefetch_dir_copy\"\n --prefetch-env-mount /cachi2/cachi2.env\n --prefetch-output-mount /cachi2/output\n \"${security_args[@]}\"\n \"${rhsm_args[@]}\"\n \"${sbom_args[@]}\"\n --containerfile-json-output /shared/parsed_dockerfile.json\n --resolved-base-images-output /shared/base_images_digests\n --no-cache\n --ulimits nofile=4096:4096\n --src-tls-verify=\"$TLSVERIFY\"\n --dest-tls-verify=\"$TLSVERIFY\"\n --allow-cross-platform-images=\"$ALLOW_CROSS_PLATFORM_IMAGES\"\n \"$@\" # --annotations, --labels, --envs, --build-args\n)\n\necho \"[$(date --utc -Ins)] $(printf '%q ' \"${cmd[@]}\")\"\n\n\"${cmd[@]}\" | tee /tmp/results.json\n\njq -j .image_url /tmp/results.json >\"/tekton/results/IMAGE_URL\"\njq -j .digest /tmp/results.json >\"/tekton/results/IMAGE_DIGEST\"\njq -j '\"\\(.image_url)@\\(.digest)\"' /tmp/results.json >\"/tekton/results/IMAGE_REF\"\n\necho\necho \"[$(date --utc -Ins)] Add metadata\"\n\n# Save the SBOM produced in prefetch so it can be merged into the final SBOM later\nif [ -f \"${prefetch_dir}/output/bom.json\" ]; then\n echo \"Making copy of sbom-prefetch.json\"\n cp \"${prefetch_dir}/output/bom.json\" /shared/sbom-prefetch.json\nfi\n\necho \"[$(date --utc -Ins)] End build\"\n\nREMOTESSHEOF\nchmod +x scripts/script-build.sh\n\nPODMAN_NVIDIA_ARGS=()\nif [[ \"$PLATFORM\" == \"linux-g\"* ]]; then\n PODMAN_NVIDIA_ARGS+=(\"--device=nvidia.com/gpu=all\" \"--security-opt=label=disable\")\nfi\n\nif ! [[ $IS_LOCALHOST ]]; then\n PRIVILEGED_NESTED_FLAGS=()\n if [[ \"${PRIVILEGED_NESTED}\" == \"true\" ]]; then\n # This is a workaround for building bootc images because the cache filesystem (/var/tmp/ on the host) must be a real filesystem that supports setting SELinux security attributes.\n # https://github.com/coreos/rpm-ostree/discussions/4648\n # shellcheck disable=SC2086\n ssh $SSH_ARGS \"$SSH_HOST\" mkdir -p \"${BUILD_DIR@Q}/var/tmp\"\n PRIVILEGED_NESTED_FLAGS=(--privileged --mount \"type=bind,source=$BUILD_DIR/var/tmp,target=/var/tmp,relabel=shared\")\n fi\n rsync --timeout=300 -ra scripts \"$SSH_HOST:$BUILD_DIR\"\n echo \"[$(date --utc -Ins)] Build via ssh\"\n # shellcheck disable=SC2086\n # Please note: all variables below the first ssh line must be quoted with ${var@Q}!\n # See https://stackoverflow.com/questions/6592376/prevent-ssh-from-breaking-up-shell-script-parameters\n ssh $SSH_ARGS \"$SSH_HOST\" $PORT_FORWARD podman run $PODMAN_PORT_FORWARD \\\n --tmpfs /run/secrets \\\n -e ADDITIONAL_SECRET=\"${ADDITIONAL_SECRET@Q}\" \\\n -e ADD_CAPABILITIES=\"${ADD_CAPABILITIES@Q}\" \\\n -e ALLOW_CROSS_PLATFORM_IMAGES=\"${ALLOW_CROSS_PLATFORM_IMAGES@Q}\" \\\n -e ANNOTATIONS_FILE=\"${ANNOTATIONS_FILE@Q}\" \\\n -e BUILD_ARGS_FILE=\"${BUILD_ARGS_FILE@Q}\" \\\n -e BUILD_TIMESTAMP=\"${BUILD_TIMESTAMP@Q}\" \\\n -e CONTEXT=\"${CONTEXT@Q}\" \\\n -e CONTEXTUALIZE_SBOM=\"${CONTEXTUALIZE_SBOM@Q}\" \\\n -e HERMETIC=\"${HERMETIC@Q}\" \\\n -e IMAGE=\"${IMAGE@Q}\" \\\n -e IMAGE_EXPIRES_AFTER=\"${IMAGE_EXPIRES_AFTER@Q}\" \\\n -e INHERIT_BASE_IMAGE_LABELS=\"${INHERIT_BASE_IMAGE_LABELS@Q}\" \\\n -e KBC_LOG_LEVEL=\"${KBC_LOG_LEVEL@Q}\" \\\n -e PRIVILEGED_NESTED=\"${PRIVILEGED_NESTED@Q}\" \\\n -e PUSH_FORMAT=\"${PUSH_FORMAT@Q}\" \\\n -e RHSM_MOUNT_CA_CERTS=\"${RHSM_MOUNT_CA_CERTS@Q}\" \\\n -e SBOM_SKIP_VALIDATION=\"${SBOM_SKIP_VALIDATION@Q}\" \\\n -e SBOM_SOURCE_SCAN_ENABLED=\"${SBOM_SOURCE_SCAN_ENABLED@Q}\" \\\n -e SBOM_SYFT_SELECT_CATALOGERS=\"${SBOM_SYFT_SELECT_CATALOGERS@Q}\" \\\n -e SBOM_TYPE=\"${SBOM_TYPE@Q}\" \\\n -e SKIP_INJECTIONS=\"${SKIP_INJECTIONS@Q}\" \\\n -e SKIP_SBOM_GENERATION=\"${SKIP_SBOM_GENERATION@Q}\" \\\n -e SKIP_UNUSED_STAGES=\"${SKIP_UNUSED_STAGES@Q}\" \\\n -e SOURCE_CODE_DIR=\"${SOURCE_CODE_DIR@Q}\" \\\n -e SQUASH=\"${SQUASH@Q}\" \\\n -e STORAGE_DRIVER=\"${STORAGE_DRIVER@Q}\" \\\n -e TARGET_STAGE=\"${TARGET_STAGE@Q}\" \\\n -e TASKRUN_NAME=\"${TASKRUN_NAME@Q}\" \\\n -e TLSVERIFY=\"${TLSVERIFY@Q}\" \\\n -e WORKINGDIR_MOUNT=\"${WORKINGDIR_MOUNT@Q}\" \\\n -e YUM_REPOS_D_FETCHED=\"${YUM_REPOS_D_FETCHED@Q}\" \\\n -e YUM_REPOS_D_SRC=\"${YUM_REPOS_D_SRC@Q}\" \\\n -e YUM_REPOS_D_TARGET=\"${YUM_REPOS_D_TARGET@Q}\" \\\n -e HOME=\"${HOME@Q}\" \\\n -e COMMIT_SHA=\"${COMMIT_SHA@Q}\" \\\n -e SOURCE_URL=\"${SOURCE_URL@Q}\" \\\n -e DOCKERFILE=\"${DOCKERFILE@Q}\" \\\n -e BUILDAH_HTTP_PROXY=\"${BUILDAH_HTTP_PROXY@Q}\" \\\n -e BUILDAH_NO_PROXY=\"${BUILDAH_NO_PROXY@Q}\" \\\n -e ICM_KEEP_COMPAT_LOCATION=\"${ICM_KEEP_COMPAT_LOCATION@Q}\" \\\n -e BUILDAH_OMIT_HISTORY=\"${BUILDAH_OMIT_HISTORY@Q}\" \\\n -e BUILDAH_SOURCE_DATE_EPOCH=\"${BUILDAH_SOURCE_DATE_EPOCH@Q}\" \\\n -e BUILDAH_REWRITE_TIMESTAMP=\"${BUILDAH_REWRITE_TIMESTAMP@Q}\" \\\n -v \"${BUILD_DIR@Q}/volumes/shared:/shared:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/workdir:/var/workdir:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/etc-pki-entitlement:/entitlement:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/activation-key:/activation-key:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/additional-secret:/additional-secret:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/trusted-ca:/mnt/trusted-ca:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/proxy-ca-bundle:/mnt/proxy-ca-bundle:Z\" \\\n -v \"${BUILD_DIR@Q}/.docker/:/root/.docker:Z\" \\\n -v \"${BUILD_DIR@Q}/results/:/tekton/results:Z\" \\\n -v \"${BUILD_DIR@Q}/scripts:/scripts:Z\" \\\n -v /var/lib/containers \\\n \"${PRIVILEGED_NESTED_FLAGS[@]@Q}\" \\\n --user=0 \"${PODMAN_NVIDIA_ARGS[@]@Q}\" --rm --entrypoint='' \"${BUILDER_IMAGE@Q}\" /scripts/script-build.sh \"${@@Q}\"\n echo \"[$(date --utc -Ins)] Rsync back\"\n rsync --timeout=300 -razW --stats \"$SSH_HOST:$BUILD_DIR/volumes/shared/\" /shared/\n rsync --timeout=300 -razW --stats \"$SSH_HOST:$BUILD_DIR/results/\" \"/tekton/results/\"\nelse\n bash scripts/script-build.sh \"$@\"\nfi\necho \"Build on remote host $SSH_HOST finished\"\n\necho \"[$(date --utc -Ins)] Final touches\"\n\nbuildah images\necho \"[$(date --utc -Ins)] End remote\"","environment":{"container":"build","image":"oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f"}},{"annotations":null,"arguments":["--additional-base-images"],"entryPoint":"#!/bin/bash\nset -euo pipefail\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\necho \"[$(date --utc -Ins)] Prepare SBOM\"\n\nif [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM generation\"\n exit 0\nfi\n\n# Convert Tekton array params into Mobster params\nADDITIONAL_BASE_IMAGES=()\nwhile [[ $# -gt 0 ]]; do\n case $1 in\n --additional-base-images)\n shift\n while [[ $# -gt 0 && $1 != --* ]]; do\n ADDITIONAL_BASE_IMAGES+=(\"$1\")\n shift\n done\n ;;\n *)\n echo \"unexpected argument: $1\" >&2\n exit 2\n ;;\n esac\ndone\n\nIMAGE_URL=\"$(cat \"/tekton/results/IMAGE_URL\")\"\nIMAGE_DIGEST=\"$(cat \"/tekton/results/IMAGE_DIGEST\")\"\n\necho \"[$(date --utc -Ins)] Generate SBOM with mobster\"\n\nmobster_args=(\n generate\n --output sbom.json\n)\n\n# Validation is a flag for `generate`, not `oci-image`, so we need to\n# handle it before the oci-image arguments\nif [ \"${SBOM_SKIP_VALIDATION}\" == \"true\" ]; then\n echo \"Skipping SBOM validation\"\n mobster_args+=(--skip-validation)\nfi\n\nmobster_args+=(\n oci-image\n --from-syft /shared/sbom-image.json\n --image-pullspec \"$IMAGE_URL\"\n --image-digest \"$IMAGE_DIGEST\"\n --parsed-dockerfile-path \"/shared/parsed_dockerfile.json\"\n --base-image-digest-file \"/shared/base_images_digests\"\n)\n\n# Add metadata to the Mobster args if provided\nmetadata_path=\"/shared/buildprobe-metadata.yaml\"\nbuilder_metadata_path=\"/shared/builder-metadata.json\"\nif [ -f \"$metadata_path\" ]; then\n mobster_args+=(--metadata-path \"$metadata_path\")\nfi\nif [ -f \"$builder_metadata_path\" ]; then\n mobster_args+=(--build-metadata-path \"$builder_metadata_path\")\nfi\n\nif [ -f /shared/sbom-source.json ]; then\n mobster_args+=(--from-syft /shared/sbom-source.json)\nfi\n\nif [ -f /shared/sbom-prefetch.json ]; then\n mobster_args+=(--from-hermeto /shared/sbom-prefetch.json)\nfi\n\nif [ -n \"${TARGET_STAGE}\" ]; then\n mobster_args+=(--dockerfile-target \"${TARGET_STAGE}\")\nfi\n\nfor ADDITIONAL_BASE_IMAGE in \"${ADDITIONAL_BASE_IMAGES[@]}\"; do\n mobster_args+=(--additional-base-image \"$ADDITIONAL_BASE_IMAGE\")\ndone\n\nif [ \"${CONTEXTUALIZE_SBOM}\" == \"true\" ] && [ \"${HERMETIC}\" == \"false\" ]; then\n mobster_args+=(--contextualize)\nfi\n\nif [ -f \"/shared/prefetch-arch\" ]; then\n mobster_args+=(--arch \"$(cat /shared/prefetch-arch)\")\nfi\n\nmobster \"${mobster_args[@]}\"\n\necho \"[$(date --utc -Ins)] End prepare-sboms\"\n","environment":{"container":"prepare-sboms","image":"oci://quay.io/konflux-ci/mobster@sha256:3eee4ecf87d50cb073318ab96097b9ea2cb6e5e59dd296a212e57017a9059f61"}},{"annotations":null,"arguments":null,"entryPoint":"#!/bin/bash\nset -euo pipefail\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nIMAGE_REF=$(cat \"/tekton/results/IMAGE_REF\")\n\n# Pre-select the correct credentials to work around cosign not supporting the containers-auth.json spec\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_REF\" >/tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\n# --- SBOM upload ---\nif [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM push because SBOM generation is disabled\"\nelse\n echo \"[$(date --utc -Ins)] Upload SBOM\"\n echo \"Pushing sbom to registry\"\n if ! retry cosign attach sbom --sbom sbom.json --type \"$SBOM_TYPE\" \"$IMAGE_REF\"; then\n echo \"Failed to push sbom to registry\"\n exit 1\n fi\n\n # Remove tag from IMAGE while allowing registry to contain a port number.\n sbom_repo=\"${IMAGE%:*}\"\n sbom_digest=\"$(sha256sum sbom.json | cut -d' ' -f1)\"\n # The SBOM_BLOB_URL is created by `cosign attach sbom`.\n echo -n \"${sbom_repo}@sha256:${sbom_digest}\" | tee \"/tekton/results/SBOM_BLOB_URL\"\nfi\n\necho\necho \"[$(date --utc -Ins)] Handle keyless signing if enabled\"\n\n# --- keyless signing ---\n# detect if keyless signing is required\nSIGNING_CONFIG='{}'\nKFLX_CONFIG_PATH='/tmp/konflux_config.json'\nif ! RETRY_STOP_IF_STDERR_MATCHES='configmaps \"cluster-config\" not found' retry kubectl get configmap cluster-config -n konflux-info -o json >\"${KFLX_CONFIG_PATH}\"; then\n echo \"Failed to fetch konflux cluster-config, default values will be used\" >&2\nelse\n SIGNING_CONFIG=\"$(cat ${KFLX_CONFIG_PATH})\"\nfi\n\n# configmap key -> variable name mapping\ndeclare -A SIGNING_KEY_MAP=(\n [defaultOIDCIssuer]=SIGSTORE_OIDC_ISSUER\n [rekorInternalUrl]=REKOR_URL\n [fulcioInternalUrl]=SIGSTORE_FULCIO_URL\n [tufInternalUrl]=TUF_URL\n)\n\n# fallback keys when internal URL is not available\ndeclare -A SIGNING_FALLBACK_MAP=(\n [rekorInternalUrl]=rekorExternalUrl\n [fulcioInternalUrl]=fulcioExternalUrl\n [tufInternalUrl]=tufExternalUrl\n)\n\nmissing=\"\"\nconfigured=0\nfor key in \"${!SIGNING_KEY_MAP[@]}\"; do\n val=$(echo \"${SIGNING_CONFIG}\" | jq -r \".data.${key} // empty\")\n if [ -z \"${val}\" ] && [ -n \"${SIGNING_FALLBACK_MAP[$key]+x}\" ]; then\n fallback_key=\"${SIGNING_FALLBACK_MAP[$key]}\"\n val=$(echo \"${SIGNING_CONFIG}\" | jq -r \".data.${fallback_key} // empty\")\n if [ -n \"${val}\" ]; then\n echo \"Using fallback ${fallback_key} instead of ${key}\"\n fi\n fi\n if [ -z \"${val}\" ]; then\n missing=\"${missing:+${missing}, }${key}\"\n else\n declare \"${SIGNING_KEY_MAP[$key]}=${val}\"\n configured=$((configured + 1))\n fi\ndone\n\nif [ \"${configured}\" -eq 0 ]; then\n echo \"Keyless signing is disabled (none of ${missing} are configured in the konflux-info/cluster-config configmap)\"\nelif [ \"${configured}\" -ne \"${#SIGNING_KEY_MAP[@]}\" ]; then\n echo \"ERROR: Incomplete keyless signing configuration in konflux-info/cluster-config configmap. Missing: ${missing}\" >&2\n exit 1\nelse\n echo \"Keyless signing is enabled\"\n\n echo \"Using Rekor URL: ${REKOR_URL}\"\n echo \"Using Fulcio URL: ${SIGSTORE_FULCIO_URL}\"\n echo \"Using OIDC issuer: ${SIGSTORE_OIDC_ISSUER}\"\n\n echo \"Initializing TUF root from ${TUF_URL}\"\n if ! retry cosign initialize --root \"${TUF_URL}/root.json\" --mirror \"${TUF_URL}\"; then\n echo \"Failed to initialize TUF root\" >&2\n exit 1\n fi\n\n # env var consumed by cosign\n SIGSTORE_ID_TOKEN=\"$(cat /var/run/sigstore/cosign/oidc-token)\"\n export SIGSTORE_ID_TOKEN\n\n echo \"[$(date --utc -Ins)] Sign image\"\n echo \"Signing image ${IMAGE_REF} using keyless signing\"\n if ! retry cosign sign -y \\\n --use-signing-config=false \\\n --rekor-url=\"${REKOR_URL}\" \\\n --fulcio-url=\"${SIGSTORE_FULCIO_URL}\" \\\n --oidc-issuer=\"${SIGSTORE_OIDC_ISSUER}\" \\\n \"${IMAGE_REF}\"; then\n echo \"Failed to sign image\" >&2\n exit 1\n fi\n\n if [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM signing because SBOM generation is disabled\"\n else\n ATT_SBOM_TYPE=\"${SBOM_TYPE}\"\n if [ \"${ATT_SBOM_TYPE}\" = \"spdx\" ]; then\n # for format cossistency with cyclonedx format, we want to use spdxjson instad of spdx\n # spdx export data as rawstring, we want structured json as cyclonedx\n ATT_SBOM_TYPE=\"spdxjson\"\n fi\n\n echo \"[$(date --utc -Ins)] Sign SBOM\"\n echo \"Signing and attaching SBOM to ${IMAGE_REF} using keyless signing\"\n if ! retry cosign attest -y --type \"${ATT_SBOM_TYPE}\" --predicate sbom.json \\\n --use-signing-config=false \\\n --rekor-url=\"${REKOR_URL}\" \\\n --fulcio-url=\"${SIGSTORE_FULCIO_URL}\" \\\n --oidc-issuer=\"${SIGSTORE_OIDC_ISSUER}\" \\\n \"${IMAGE_REF}\"; then\n echo \"Failed to sign SBOM\" >&2\n exit 1\n fi\n fi\nfi\n\necho\necho \"[$(date --utc -Ins)] End upload-sbom\"\n","environment":{"container":"upload-sbom","image":"oci://quay.io/konflux-ci/task-runner@sha256:4b01fbf98fa7155f5c21443c285f88853864ae7cc66981cf6b543fc6ba16b81b"}}]},{"after":["prefetch-dependencies","clone-repository","rhoai-init"],"finishedOn":"2026-09-08T21:25:59Z","invocation":{"configSource":{"digest":{"sha256":"ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344"},"entryPoint":"buildah-remote-oci-ta","uri":"quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/allocation-start-time":"1788902512","build.appstudio.redhat.com/cloud-address":"10.29.77.101","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/52195ac0-10ef-431f-b492-c48b518ad346","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"image-build, konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-1bf796cedfd19738-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","build.appstudio.redhat.com/build_type":"docker","build.appstudio.redhat.com/cloud-dynamic-platform":"linux-m2xlarge-arm64","build.appstudio.redhat.com/target-platform":"linux-m2xlarge-arm64","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"build-images","tekton.dev/task":"buildah-remote-oci-ta"}},"parameters":{"ACTIVATION_KEY":"custom-activation-key","ADDITIONAL_BASE_IMAGES":[],"ADDITIONAL_SECRET":"does-not-exist","ADD_CAPABILITIES":"","ALLOW_CROSS_PLATFORM_IMAGES":"false","ANNOTATIONS":[],"ANNOTATIONS_FILE":"","BUILDAH_FORMAT":"docker","BUILD_ARGS":[],"BUILD_ARGS_FILE":"","BUILD_TIMESTAMP":"","CACHI2_ARTIFACT":"","COMMIT_SHA":"58e7f0f6d889933345394152903c95c62e6bd9c3","CONTEXT":".","CONTEXTUALIZE_SBOM":"false","DOCKERFILE":"Dockerfiles/agent.Dockerfile.konflux","ENTITLEMENT_SECRET":"etc-pki-entitlement","ENV_VARS":[],"HERMETIC":"false","HTTP_PROXY":"","ICM_KEEP_COMPAT_LOCATION":"true","IMAGE":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","IMAGE_APPEND_PLATFORM":"true","IMAGE_EXPIRES_AFTER":"","INHERIT_BASE_IMAGE_LABELS":"true","LABELS":["version=v2.25.11","url=https://github.com/red-hat-data-services/kserve","release=1788902446","git.url=https://github.com/red-hat-data-services/kserve","git.commit=58e7f0f6d889933345394152903c95c62e6bd9c3","cpe=","name=rhoai/odh-kserve-agent-rhel9","io.openshift.tags=odh-kserve-agent","com.redhat.component=odh-kserve-agent-rhel9","summary=ODH Kserve Agent","description=ODH Kserve Agent","io.k8s.display-name=ODH Kserve Agent","io.k8s.description=ODH Kserve Agent","vendor=Red Hat, Inc.","maintainer=RHOAI DevTestOps Team [openshift-ai-devtestops@redhat.com]"],"LOG_LEVEL":"info","NO_PROXY":"","OMIT_HISTORY":"false","PLATFORM":"linux-m2xlarge/arm64","PREFETCH_INPUT":"","PRIVILEGED_NESTED":"false","PROXY_CA_TRUST_CONFIG_MAP_KEY":"ca-bundle.crt","PROXY_CA_TRUST_CONFIG_MAP_NAME":"caching-ca-bundle","REWRITE_TIMESTAMP":"false","RHSM_MOUNT_CA_CERTS":"auto","SBOM_SKIP_VALIDATION":"true","SBOM_SOURCE_SCAN_ENABLED":"true","SBOM_SYFT_SELECT_CATALOGERS":"","SBOM_TYPE":"spdx","SKIP_INJECTIONS":"false","SKIP_SBOM_GENERATION":"false","SKIP_UNUSED_STAGES":"true","SOURCE_ARTIFACT":"oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735","SOURCE_DATE_EPOCH":"","SOURCE_URL":"","SQUASH":"false","STORAGE_DRIVER":"overlay","TARGET_STAGE":"","TLSVERIFY":"true","WORKINGDIR_MOUNT":"","YUM_REPOS_D_FETCHED":"fetched.repos.d","YUM_REPOS_D_SRC":"repos.d","YUM_REPOS_D_TARGET":"/etc/yum.repos.d","caTrustConfigMapKey":"ca-bundle.crt","caTrustConfigMapName":"trusted-ca"}},"name":"build-images","ref":{"params":[{"name":"name","value":"buildah-remote-oci-ta"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.12.1@sha256:ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"IMAGE_DIGEST","type":"string","value":"sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35"},{"name":"IMAGE_REF","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-m2xlarge-arm64@sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35"},{"name":"IMAGE_URL","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-m2xlarge-arm64"},{"name":"SBOM_BLOB_URL","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9@sha256:bc3679d864ec2aa6153470406486c4eed14351b4dc6e5c6931a19a6c8607c4eb"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:21:50Z","status":"Succeeded","steps":[{"annotations":null,"arguments":["use","oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source","=/var/workdir/cachi2"],"entryPoint":"","environment":{"container":"use-trusted-artifact","image":"oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c"}},{"annotations":null,"arguments":["--build-args","--envs","--labels","version=v2.25.11","url=https://github.com/red-hat-data-services/kserve","release=1788902446","git.url=https://github.com/red-hat-data-services/kserve","git.commit=58e7f0f6d889933345394152903c95c62e6bd9c3","cpe=","name=rhoai/odh-kserve-agent-rhel9","io.openshift.tags=odh-kserve-agent","com.redhat.component=odh-kserve-agent-rhel9","summary=ODH Kserve Agent","description=ODH Kserve Agent","io.k8s.display-name=ODH Kserve Agent","io.k8s.description=ODH Kserve Agent","vendor=Red Hat, Inc.","maintainer=RHOAI DevTestOps Team [openshift-ai-devtestops@redhat.com]","--annotations"],"entryPoint":"#!/bin/bash\nset -e\nset -o verbose\n\necho \"[$(date --utc -Ins)] Prepare connection\"\n\nmkdir -p ~/.ssh\nif [ -e \"/ssh/error\" ]; then\n #no server could be provisioned\n cat /ssh/error\n exit 1\nfi\n\nSSH_HOST=$(cat /ssh/host)\nexport SSH_HOST\n\nif [ \"$SSH_HOST\" == \"localhost\" ] ; then\n IS_LOCALHOST=true\n echo \"Localhost detected; running build in cluster\"\nelif [ -e \"/ssh/otp\" ]; then\n if ! curl --fail --cacert /ssh/otp-ca -XPOST -d @/ssh/otp \"$(cat /ssh/otp-server)\" >~/.ssh/id_rsa; then\n echo \"Failed to retrieve SSH key from the OTP server. This can happen when the PipelineRun retry option re-runs a task whose one-time credential was already consumed. Please, start a new build, and if problem persists, please report it as an MPC bug.\" >&2\n exit 1\n fi\n echo \"\" >> ~/.ssh/id_rsa\nelse\n cp /ssh/id_rsa ~/.ssh\nfi\n\nmkdir -p scripts\n\nif ! [[ $IS_LOCALHOST ]]; then\n echo \"[$(date --utc -Ins)] Setup VM\"\n\n if [[ \"$BUILDAH_HTTP_PROXY\" =~ .+\\.cluster\\.local ]]; then\n echo \"[$(date --utc -Ins)] Ignoring cluster local proxy for remote build\"\n unset BUILDAH_HTTP_PROXY BUILDAH_NO_PROXY\n fi\n\n chmod 0400 ~/.ssh/id_rsa\n BUILD_DIR=$(cat /ssh/user-dir)\n export BUILD_DIR\n export SSH_ARGS=\"-o StrictHostKeyChecking=no -o ServerAliveInterval=60 -o ServerAliveCountMax=10\"\n echo \"$BUILD_DIR\"\n # shellcheck disable=SC2086\n ssh $SSH_ARGS \"$SSH_HOST\" mkdir -p \"${BUILD_DIR@Q}/workspaces\" \"${BUILD_DIR@Q}/scripts\" \"${BUILD_DIR@Q}/volumes\"\n\n PORT_FORWARD=\"\"\n PODMAN_PORT_FORWARD=\"\"\n if [ -n \"$JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR\" ] ; then\n PORT_FORWARD=\" -L 80:$JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR:80\"\n PODMAN_PORT_FORWARD=\" -e JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR=localhost\"\n fi\n\n echo \"[$(date --utc -Ins)] Rsync data\"\n\n rsync --timeout=300 -razW /shared/ \"$SSH_HOST:$BUILD_DIR/volumes/shared/\"\n rsync --timeout=300 -razW /var/workdir/ \"$SSH_HOST:$BUILD_DIR/volumes/workdir/\"\n rsync --timeout=300 -razW /entitlement/ \"$SSH_HOST:$BUILD_DIR/volumes/etc-pki-entitlement/\"\n rsync --timeout=300 -razW /activation-key/ \"$SSH_HOST:$BUILD_DIR/volumes/activation-key/\"\n rsync --timeout=300 -razW /additional-secret/ \"$SSH_HOST:$BUILD_DIR/volumes/additional-secret/\"\n rsync --timeout=300 -razW /mnt/trusted-ca/ \"$SSH_HOST:$BUILD_DIR/volumes/trusted-ca/\"\n rsync --timeout=300 -razW /mnt/proxy-ca-bundle/ \"$SSH_HOST:$BUILD_DIR/volumes/proxy-ca-bundle/\"\n rsync --timeout=300 -razW \"$HOME/.docker/\" \"$SSH_HOST:$BUILD_DIR/.docker/\"\n rsync --timeout=300 -razW \"/tekton/results/\" \"$SSH_HOST:$BUILD_DIR/results/\"\nfi\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\ncat >scripts/script-build.sh <<'REMOTESSHEOF'\n#!/bin/bash\nset -euo pipefail\ncd /var/workdir\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nproxy_ca_bundle=/mnt/proxy-ca-bundle/ca-bundle.crt\nupdate_ca_trust=false\n\nif [ -f \"$ca_bundle\" ]; then\n echo \"[$(date --utc -Ins)] Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors/ca-bundle.crt\n update_ca_trust=true\nfi\n\nif [ -f \"$proxy_ca_bundle\" ] && [ -n \"${BUILDAH_HTTP_PROXY}\" ]; then\n echo \"[$(date --utc -Ins)] Using mounted proxy CA bundle: $proxy_ca_bundle\"\n cp -vf $proxy_ca_bundle /etc/pki/ca-trust/source/anchors/proxy-ca-bundle.crt\n update_ca_trust=true\nfi\n\nif [ \"$update_ca_trust\" = \"true\" ]; then\n echo \"[$(date --utc -Ins)] Update CA trust\"\n update-ca-trust\nfi\n\necho \"[$(date --utc -Ins)] Prepare system (architecture: $(uname -m))\"\n\n# Fixing group permission on /var/lib/containers\nchown root:root /var/lib/containers\n\nsed -i 's/^\\s*short-name-mode\\s*=\\s*.*/short-name-mode = \"disabled\"/' /etc/containers/registries.conf\n\n# Delete policy settings for Red Hat registries to disable signature verification.\n# TODO: don't do this?\ncontainer_policy=$(\n jq '.transports |= (\n del(.docker.[\"registry.access.redhat.com\"]) |\n del(.docker.[\"registry.redhat.io\"]) |\n if (.docker == {}) then del(.docker) else . end\n )' /etc/containers/policy.json\n)\necho \"Effective container policy:\"\nprintf '%s\\n' \"$container_policy\" | tee /etc/containers/policy.json\n\n# Setting new namespace to run buildah - 2^32-2\necho 'root:1:4294967294' | tee -a /etc/subuid >>/etc/subgid\n\necho \"[$(date --utc -Ins)] Run the build\"\n\nif [ -e \"$SOURCE_CODE_DIR/$CONTEXT/$DOCKERFILE\" ]; then\n dockerfile_path=\"$(pwd)/$SOURCE_CODE_DIR/$CONTEXT/$DOCKERFILE\"\nelif [ -e \"$SOURCE_CODE_DIR/$DOCKERFILE\" ]; then\n dockerfile_path=\"$(pwd)/$SOURCE_CODE_DIR/$DOCKERFILE\"\nelse\n echo \"Cannot find Dockerfile $DOCKERFILE\"\n exit 1\nfi\n\nif [ -n \"${ANNOTATIONS_FILE}\" ] && [ -f \"${SOURCE_CODE_DIR}/${ANNOTATIONS_FILE}\" ]; then\n ANNOTATIONS_FILE=$(realpath \"${SOURCE_CODE_DIR}/${ANNOTATIONS_FILE}\")\nfi\n\nif [ -n \"${BUILD_ARGS_FILE}\" ]; then\n BUILD_ARGS_FILE=$(realpath \"${SOURCE_CODE_DIR}/${BUILD_ARGS_FILE}\")\nfi\n\n# Necessary for newer version of buildah if the host system does not contain up to date version of container-selinux\n# TODO remove the option once all hosts were updated\nsecurity_args=(--security-opts unmask=/proc/interrupts)\n\nif [ \"${PRIVILEGED_NESTED}\" == \"true\" ]; then\n security_args+=(--security-opts label=disable)\n security_args+=(--cap-add all)\n security_args+=(--devices /dev/fuse)\nfi\nif [ -n \"${ADD_CAPABILITIES}\" ]; then\n security_args+=(--cap-add \"${ADD_CAPABILITIES}\")\nfi\n\nif [ -f \"/var/workdir/cachi2/cachi2.env\" ]; then\n prefetch_dir=\"/var/workdir/cachi2\"\n # KBC defaults to ${prefetch_dir}/copy-*\n # Copy to a sibling dir instead in case we don't have write permissions to the prefetch_dir.\n # It's still on the same filesystem, so copying via reflinks should be possible.\n prefetch_dir_copy=\"/var/workdir/prefetch-copy\"\n # Save the build machine's architecture to pass to Mobster later\n uname -m >/shared/prefetch-arch\nelse\n prefetch_dir=\"\"\n prefetch_dir_copy=\"\"\nfi\n\nyum_repos_d_sources=()\nif [ -d \"${YUM_REPOS_D_FETCHED}\" ]; then\n yum_repos_d_sources+=(\"${YUM_REPOS_D_FETCHED}\")\nfi\nif [ -d \"${SOURCE_CODE_DIR}/${YUM_REPOS_D_SRC}\" ]; then\n yum_repos_d_sources+=(\"${SOURCE_CODE_DIR}/${YUM_REPOS_D_SRC}\")\nfi\n\n# 0. if hermetic=true, skip all subscription related stuff\n# 1. do not enable activation key and entitlement at same time. If both are provided, prefer activation key.\n# 2. Activation-keys will be used when the key 'org' exists in the activation key secret.\n# 3. try to pre-register and mount files to the correct location so that users do no need to modify Dockerfiles.\n# 4. If the Dockerfile contains the string \"subcription-manager register\", add the activation-keys volume\n# to buildah but don't pre-register for backwards compatibility. Mount an empty directory on\n# to \"/etc/pki/entitlement\" to prevent certificates from being included\nrhsm_args=()\nif [ \"${HERMETIC}\" != \"true\" ]; then\n if [ -e /activation-key/org ]; then\n rhsm_args+=(--rhsm-activation-key=/activation-key/activationkey\n --rhsm-org=/activation-key/org\n --rhsm-activation-mount=/activation-key)\n\n if ! grep -E \"^[^#]*subscription-manager.[^#]*register\" \"$dockerfile_path\"; then\n # user is not running registration in the Containerfile: pre-register.\n rhsm_args+=(--rhsm-activation-preregister)\n fi\n elif find /entitlement -name \"*.pem\" >/dev/null; then\n rhsm_args+=(--rhsm-entitlements=/entitlement)\n fi\nfi\nif [ \"${RHSM_MOUNT_CA_CERTS}\" != \"auto\" ]; then\n rhsm_args+=(--rhsm-mount-ca-certs=\"$RHSM_MOUNT_CA_CERTS\")\nfi\n\nsbom_args=()\nif [[ \"$SKIP_SBOM_GENERATION\" != true ]]; then\n sbom_args+=(\n --sbom-format \"$SBOM_TYPE\"\n --syft-select-catalogers \"$SBOM_SYFT_SELECT_CATALOGERS\"\n --syft-image-output /shared/sbom-image.json\n )\n if [[ \"${HERMETIC}\" == \"false\" && \"${SBOM_SOURCE_SCAN_ENABLED}\" == \"true\" ]]; then\n sbom_args+=(--syft-source-output /shared/sbom-source.json)\n fi\n if [ \"${CONTEXTUALIZE_SBOM}\" == \"true\" ]; then\n sbom_args+=(\n --builder-metadata-output=/shared/builder-metadata.json\n --buildprobe-output=/shared/buildprobe-metadata.yaml\n )\n fi\nfi\n\n# Prevent ShellCheck from giving a warning because 'image' is defined and 'IMAGE' is not.\ndeclare IMAGE\n\ncmd=(\n konflux-build-cli image build\n -f \"$dockerfile_path\" -t \"$IMAGE\" --source \"$SOURCE_CODE_DIR\" --context \"$CONTEXT\"\n # use the taskRun name as a unique tag to prevent the $IMAGE from being garbage collected\n # if another build pushes to the same $IMAGE output ref\n --additional-tags \"$TASKRUN_NAME\"\n --push\n --push-format \"$PUSH_FORMAT\"\n --secret-dirs \"src=/additional-secret,name=$ADDITIONAL_SECRET,optional=true\"\n --workdir-mount \"$WORKINGDIR_MOUNT\"\n --target \"$TARGET_STAGE\"\n --inherit-labels=\"$INHERIT_BASE_IMAGE_LABELS\"\n --source-date-epoch \"$BUILDAH_SOURCE_DATE_EPOCH\"\n --rewrite-timestamp=\"$BUILDAH_REWRITE_TIMESTAMP\"\n --squash=\"$SQUASH\"\n --omit-history=\"$BUILDAH_OMIT_HISTORY\"\n --image-source \"$SOURCE_URL\"\n --image-revision \"$COMMIT_SHA\"\n --quay-image-expires-after \"$IMAGE_EXPIRES_AFTER\"\n --build-args-file \"$BUILD_ARGS_FILE\"\n --annotations-file \"$ANNOTATIONS_FILE\"\n --legacy-build-timestamp \"$BUILD_TIMESTAMP\"\n --add-legacy-labels\n --include-legacy-buildinfo-path=\"$ICM_KEEP_COMPAT_LOCATION\"\n --skip-injections=\"$SKIP_INJECTIONS\"\n --skip-unused-stages=\"$SKIP_UNUSED_STAGES\"\n --hermetic=\"$HERMETIC\"\n --image-pull-proxy \"$BUILDAH_HTTP_PROXY\"\n --image-pull-noproxy \"$BUILDAH_NO_PROXY\"\n --yum-repos-d-sources \"${yum_repos_d_sources[@]}\"\n --yum-repos-d-target \"$YUM_REPOS_D_TARGET\"\n --prefetch-dir \"$prefetch_dir\"\n --prefetch-dir-copy \"$prefetch_dir_copy\"\n --prefetch-env-mount /cachi2/cachi2.env\n --prefetch-output-mount /cachi2/output\n \"${security_args[@]}\"\n \"${rhsm_args[@]}\"\n \"${sbom_args[@]}\"\n --containerfile-json-output /shared/parsed_dockerfile.json\n --resolved-base-images-output /shared/base_images_digests\n --no-cache\n --ulimits nofile=4096:4096\n --src-tls-verify=\"$TLSVERIFY\"\n --dest-tls-verify=\"$TLSVERIFY\"\n --allow-cross-platform-images=\"$ALLOW_CROSS_PLATFORM_IMAGES\"\n \"$@\" # --annotations, --labels, --envs, --build-args\n)\n\necho \"[$(date --utc -Ins)] $(printf '%q ' \"${cmd[@]}\")\"\n\n\"${cmd[@]}\" | tee /tmp/results.json\n\njq -j .image_url /tmp/results.json >\"/tekton/results/IMAGE_URL\"\njq -j .digest /tmp/results.json >\"/tekton/results/IMAGE_DIGEST\"\njq -j '\"\\(.image_url)@\\(.digest)\"' /tmp/results.json >\"/tekton/results/IMAGE_REF\"\n\necho\necho \"[$(date --utc -Ins)] Add metadata\"\n\n# Save the SBOM produced in prefetch so it can be merged into the final SBOM later\nif [ -f \"${prefetch_dir}/output/bom.json\" ]; then\n echo \"Making copy of sbom-prefetch.json\"\n cp \"${prefetch_dir}/output/bom.json\" /shared/sbom-prefetch.json\nfi\n\necho \"[$(date --utc -Ins)] End build\"\n\nREMOTESSHEOF\nchmod +x scripts/script-build.sh\n\nPODMAN_NVIDIA_ARGS=()\nif [[ \"$PLATFORM\" == \"linux-g\"* ]]; then\n PODMAN_NVIDIA_ARGS+=(\"--device=nvidia.com/gpu=all\" \"--security-opt=label=disable\")\nfi\n\nif ! [[ $IS_LOCALHOST ]]; then\n PRIVILEGED_NESTED_FLAGS=()\n if [[ \"${PRIVILEGED_NESTED}\" == \"true\" ]]; then\n # This is a workaround for building bootc images because the cache filesystem (/var/tmp/ on the host) must be a real filesystem that supports setting SELinux security attributes.\n # https://github.com/coreos/rpm-ostree/discussions/4648\n # shellcheck disable=SC2086\n ssh $SSH_ARGS \"$SSH_HOST\" mkdir -p \"${BUILD_DIR@Q}/var/tmp\"\n PRIVILEGED_NESTED_FLAGS=(--privileged --mount \"type=bind,source=$BUILD_DIR/var/tmp,target=/var/tmp,relabel=shared\")\n fi\n rsync --timeout=300 -ra scripts \"$SSH_HOST:$BUILD_DIR\"\n echo \"[$(date --utc -Ins)] Build via ssh\"\n # shellcheck disable=SC2086\n # Please note: all variables below the first ssh line must be quoted with ${var@Q}!\n # See https://stackoverflow.com/questions/6592376/prevent-ssh-from-breaking-up-shell-script-parameters\n ssh $SSH_ARGS \"$SSH_HOST\" $PORT_FORWARD podman run $PODMAN_PORT_FORWARD \\\n --tmpfs /run/secrets \\\n -e ADDITIONAL_SECRET=\"${ADDITIONAL_SECRET@Q}\" \\\n -e ADD_CAPABILITIES=\"${ADD_CAPABILITIES@Q}\" \\\n -e ALLOW_CROSS_PLATFORM_IMAGES=\"${ALLOW_CROSS_PLATFORM_IMAGES@Q}\" \\\n -e ANNOTATIONS_FILE=\"${ANNOTATIONS_FILE@Q}\" \\\n -e BUILD_ARGS_FILE=\"${BUILD_ARGS_FILE@Q}\" \\\n -e BUILD_TIMESTAMP=\"${BUILD_TIMESTAMP@Q}\" \\\n -e CONTEXT=\"${CONTEXT@Q}\" \\\n -e CONTEXTUALIZE_SBOM=\"${CONTEXTUALIZE_SBOM@Q}\" \\\n -e HERMETIC=\"${HERMETIC@Q}\" \\\n -e IMAGE=\"${IMAGE@Q}\" \\\n -e IMAGE_EXPIRES_AFTER=\"${IMAGE_EXPIRES_AFTER@Q}\" \\\n -e INHERIT_BASE_IMAGE_LABELS=\"${INHERIT_BASE_IMAGE_LABELS@Q}\" \\\n -e KBC_LOG_LEVEL=\"${KBC_LOG_LEVEL@Q}\" \\\n -e PRIVILEGED_NESTED=\"${PRIVILEGED_NESTED@Q}\" \\\n -e PUSH_FORMAT=\"${PUSH_FORMAT@Q}\" \\\n -e RHSM_MOUNT_CA_CERTS=\"${RHSM_MOUNT_CA_CERTS@Q}\" \\\n -e SBOM_SKIP_VALIDATION=\"${SBOM_SKIP_VALIDATION@Q}\" \\\n -e SBOM_SOURCE_SCAN_ENABLED=\"${SBOM_SOURCE_SCAN_ENABLED@Q}\" \\\n -e SBOM_SYFT_SELECT_CATALOGERS=\"${SBOM_SYFT_SELECT_CATALOGERS@Q}\" \\\n -e SBOM_TYPE=\"${SBOM_TYPE@Q}\" \\\n -e SKIP_INJECTIONS=\"${SKIP_INJECTIONS@Q}\" \\\n -e SKIP_SBOM_GENERATION=\"${SKIP_SBOM_GENERATION@Q}\" \\\n -e SKIP_UNUSED_STAGES=\"${SKIP_UNUSED_STAGES@Q}\" \\\n -e SOURCE_CODE_DIR=\"${SOURCE_CODE_DIR@Q}\" \\\n -e SQUASH=\"${SQUASH@Q}\" \\\n -e STORAGE_DRIVER=\"${STORAGE_DRIVER@Q}\" \\\n -e TARGET_STAGE=\"${TARGET_STAGE@Q}\" \\\n -e TASKRUN_NAME=\"${TASKRUN_NAME@Q}\" \\\n -e TLSVERIFY=\"${TLSVERIFY@Q}\" \\\n -e WORKINGDIR_MOUNT=\"${WORKINGDIR_MOUNT@Q}\" \\\n -e YUM_REPOS_D_FETCHED=\"${YUM_REPOS_D_FETCHED@Q}\" \\\n -e YUM_REPOS_D_SRC=\"${YUM_REPOS_D_SRC@Q}\" \\\n -e YUM_REPOS_D_TARGET=\"${YUM_REPOS_D_TARGET@Q}\" \\\n -e HOME=\"${HOME@Q}\" \\\n -e COMMIT_SHA=\"${COMMIT_SHA@Q}\" \\\n -e SOURCE_URL=\"${SOURCE_URL@Q}\" \\\n -e DOCKERFILE=\"${DOCKERFILE@Q}\" \\\n -e BUILDAH_HTTP_PROXY=\"${BUILDAH_HTTP_PROXY@Q}\" \\\n -e BUILDAH_NO_PROXY=\"${BUILDAH_NO_PROXY@Q}\" \\\n -e ICM_KEEP_COMPAT_LOCATION=\"${ICM_KEEP_COMPAT_LOCATION@Q}\" \\\n -e BUILDAH_OMIT_HISTORY=\"${BUILDAH_OMIT_HISTORY@Q}\" \\\n -e BUILDAH_SOURCE_DATE_EPOCH=\"${BUILDAH_SOURCE_DATE_EPOCH@Q}\" \\\n -e BUILDAH_REWRITE_TIMESTAMP=\"${BUILDAH_REWRITE_TIMESTAMP@Q}\" \\\n -v \"${BUILD_DIR@Q}/volumes/shared:/shared:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/workdir:/var/workdir:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/etc-pki-entitlement:/entitlement:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/activation-key:/activation-key:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/additional-secret:/additional-secret:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/trusted-ca:/mnt/trusted-ca:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/proxy-ca-bundle:/mnt/proxy-ca-bundle:Z\" \\\n -v \"${BUILD_DIR@Q}/.docker/:/root/.docker:Z\" \\\n -v \"${BUILD_DIR@Q}/results/:/tekton/results:Z\" \\\n -v \"${BUILD_DIR@Q}/scripts:/scripts:Z\" \\\n -v /var/lib/containers \\\n \"${PRIVILEGED_NESTED_FLAGS[@]@Q}\" \\\n --user=0 \"${PODMAN_NVIDIA_ARGS[@]@Q}\" --rm --entrypoint='' \"${BUILDER_IMAGE@Q}\" /scripts/script-build.sh \"${@@Q}\"\n echo \"[$(date --utc -Ins)] Rsync back\"\n rsync --timeout=300 -razW --stats \"$SSH_HOST:$BUILD_DIR/volumes/shared/\" /shared/\n rsync --timeout=300 -razW --stats \"$SSH_HOST:$BUILD_DIR/results/\" \"/tekton/results/\"\nelse\n bash scripts/script-build.sh \"$@\"\nfi\necho \"Build on remote host $SSH_HOST finished\"\n\necho \"[$(date --utc -Ins)] Final touches\"\n\nbuildah images\necho \"[$(date --utc -Ins)] End remote\"","environment":{"container":"build","image":"oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f"}},{"annotations":null,"arguments":["--additional-base-images"],"entryPoint":"#!/bin/bash\nset -euo pipefail\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\necho \"[$(date --utc -Ins)] Prepare SBOM\"\n\nif [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM generation\"\n exit 0\nfi\n\n# Convert Tekton array params into Mobster params\nADDITIONAL_BASE_IMAGES=()\nwhile [[ $# -gt 0 ]]; do\n case $1 in\n --additional-base-images)\n shift\n while [[ $# -gt 0 && $1 != --* ]]; do\n ADDITIONAL_BASE_IMAGES+=(\"$1\")\n shift\n done\n ;;\n *)\n echo \"unexpected argument: $1\" >&2\n exit 2\n ;;\n esac\ndone\n\nIMAGE_URL=\"$(cat \"/tekton/results/IMAGE_URL\")\"\nIMAGE_DIGEST=\"$(cat \"/tekton/results/IMAGE_DIGEST\")\"\n\necho \"[$(date --utc -Ins)] Generate SBOM with mobster\"\n\nmobster_args=(\n generate\n --output sbom.json\n)\n\n# Validation is a flag for `generate`, not `oci-image`, so we need to\n# handle it before the oci-image arguments\nif [ \"${SBOM_SKIP_VALIDATION}\" == \"true\" ]; then\n echo \"Skipping SBOM validation\"\n mobster_args+=(--skip-validation)\nfi\n\nmobster_args+=(\n oci-image\n --from-syft /shared/sbom-image.json\n --image-pullspec \"$IMAGE_URL\"\n --image-digest \"$IMAGE_DIGEST\"\n --parsed-dockerfile-path \"/shared/parsed_dockerfile.json\"\n --base-image-digest-file \"/shared/base_images_digests\"\n)\n\n# Add metadata to the Mobster args if provided\nmetadata_path=\"/shared/buildprobe-metadata.yaml\"\nbuilder_metadata_path=\"/shared/builder-metadata.json\"\nif [ -f \"$metadata_path\" ]; then\n mobster_args+=(--metadata-path \"$metadata_path\")\nfi\nif [ -f \"$builder_metadata_path\" ]; then\n mobster_args+=(--build-metadata-path \"$builder_metadata_path\")\nfi\n\nif [ -f /shared/sbom-source.json ]; then\n mobster_args+=(--from-syft /shared/sbom-source.json)\nfi\n\nif [ -f /shared/sbom-prefetch.json ]; then\n mobster_args+=(--from-hermeto /shared/sbom-prefetch.json)\nfi\n\nif [ -n \"${TARGET_STAGE}\" ]; then\n mobster_args+=(--dockerfile-target \"${TARGET_STAGE}\")\nfi\n\nfor ADDITIONAL_BASE_IMAGE in \"${ADDITIONAL_BASE_IMAGES[@]}\"; do\n mobster_args+=(--additional-base-image \"$ADDITIONAL_BASE_IMAGE\")\ndone\n\nif [ \"${CONTEXTUALIZE_SBOM}\" == \"true\" ] && [ \"${HERMETIC}\" == \"false\" ]; then\n mobster_args+=(--contextualize)\nfi\n\nif [ -f \"/shared/prefetch-arch\" ]; then\n mobster_args+=(--arch \"$(cat /shared/prefetch-arch)\")\nfi\n\nmobster \"${mobster_args[@]}\"\n\necho \"[$(date --utc -Ins)] End prepare-sboms\"\n","environment":{"container":"prepare-sboms","image":"oci://quay.io/konflux-ci/mobster@sha256:3eee4ecf87d50cb073318ab96097b9ea2cb6e5e59dd296a212e57017a9059f61"}},{"annotations":null,"arguments":null,"entryPoint":"#!/bin/bash\nset -euo pipefail\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nIMAGE_REF=$(cat \"/tekton/results/IMAGE_REF\")\n\n# Pre-select the correct credentials to work around cosign not supporting the containers-auth.json spec\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_REF\" >/tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\n# --- SBOM upload ---\nif [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM push because SBOM generation is disabled\"\nelse\n echo \"[$(date --utc -Ins)] Upload SBOM\"\n echo \"Pushing sbom to registry\"\n if ! retry cosign attach sbom --sbom sbom.json --type \"$SBOM_TYPE\" \"$IMAGE_REF\"; then\n echo \"Failed to push sbom to registry\"\n exit 1\n fi\n\n # Remove tag from IMAGE while allowing registry to contain a port number.\n sbom_repo=\"${IMAGE%:*}\"\n sbom_digest=\"$(sha256sum sbom.json | cut -d' ' -f1)\"\n # The SBOM_BLOB_URL is created by `cosign attach sbom`.\n echo -n \"${sbom_repo}@sha256:${sbom_digest}\" | tee \"/tekton/results/SBOM_BLOB_URL\"\nfi\n\necho\necho \"[$(date --utc -Ins)] Handle keyless signing if enabled\"\n\n# --- keyless signing ---\n# detect if keyless signing is required\nSIGNING_CONFIG='{}'\nKFLX_CONFIG_PATH='/tmp/konflux_config.json'\nif ! RETRY_STOP_IF_STDERR_MATCHES='configmaps \"cluster-config\" not found' retry kubectl get configmap cluster-config -n konflux-info -o json >\"${KFLX_CONFIG_PATH}\"; then\n echo \"Failed to fetch konflux cluster-config, default values will be used\" >&2\nelse\n SIGNING_CONFIG=\"$(cat ${KFLX_CONFIG_PATH})\"\nfi\n\n# configmap key -> variable name mapping\ndeclare -A SIGNING_KEY_MAP=(\n [defaultOIDCIssuer]=SIGSTORE_OIDC_ISSUER\n [rekorInternalUrl]=REKOR_URL\n [fulcioInternalUrl]=SIGSTORE_FULCIO_URL\n [tufInternalUrl]=TUF_URL\n)\n\n# fallback keys when internal URL is not available\ndeclare -A SIGNING_FALLBACK_MAP=(\n [rekorInternalUrl]=rekorExternalUrl\n [fulcioInternalUrl]=fulcioExternalUrl\n [tufInternalUrl]=tufExternalUrl\n)\n\nmissing=\"\"\nconfigured=0\nfor key in \"${!SIGNING_KEY_MAP[@]}\"; do\n val=$(echo \"${SIGNING_CONFIG}\" | jq -r \".data.${key} // empty\")\n if [ -z \"${val}\" ] && [ -n \"${SIGNING_FALLBACK_MAP[$key]+x}\" ]; then\n fallback_key=\"${SIGNING_FALLBACK_MAP[$key]}\"\n val=$(echo \"${SIGNING_CONFIG}\" | jq -r \".data.${fallback_key} // empty\")\n if [ -n \"${val}\" ]; then\n echo \"Using fallback ${fallback_key} instead of ${key}\"\n fi\n fi\n if [ -z \"${val}\" ]; then\n missing=\"${missing:+${missing}, }${key}\"\n else\n declare \"${SIGNING_KEY_MAP[$key]}=${val}\"\n configured=$((configured + 1))\n fi\ndone\n\nif [ \"${configured}\" -eq 0 ]; then\n echo \"Keyless signing is disabled (none of ${missing} are configured in the konflux-info/cluster-config configmap)\"\nelif [ \"${configured}\" -ne \"${#SIGNING_KEY_MAP[@]}\" ]; then\n echo \"ERROR: Incomplete keyless signing configuration in konflux-info/cluster-config configmap. Missing: ${missing}\" >&2\n exit 1\nelse\n echo \"Keyless signing is enabled\"\n\n echo \"Using Rekor URL: ${REKOR_URL}\"\n echo \"Using Fulcio URL: ${SIGSTORE_FULCIO_URL}\"\n echo \"Using OIDC issuer: ${SIGSTORE_OIDC_ISSUER}\"\n\n echo \"Initializing TUF root from ${TUF_URL}\"\n if ! retry cosign initialize --root \"${TUF_URL}/root.json\" --mirror \"${TUF_URL}\"; then\n echo \"Failed to initialize TUF root\" >&2\n exit 1\n fi\n\n # env var consumed by cosign\n SIGSTORE_ID_TOKEN=\"$(cat /var/run/sigstore/cosign/oidc-token)\"\n export SIGSTORE_ID_TOKEN\n\n echo \"[$(date --utc -Ins)] Sign image\"\n echo \"Signing image ${IMAGE_REF} using keyless signing\"\n if ! retry cosign sign -y \\\n --use-signing-config=false \\\n --rekor-url=\"${REKOR_URL}\" \\\n --fulcio-url=\"${SIGSTORE_FULCIO_URL}\" \\\n --oidc-issuer=\"${SIGSTORE_OIDC_ISSUER}\" \\\n \"${IMAGE_REF}\"; then\n echo \"Failed to sign image\" >&2\n exit 1\n fi\n\n if [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM signing because SBOM generation is disabled\"\n else\n ATT_SBOM_TYPE=\"${SBOM_TYPE}\"\n if [ \"${ATT_SBOM_TYPE}\" = \"spdx\" ]; then\n # for format cossistency with cyclonedx format, we want to use spdxjson instad of spdx\n # spdx export data as rawstring, we want structured json as cyclonedx\n ATT_SBOM_TYPE=\"spdxjson\"\n fi\n\n echo \"[$(date --utc -Ins)] Sign SBOM\"\n echo \"Signing and attaching SBOM to ${IMAGE_REF} using keyless signing\"\n if ! retry cosign attest -y --type \"${ATT_SBOM_TYPE}\" --predicate sbom.json \\\n --use-signing-config=false \\\n --rekor-url=\"${REKOR_URL}\" \\\n --fulcio-url=\"${SIGSTORE_FULCIO_URL}\" \\\n --oidc-issuer=\"${SIGSTORE_OIDC_ISSUER}\" \\\n \"${IMAGE_REF}\"; then\n echo \"Failed to sign SBOM\" >&2\n exit 1\n fi\n fi\nfi\n\necho\necho \"[$(date --utc -Ins)] End upload-sbom\"\n","environment":{"container":"upload-sbom","image":"oci://quay.io/konflux-ci/task-runner@sha256:4b01fbf98fa7155f5c21443c285f88853864ae7cc66981cf6b543fc6ba16b81b"}}]},{"after":["build-images"],"finishedOn":"2026-09-08T21:27:27Z","invocation":{"configSource":{"digest":{"sha256":"290c9ec319423ff9ae7b2cb78fa859e1d333abcdd2ef6c001533377812020071"},"entryPoint":"build-image-index","uri":"quay.io/konflux-ci/tekton-catalog/task-build-image-index"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/e195e5b0-7b0d-4835-856f-e89fd7f2710d","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"image-build, konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-f0fd55e6fc067488-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"build-image-index","tekton.dev/task":"build-image-index"}},"parameters":{"ALWAYS_BUILD_INDEX":"true","BUILDAH_FORMAT":"docker","IMAGE":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","IMAGES":["quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-x86-64@sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b","quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-ppc64le@sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75","quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-s390x@sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f","quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-m2xlarge-arm64@sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35"],"SBOM_SKIP_VALIDATION":"false","STORAGE_DRIVER":"vfs","TLSVERIFY":"true","caTrustConfigMapKey":"ca-bundle.crt","caTrustConfigMapName":"trusted-ca"}},"name":"build-image-index","ref":{"params":[{"name":"name","value":"build-image-index"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.3.1@sha256:290c9ec319423ff9ae7b2cb78fa859e1d333abcdd2ef6c001533377812020071"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"IMAGES","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9@sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b,quay.io/rhoai/odh-kserve-agent-rhel9@sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75,quay.io/rhoai/odh-kserve-agent-rhel9@sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f,quay.io/rhoai/odh-kserve-agent-rhel9@sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35"},{"name":"IMAGE_DIGEST","type":"string","value":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532"},{"name":"IMAGE_REF","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9@sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532"},{"name":"IMAGE_URL","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25"},{"name":"SBOM_BLOB_URL","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9@sha256:72450faa03d74b2804511cadca6f81db14fdd03e747d7643b53d813233fe3198"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:05Z","status":"Succeeded","steps":[{"annotations":null,"arguments":["quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-x86-64@sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b","quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-ppc64le@sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75","quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-s390x@sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f","quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-m2xlarge-arm64@sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35"],"entryPoint":"#!/bin/bash\n# Fixing group permission on /var/lib/containers\nset -eu\nset -o pipefail\nchown root:root /var/lib/containers\n\nsed -i 's/^\\s*short-name-mode\\s*=\\s*.*/short-name-mode = \"disabled\"/' /etc/containers/registries.conf\n\necho \"[$(date --utc -Ins)] Update CA trust\"\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nMANIFEST_DATA_FILE=\"/index-build-data/manifest_data.json\"\n\necho \"Running konflux-build-cli\"\nif ! konflux-build-cli image build-image-index \\\n --image \"$IMAGE\" \\\n --tls-verify=\"$TLSVERIFY\" \\\n --buildah-format \"$BUILDAH_FORMAT\" \\\n --always-build-index=\"$ALWAYS_BUILD_INDEX\" \\\n --additional-tags \"odh-kserve-agent-v2-25-on-push-xwfsp-build-image-index\" \\\n --output-manifest-path \"$MANIFEST_DATA_FILE\" \\\n --result-path-image-digest \"/tekton/results/IMAGE_DIGEST\" \\\n --result-path-image-url \"/tekton/results/IMAGE_URL\" \\\n --result-path-image-ref \"/tekton/results/IMAGE_REF\" \\\n --result-path-images \"/tekton/results/IMAGES\" \\\n --images \"$@\"; then\n echo \"Failed to build image index\"\n exit 1\nfi\n","environment":{"container":"build","image":"oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f"}},{"annotations":null,"arguments":null,"entryPoint":"#!/bin/bash\nset -e\n\nMANIFEST_DATA_FILE=\"/index-build-data/manifest_data.json\"\nif [ ! -f \"$MANIFEST_DATA_FILE\" ]; then\n echo \"The manifest_data.json file does not exist. Skipping the SBOM creation...\"\n exit 0\nfi\n\nIMAGE_URL=\"$(cat \"/tekton/results/IMAGE_URL\")\"\nIMAGE_DIGEST=\"$(cat \"/tekton/results/IMAGE_DIGEST\")\"\necho \"Creating SBOM result file...\"\nmobster_args=(generate --output /index-build-data/index.spdx.json)\n\nif [ \"${SBOM_SKIP_VALIDATION}\" == \"true\" ]; then\n echo \"Skipping SBOM validation\"\n mobster_args+=(--skip-validation)\nfi\n\nmobster_args+=(\n oci-index\n --index-image-pullspec \"$IMAGE_URL\"\n --index-image-digest \"$IMAGE_DIGEST\"\n --index-manifest-path \"$MANIFEST_DATA_FILE\"\n)\nmobster \"${mobster_args[@]}\"\n","environment":{"container":"create-sbom","image":"oci://quay.io/konflux-ci/mobster@sha256:135eec87fe80d0751a1ea5e8e47b240147b25ee9a41973cae365540d2e2ee473"}},{"annotations":null,"arguments":null,"entryPoint":"#!/bin/bash\nset -e\n\necho \"[$(date --utc -Ins)] Update CA trust\"\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nSBOM_RESULT_FILE=\"/index-build-data/index.spdx.json\"\nif [ ! -f \"$SBOM_RESULT_FILE\" ]; then\n echo \"The index.spdx.json file does not exists. Skipping the SBOM upload...\"\n exit 0\nfi\n\n# Pre-select the correct credentials to work around cosign not supporting the containers-auth.json spec\nmkdir -p /tmp/auth && select-oci-auth \"$(cat \"/tekton/results/IMAGE_REF\")\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\necho \"Pushing sbom to registry\"\nif ! retry cosign attach sbom --sbom \"$SBOM_RESULT_FILE\" --type spdx \"$(cat \"/tekton/results/IMAGE_REF\")\"\nthen\n echo \"Failed to push sbom to registry\"\n exit 1\nfi\n\n# Remove tag from IMAGE while allowing registry to contain a port number.\nsbom_repo=\"${IMAGE%:*}\"\nsbom_digest=\"$(sha256sum \"$SBOM_RESULT_FILE\" | cut -d' ' -f1)\"\n# The SBOM_BLOB_URL is created by `cosign attach sbom`.\necho -n \"${sbom_repo}@sha256:${sbom_digest}\" | tee \"/tekton/results/SBOM_BLOB_URL\"\n","environment":{"container":"upload-sbom","image":"oci://quay.io/konflux-ci/task-runner@sha256:4b01fbf98fa7155f5c21443c285f88853864ae7cc66981cf6b543fc6ba16b81b"}}]},{"after":["build-image-index","prefetch-dependencies"],"finishedOn":"2026-09-08T21:28:00Z","invocation":{"configSource":{"digest":{"sha256":"1808485d95cf77fb7912f6fe69191bead05fc0f2f71e00031941a7ea38a5f665"},"entryPoint":"source-build-oci-ta","uri":"quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/0d203381-9564-424e-a3e3-770f537cef63","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-f86a145d3ef4374d-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"build-source-image","tekton.dev/task":"source-build-oci-ta"}},"parameters":{"BASE_IMAGES":"","BINARY_IMAGE":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","BINARY_IMAGE_DIGEST":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","CACHI2_ARTIFACT":"","IGNORE_UNSIGNED_IMAGE":"false","SOURCE_ARTIFACT":"oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735","caTrustConfigMapKey":"ca-bundle.crt","caTrustConfigMapName":"trusted-ca"}},"name":"build-source-image","ref":{"params":[{"name":"name","value":"source-build-oci-ta"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.3.1@sha256:1808485d95cf77fb7912f6fe69191bead05fc0f2f71e00031941a7ea38a5f665"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"BUILD_RESULT","type":"string","value":"{\"status\": \"success\", \"dependencies_included\": false, \"base_image_source_included\": true, \"image_url\": \"quay.io/rhoai/odh-kserve-agent-rhel9:sha256-c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532.src\", \"image_digest\": \"sha256:3ffa8b0b17d1b3849c2beb64d31469bd872c42a05e78385f834b753b71a8eb9e\"}"},{"name":"IMAGE_REF","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9:sha256-c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532.src@sha256:3ffa8b0b17d1b3849c2beb64d31469bd872c42a05e78385f834b753b71a8eb9e"},{"name":"SOURCE_IMAGE_DIGEST","type":"string","value":"sha256:3ffa8b0b17d1b3849c2beb64d31469bd872c42a05e78385f834b753b71a8eb9e"},{"name":"SOURCE_IMAGE_URL","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9:sha256-c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532.src"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:27Z","status":"Succeeded","steps":[{"annotations":null,"arguments":["use","oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source","=/var/workdir/cachi2"],"entryPoint":"","environment":{"container":"use-trusted-artifact","image":"oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -euo pipefail\n\nif [[ ! $BINARY_IMAGE_DIGEST =~ ^sha256:[[:xdigit:]]+$ ]]; then\n echo \"$BINARY_IMAGE_DIGEST is not a valid sha256 digest.\"\n exit 1\nfi\n\nif [[ -n \"$BASE_IMAGES\" ]]; then\n echo \"BASE_IMAGES param received:\"\n printf \"%s\" \"$BASE_IMAGES\" | tee \"$BASE_IMAGES_FILE\"\n exit\nfi\n\necho \"BASE_IMAGES param is empty, inspecting the SBOM instead\"\n\nimage_pinned_by_digest=\"${BINARY_IMAGE%:*}@${BINARY_IMAGE_DIGEST}\"\n\nif raw_inspect=$(skopeo inspect --raw \"docker://${image_pinned_by_digest}\"); then\n echo \"Got manifest of image ${image_pinned_by_digest}\"\nelse\n if [[ $? == 2 ]]; then\n printf \"Binary image %s no longer exists in the registry.\\n\" \"$image_pinned_by_digest\" |\n tee \"$IMAGE_NOT_EXIST_FLAG\"\n exit\n else\n exit 1\n fi\nfi\n\nif manifest_digest=$(jq -e -r '.manifests[0].digest' <<<\"$raw_inspect\"); then\n # The BINARY_IMAGE is an image index, each manifest in the list has its own SBOM.\n # We're gonna assume the base images are the same or similar enough in all the SBOMs.\n echo \"Image (${image_pinned_by_digest}) is a manifest list, picking an arbitrary image from the list\"\n image=${image_pinned_by_digest%@*}@${manifest_digest}\nelse\n # The image is a single manifest\n image=$image_pinned_by_digest\nfi\n\n# Pre-select the correct credentials to work around cosign not supporting the containers-auth.json spec\nmkdir -p /tmp/auth && select-oci-auth \"$image\" >/tmp/auth/config.json\n\nfor i in {1..5}; do\n echo \"Downloading SBOM for $image (attempt $i)\"\n sbom=$(DOCKER_CONFIG=/tmp/auth cosign download sbom \"$image\") && break\n [[ \"$i\" -lt 5 ]] && sleep 1\ndone\n\nif [[ -z \"$sbom\" ]]; then\n echo \"Failed to download SBOM after 5 attempts. Proceeding anyway.\"\n echo \"WARNING: the source image will not include sources for the base image.\"\n exit 0\nfi\n\necho -n \"Looking for base image in SBOM\"\n\n# Note: the SBOM should contain at most one image with the is_base_image property - the\n# base image for the last FROM instruction. That is the only base image we care about.\nif jq -e '.bomFormat == \"CycloneDX\"' <<<\"$sbom\" >/dev/null; then\n echo \" (.formulation[].components[] with 'konflux:container:is_base_image' property)\"\n jq -r '\n .formulation[]?\n | .components[]?\n | select(any(.properties[]?; .name == \"konflux:container:is_base_image\"))\n | (\n .purl\n | capture(\"^pkg:oci/.*?@(?<digest>[a-z0-9]+:[a-f0-9]+)(?:\\\\?[^#]*repository_url=(?<repository_url>[^&#]*))?\")\n ) as $matched\n | $matched.repository_url + \"@\" + $matched.digest\n ' <<<\"$sbom\" | tee \"$BASE_IMAGES_FILE\"\nelse\n echo ' (a package with a {\"name\": \"konflux:container:is_base_image\"} JSON-encoded annotation)'\n jq -r '\n .packages[]\n | select(any(.annotations[]?.comment; (fromjson?).name? == \"konflux:container:is_base_image\"))\n | [.externalRefs[]? | select(.referenceType == \"purl\").referenceLocator] as $purls\n | (\n $purls | first\n | capture(\"^pkg:oci/.*?@(?<digest>[a-z0-9]+:[a-f0-9]+)(?:\\\\?[^#]*repository_url=(?<repository_url>[^&#]*))?\")\n ) as $matched\n | $matched.repository_url + \"@\" + $matched.digest\n\n ' <<<\"$sbom\" | tee \"$BASE_IMAGES_FILE\"\nfi\n","environment":{"container":"get-base-images","image":"oci://quay.io/konflux-ci/task-runner@sha256:38bfc93b0eacecd0aa5228225427524441c30e911b282a6b2eff9fdb0fdd021e"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -euo pipefail\n\nif [ -f \"$IMAGE_NOT_EXIST_FLAG\" ]; then\n echo \"Drop building source container image.\"\n printf \"\" >\"$RESULT_SOURCE_IMAGE_URL\"\n printf \"\" >\"$RESULT_SOURCE_IMAGE_DIGEST\"\n printf \"\" >\"$RESULT_IMAGE_REF\"\n message=$(cat \"$IMAGE_NOT_EXIST_FLAG\")\n printf \"{\\\"status\\\": \\\"drop\\\", \\\"message\\\": \\\"%s\\\"}\" \"$message\" >\"$WS_BUILD_RESULT_FILE\"\n exit\nfi\n\napp_dir=/opt/source_build\nregistry_allowlist=\"\nregistry.access.redhat.com\nregistry.redhat.io\n\"\n\n## This is needed for the builds performed by the rpm-ostree task\n## otherwise, we can see this error:\n## \"fatal: detected dubious ownership in repository at '/var/workdir/source'\"\n##\ngit config --global --add safe.directory \"$SOURCE_DIR\"\n\nbase_images=$(if [[ -f \"$BASE_IMAGES_FILE\" ]]; then cat \"$BASE_IMAGES_FILE\"; fi)\n\nargs=(\n --binary-image-ref \"${BINARY_IMAGE}@${BINARY_IMAGE_DIGEST}\"\n --workspace /var/workdir\n --source-dir \"$SOURCE_DIR\"\n --base-images \"$base_images\"\n --write-result-to \"$RESULT_FILE\"\n --prefetch-artifacts-dir \"$CACHI2_ARTIFACTS_DIR\"\n --registry-allowlist=\"$registry_allowlist\"\n)\nif [ \"$IGNORE_UNSIGNED_IMAGE\" == \"true\" ]; then\n args+=(--ignore-unsigned-image)\nfi\n\n${app_dir}/appenv/bin/python3 ${app_dir}/source_build.py \"${args[@]}\"\n\njq -j \".image_url\" <\"$RESULT_FILE\" >\"$RESULT_SOURCE_IMAGE_URL\"\njq -j \".image_digest\" <\"$RESULT_FILE\" >\"$RESULT_SOURCE_IMAGE_DIGEST\"\njq -j '\"\\(.image_url)@\\(.image_digest)\"' \"${RESULT_FILE}\" >\"$RESULT_IMAGE_REF\"\n\ncp \"$RESULT_FILE\" \"$WS_BUILD_RESULT_FILE\"\n","environment":{"container":"build","image":"oci://quay.io/konflux-ci/source-container-build@sha256:a8416f792207e4b9b8bfea1c9b86ad54ae7bc28384d14de0726cced3dee01ae5"}}]},{"after":["build-image-index"],"finishedOn":"2026-09-08T21:27:48Z","invocation":{"configSource":{"digest":{"sha256":"0ccc688a77e9b7b0b8973c132a1e840844137e77f887be4a0bec8893b0776872"},"entryPoint":"deprecated-image-check","uri":"quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/74f05ed2-9278-40b4-a6aa-321ab47c245a","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-3e2af06bf99ee472-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"deprecated-base-image-check","tekton.dev/task":"deprecated-image-check"}},"parameters":{"BASE_IMAGES_DIGESTS":"","CA_TRUST_CONFIG_MAP_KEY":"ca-bundle.crt","CA_TRUST_CONFIG_MAP_NAME":"trusted-ca","IMAGE_DIGEST":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","IMAGE_URL":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","POLICY_DIR":"/project/repository/","POLICY_NAMESPACE":"required_checks"}},"name":"deprecated-base-image-check","ref":{"params":[{"name":"name","value":"deprecated-image-check"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:0ccc688a77e9b7b0b8973c132a1e840844137e77f887be4a0bec8893b0776872"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"IMAGES_PROCESSED","type":"string","value":"{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b\",\"sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75\",\"sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f\",\"sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n"},{"name":"TEST_OUTPUT","type":"string","value":"{\"result\":\"SUCCESS\",\"timestamp\":\"2026-09-08T21:27:47+00:00\",\"note\":\"Task deprecated-image-check completed: Check result for task result.\",\"namespace\":\"required_checks\",\"successes\":2,\"failures\":0,\"warnings\":0}\n"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:27Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\nsource /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\nIMAGES_TO_BE_PROCESSED_PATH=\"/tmp/images_to_be_processed.txt\"\ntouch /tmp/images_to_be_processed.txt\n\nsuccess_counter=0\nfailure_counter=0\nerror_counter=0\nwarnings_counter=0\n\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\n\n# Get the arch and image manifests by inspecting the image. This is mainly for identifying image indexes\nimage_manifests=$(get_image_manifests -i \"${imageanddigest}\")\nif [ -n \"$image_manifests\" ]; then\n while read -r arch arch_sha; do\n SBOM_FILE_PATH=\"/tmp/sbom-${arch}.json\"\n arch_imageanddigest=\"${imagewithouttag}@${arch_sha}\"\n\n # Pre-select the correct credentials to work around cosign not supporting the containers-auth.json spec\n mkdir -p /tmp/auth && select-oci-auth \"${arch_imageanddigest}\" >/tmp/auth/config.json\n export DOCKER_CONFIG=/tmp/auth\n\n # Get base images from SBOM\n if ! cosign download sbom \"$arch_imageanddigest\" > \"${SBOM_FILE_PATH}\"; then\n echo \"Unable to download sbom for arch $arch.\"\n continue\n fi\n\n < \"${SBOM_FILE_PATH}\" jq -r '\n if .bomFormat == \"CycloneDX\" then\n .formulation[]?\n | .components[]?\n | select(any(.properties[]?; .name | test(\"^konflux:container:is_(base|builder)_image\")))\n | (\n .purl\n | capture(\"^pkg:oci/.*?@(?<digest>[a-z0-9]+:[a-f0-9]+)(?:\\\\?[^#]*repository_url=(?<repository_url>[^&#]*))?\")\n ) as $matched\n | $matched.repository_url\n else\n .packages[]\n | select(any(.annotations[]?.comment; (fromjson?).name? | test(\"^konflux:container:is_(base|builder)_image\")?))\n | [.externalRefs[]? | select(.referenceType == \"purl\").referenceLocator] as $purls\n | (\n $purls | first\n | capture(\"^pkg:oci/.*?@(?<digest>[a-z0-9]+:[a-f0-9]+)(?:\\\\?[^#]*repository_url=(?<repository_url>[^&#]*))?\")\n ) as $matched\n | $matched.repository_url\n end\n ' >> \"${IMAGES_TO_BE_PROCESSED_PATH}\"\n echo \"Detected base images from $arch SBOM:\"\n cat \"${IMAGES_TO_BE_PROCESSED_PATH}\"\n echo \"\"\n\n digests_processed+=(\"\\\"$arch_sha\\\"\")\n done < <(echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"')\nelse\n echo \"Failed to get image manifests from image \\\"$imageanddigest\\\"\"\n note=\"Task deprecated-image-check failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\n\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\n\nif [ -n \"${BASE_IMAGES_DIGESTS}\" ];\nthen\n echo \"Base images passed by param BASE_IMAGES_DIGESTS: $BASE_IMAGES_DIGESTS\"\n # Get images from the parameter\n for IMAGE_WITH_TAG in $(echo -n \"$BASE_IMAGES_DIGESTS\" | sed 's/\\\\n/\\'$'\\n''/g' );\n do\n echo \"$IMAGE_WITH_TAG\" | cut -d \":\" -f1 >> \"${IMAGES_TO_BE_PROCESSED_PATH}\"\n done\nfi\n\n# we want to remove duplicated entries\nBASE_IMAGES=$(sort -u \"${IMAGES_TO_BE_PROCESSED_PATH}\")\n\necho \"Images to be checked:\"\necho \"$BASE_IMAGES\"\necho \"\"\n\nfor BASE_IMAGE in ${BASE_IMAGES};\ndo\n IFS=:'/' read -r IMAGE_REGISTRY IMAGE_REPOSITORY<<< \"$BASE_IMAGE\"\n\n # Red Hat Catalog hack: registry.redhat.io must be queried as registry.access.redhat.com in Red Hat catalog\n IMAGE_REGISTRY_CATALOG=$(echo \"${IMAGE_REGISTRY}\" | sed 's/^registry.redhat.io$/registry.access.redhat.com/')\n\n export IMAGE_REPO_PATH=\"/tmp/${IMAGE_REPOSITORY}\"\n mkdir -p \"${IMAGE_REPO_PATH}\"\n echo \"Querying Red Hat Catalog for $BASE_IMAGE.\"\n http_code=$(curl -s -o \"${IMAGE_REPO_PATH}/repository_data.json\" -w '%{http_code}' \"https://catalog.redhat.com/api/containers/v1/repositories/registry/${IMAGE_REGISTRY_CATALOG}/repository/${IMAGE_REPOSITORY}\")\n\n if [ \"$http_code\" == \"200\" ];\n then\n echo \"Running conftest using $POLICY_DIR policy, $POLICY_NAMESPACE namespace.\"\n /usr/bin/conftest test --no-fail \"${IMAGE_REPO_PATH}/repository_data.json\" \\\n --policy \"$POLICY_DIR\" --namespace \"$POLICY_NAMESPACE\" \\\n --output=json | tee \"${IMAGE_REPO_PATH}/deprecated_image_check_output.json\"\n\n failures_num=$(jq -r '.[].failures|length' \"${IMAGE_REPO_PATH}/deprecated_image_check_output.json\")\n if [[ \"${failures_num}\" -gt 0 ]]; then\n echo \"[FAILURE] Image ${IMAGE_REGISTRY}/${IMAGE_REPOSITORY} has been deprecated\"\n fi\n failure_counter=$((failure_counter+failures_num))\n\n successes_num=$(jq -r '.[].successes' \"${IMAGE_REPO_PATH}/deprecated_image_check_output.json\")\n if [[ \"${successes_num}\" -gt 0 ]]; then\n echo \"[SUCCESS] Image ${IMAGE_REGISTRY}/${IMAGE_REPOSITORY} is valid\"\n fi\n success_counter=$((success_counter+successes_num))\n\n elif [ \"$http_code\" == \"404\" ];\n then\n echo \"[WARNING] Registry/image ${IMAGE_REGISTRY}/${IMAGE_REPOSITORY} not found in Red Hat Catalog. Task cannot provide results if image is deprecated.\"\n warnings_counter=$((warnings_counter+1))\n else\n echo \"[ERROR] Unexpected error (HTTP code: ${http_code}) occurred for registry/image ${IMAGE_REGISTRY}/${IMAGE_REPOSITORY}.\"\n error_counter=$((error_counter+1))\n fi\ndone\n\nnote=\"Task deprecated-image-check failed: Command conftest failed. For details, check Tekton task log.\"\nERROR_OUTPUT=$(make_result_json -r ERROR -n \"$POLICY_NAMESPACE\" -t \"$note\")\n\nnote=\"Task deprecated-image-check completed: Check result for task result.\"\nif [[ \"$error_counter\" == 0 ]];\nthen\n if [[ \"${failure_counter}\" -gt 0 ]]; then\n RES=\"FAILURE\"\n elif [[ \"${warnings_counter}\" -gt 0 ]]; then\n RES=\"WARNING\"\n elif [[ \"${success_counter}\" -eq 0 ]]; then\n # when all counters are 0, there are no base images to check\n note=\"Task deprecated-image-check success: No base images to check.\"\n RES=\"SUCCESS\"\n else\n RES=\"SUCCESS\"\n fi\n TEST_OUTPUT=$(make_result_json \\\n -r \"${RES}\" -n \"$POLICY_NAMESPACE\" \\\n -s \"${success_counter}\" -f \"${failure_counter}\" -w \"${warnings_counter}\" -t \"$note\")\nfi\necho \"${TEST_OUTPUT:-${ERROR_OUTPUT}}\" | tee \"/tekton/results/TEST_OUTPUT\"\n\necho \"${images_processed_template/\\[%s]/[$digests_processed_string]}\" | tee \"/tekton/results/IMAGES_PROCESSED\"\n","environment":{"container":"check-images","image":"oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b"}}]},{"after":["build-image-index"],"finishedOn":"2026-09-08T21:28:15Z","invocation":{"configSource":{"digest":{"sha256":"f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174"},"entryPoint":"clair-scan","uri":"quay.io/konflux-ci/tekton-catalog/task-clair-scan"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/56735d8f-bd4c-42b3-9a62-502f4fe97c89","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-f2c49c1938a61c45-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"clair-scan","tekton.dev/task":"clair-scan"}},"parameters":{"ca-trust-config-map-key":"ca-bundle.crt","ca-trust-config-map-name":"trusted-ca","docker-auth":"","image-digest":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","image-platform":"linux/x86_64","image-url":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","skip-oci-attach-report":"false"}},"name":"clair-scan","ref":{"params":[{"name":"name","value":"clair-scan"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3.2@sha256:f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"IMAGES_PROCESSED","type":"string","value":"{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n"},{"name":"REPORTS","type":"string","value":"{\"sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b\":\"sha256:d88ff3dacf3d16651aa77594a46b95137350c3deb60354d8ff41e94190264703\"}\n"},{"name":"SCAN_OUTPUT","type":"string","value":"{\"vulnerabilities\":{\"critical\":0,\"high\":0,\"medium\":0,\"low\":0,\"unknown\":0},\"unpatched_vulnerabilities\":{\"critical\":0,\"high\":9,\"medium\":80,\"low\":59,\"unknown\":3}}\n"},{"name":"TEST_OUTPUT","type":"string","value":"{\"result\":\"SUCCESS\",\"timestamp\":\"2026-09-08T21:28:14+00:00\",\"note\":\"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.\",\"namespace\":\"default\",\"successes\":0,\"failures\":0,\"warnings\":0}\n"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:27Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\necho \"Inspecting raw image manifest $imageanddigest.\"\n\n# Get the arch and image manifests by inspecting the image. This is mainly for identifying image indexes\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_URL\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\nimage_manifests=$(get_image_manifests -i \"${imageanddigest}\")\nif [ -n \"$image_manifests\" ]; then\n echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"' | while read -r arch arch_sha; do\n echo \"$arch_sha\" > \"/tekton/home/image-manifest-${arch}.sha\"\n done\nelse\n echo \"Failed to get image manifests from image \\\"$imageanddigest\\\"\"\n note=\"Task clair-scan failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n","environment":{"container":"get-image-manifests","image":"oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\n\nset -o errexit\nset -o nounset\nset -o pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\n\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_URL\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\n\n# the quay report format used by the Conftest rules in the\n# conftest-vulnerabilities step doesn't contain the \"issued\" date which\n# we require in the policy rules, so we resort to running clair-action\n# twice to produce both quay and clair formatted output\nclair_report() {\n { retry clair-action report --image-ref=\"$1\" --db-path=/tmp/matcher.db --docker-config-dir=/tmp/auth --format=clair | tee \"clair-report-$2.json\"; } && \\\n { retry clair-action convert --file-path=\"clair-report-$2.json\" --format=quay > \"clair-result-$2.json\"; }\n}\n\nrun_clair_on_arch() {\n local arch=\"$1\"\n local sha_file=\"image-manifest-$arch.sha\"\n\n if [ -e \"$sha_file\" ]; then\n local arch_sha\n arch_sha=$(<\"$sha_file\")\n local digest=\"${imagewithouttag}@${arch_sha}\"\n\n echo \"Running clair-action on $arch image manifest...\"\n clair_report \"$digest\" \"$arch\" || true\n\n digests_processed+=(\"\\\"$arch_sha\\\"\")\n fi\n}\n\nplatform=\"${IMAGE_PLATFORM}\"\n\n# If a platform is specified, extract the architecture and run clair-action on the corresponding image manifest\nif [ -n \"$platform\" ]; then\n arch=\"${platform#*/}\"\n if [ \"$arch\" = \"x86_64\" ] || [ \"$arch\" = \"local\" ] || [ \"$arch\" = \"localhost\" ]; then\n arch=\"amd64\"\n fi\n # Validate against supported arch list. If it's not a known arch, fallback to amd64\n case \"$arch\" in\n amd64|ppc64le|arm64|s390x)\n ;;\n *)\n echo \"Error: Unsupported or malformed architecture: '$arch' (parsed from platform: '$platform')\"\n exit 0\n ;;\n esac\n\n run_clair_on_arch \"$arch\"\n\n# If no platform is specified, run clair-action on all available image manifests\nelse\n for sha_file in image-manifest-*.sha; do\n if [ -e \"$sha_file\" ]; then\n arch=$(basename \"$sha_file\" | sed 's/image-manifest-//;s/.sha//')\n run_clair_on_arch \"$arch\"\n fi\n done\nfi\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\n\nimages_processed=\"${images_processed_template/\\[%s]/[$digests_processed_string]}\"\necho \"$images_processed\" > images-processed.json\n","environment":{"container":"get-vulnerabilities","image":"oci://quay.io/konflux-ci/clair-in-ci@sha256:6ed1dbb16de5a87f42df0d11cfb5b6bb0571a56e793b2c702c03e010846d34d5"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\n\nset -o errexit\nset -o nounset\nset -o pipefail\n\nif [ \"$SKIP_OCI_ATTACH_REPORT\" = \"true\" ]; then\n echo 'OCI attach report skipped by parameter.'\n echo '{}' > reports.json\n exit 0\nfi\n\nif ! compgen -G \"clair-report-*.json\" > /dev/null; then\n echo 'No Clair reports generated. Skipping upload.'\n echo '{}' > reports.json\n exit 0\nfi\n\necho \"Selecting auth\"\nselect-oci-auth \"$IMAGE_URL\" > \"$HOME/auth.json\"\n\nrepository=\"${IMAGE_URL/:*/}\"\n\narch() {\n report_file=\"$1\"\n arch=\"${report_file/*-}\"\n echo \"${arch/.json/}\"\n}\n\nMEDIA_TYPE='application/vnd.redhat.clair-report+json'\n\nreports_json=\"\"\nfor f in clair-report-*.json; do\n digest=$(cat \"image-manifest-$(arch \"$f\").sha\")\n image_ref=\"${repository}@${digest}\"\n mkdir -p /tmp/auth && select-oci-auth \"${image_ref}\" > /tmp/auth/config.json\n export DOCKER_CONFIG=/tmp/auth\n echo \"Attaching $f to ${image_ref}\"\n if ! report_digest=\"$(retry oras attach --no-tty --format go-template='{{.digest}}' --registry-config \\\n \"/tmp/auth/config.json\" --artifact-type \"${MEDIA_TYPE}\" \"${image_ref}\" \"$f:${MEDIA_TYPE}\")\"\n then\n echo \"Failed to attach ${f} to ${image_ref}\"\n exit 1\n fi\n # shellcheck disable=SC2016\n reports_json=\"$(yq --output-format json --indent=0 eval-all '. as $i ireduce ({}; . * $i)' <(echo \"${reports_json}\") <(echo \"${digest}: ${report_digest}\"))\"\ndone\necho \"${reports_json}\" > reports.json\n","environment":{"container":"oci-attach-report","image":"oci://quay.io/konflux-ci/task-runner@sha256:1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\nclair_result_files=$(ls /tekton/home/clair-result-*.json)\nif [ -z \"$clair_result_files\" ]; then\n echo \"Previous step [get-vulnerabilities] failed: No clair-result files found in /tekton/home.\"\nfi\n\nmissing_vulnerabilities_files=\"\"\nfor file in $clair_result_files; do\n file_suffix=$(basename \"$file\" | sed 's/clair-result-//;s/.json//')\n if [ ! -s \"$file\" ]; then\n echo \"Previous step [get-vulnerabilities] failed: $file is empty.\"\n else\n /usr/bin/conftest test --no-fail \"$file\" \\\n --policy /project/clair/vulnerabilities-check.rego --namespace required_checks \\\n --output=json | tee \"/tekton/home/clair-vulnerabilities-${file_suffix}.json\" || true\n fi\n\n #check for missing \"clair-vulnerabilities-<arch>/image-index\" file and create a string\n if [ ! -f \"/tekton/home/clair-vulnerabilities-$file_suffix.json\" ]; then\n missing_vulnerabilities_files+=\"${missing_vulnerabilities_files:+, }/tekton/home/clair-vulnerabilities-$file_suffix.json\"\n fi\ndone\n\nif [ -n \"$missing_vulnerabilities_files\" ]; then\n note=\"Task clair-scan failed: $missing_vulnerabilities_files did not generate. For details, check Tekton task log.\"\n TEST_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"$missing_vulnerabilities_files did not generate correctly. For details, check conftest command in Tekton task log.\"\n echo \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n\nscan_result='{\"vulnerabilities\":{\"critical\":0, \"high\":0, \"medium\":0, \"low\":0, \"unknown\":0}, \"unpatched_vulnerabilities\":{\"critical\":0, \"high\":0, \"medium\":0, \"low\":0, \"unknown\":0}}'\nfor file in /tekton/home/clair-vulnerabilities-*.json; do\n result=$(jq -rce \\\n '{\n vulnerabilities:{\n critical: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_critical_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n high: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_high_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n medium: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_medium_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n low: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_low_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n unknown: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unknown_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0)\n },\n unpatched_vulnerabilities:{\n critical: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_critical_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n high: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_high_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n medium: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_medium_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n low: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_low_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n unknown: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_unknown_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0)\n }\n }' \"$file\")\n\n scan_result=$(jq -s -rce \\\n '.[0].vulnerabilities.critical += .[1].vulnerabilities.critical |\n .[0].vulnerabilities.high += .[1].vulnerabilities.high |\n .[0].vulnerabilities.medium += .[1].vulnerabilities.medium |\n .[0].vulnerabilities.low += .[1].vulnerabilities.low |\n .[0].vulnerabilities.unknown += .[1].vulnerabilities.unknown |\n .[0].unpatched_vulnerabilities.critical += .[1].unpatched_vulnerabilities.critical |\n .[0].unpatched_vulnerabilities.high += .[1].unpatched_vulnerabilities.high |\n .[0].unpatched_vulnerabilities.medium += .[1].unpatched_vulnerabilities.medium |\n .[0].unpatched_vulnerabilities.low += .[1].unpatched_vulnerabilities.low |\n .[0].unpatched_vulnerabilities.unknown += .[1].unpatched_vulnerabilities.unknown |\n .[0]' <<<\"$scan_result $result\")\ndone\n\necho \"$scan_result\" | tee \"/tekton/results/SCAN_OUTPUT\"\n\ntee \"/tekton/results/IMAGES_PROCESSED\" < /tekton/home/images-processed.json\n# shellcheck disable=SC2154\ncat /tekton/home/reports.json > \"/tekton/results/REPORTS\"\n\nnote=\"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.\"\nTEST_OUTPUT=$(make_result_json -r \"SUCCESS\" -t \"$note\")\necho \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n","environment":{"container":"conftest-vulnerabilities","image":"oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b"}}]},{"after":["build-image-index"],"finishedOn":"2026-09-08T21:28:16Z","invocation":{"configSource":{"digest":{"sha256":"f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174"},"entryPoint":"clair-scan","uri":"quay.io/konflux-ci/tekton-catalog/task-clair-scan"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/ef8501e0-b10c-4a23-aefe-1331729e8346","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-8b940cec21748595-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"clair-scan","tekton.dev/task":"clair-scan"}},"parameters":{"ca-trust-config-map-key":"ca-bundle.crt","ca-trust-config-map-name":"trusted-ca","docker-auth":"","image-digest":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","image-platform":"linux/ppc64le","image-url":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","skip-oci-attach-report":"false"}},"name":"clair-scan","ref":{"params":[{"name":"name","value":"clair-scan"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3.2@sha256:f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"IMAGES_PROCESSED","type":"string","value":"{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n"},{"name":"REPORTS","type":"string","value":"{\"sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75\":\"sha256:26ff675350098968a65ce8ef71470afe3428e78d817955ad22f6551e303ce48c\"}\n"},{"name":"SCAN_OUTPUT","type":"string","value":"{\"vulnerabilities\":{\"critical\":0,\"high\":0,\"medium\":0,\"low\":0,\"unknown\":0},\"unpatched_vulnerabilities\":{\"critical\":0,\"high\":9,\"medium\":80,\"low\":59,\"unknown\":3}}\n"},{"name":"TEST_OUTPUT","type":"string","value":"{\"result\":\"SUCCESS\",\"timestamp\":\"2026-09-08T21:28:15+00:00\",\"note\":\"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.\",\"namespace\":\"default\",\"successes\":0,\"failures\":0,\"warnings\":0}\n"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:27Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\necho \"Inspecting raw image manifest $imageanddigest.\"\n\n# Get the arch and image manifests by inspecting the image. This is mainly for identifying image indexes\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_URL\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\nimage_manifests=$(get_image_manifests -i \"${imageanddigest}\")\nif [ -n \"$image_manifests\" ]; then\n echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"' | while read -r arch arch_sha; do\n echo \"$arch_sha\" > \"/tekton/home/image-manifest-${arch}.sha\"\n done\nelse\n echo \"Failed to get image manifests from image \\\"$imageanddigest\\\"\"\n note=\"Task clair-scan failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n","environment":{"container":"get-image-manifests","image":"oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\n\nset -o errexit\nset -o nounset\nset -o pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\n\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_URL\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\n\n# the quay report format used by the Conftest rules in the\n# conftest-vulnerabilities step doesn't contain the \"issued\" date which\n# we require in the policy rules, so we resort to running clair-action\n# twice to produce both quay and clair formatted output\nclair_report() {\n { retry clair-action report --image-ref=\"$1\" --db-path=/tmp/matcher.db --docker-config-dir=/tmp/auth --format=clair | tee \"clair-report-$2.json\"; } && \\\n { retry clair-action convert --file-path=\"clair-report-$2.json\" --format=quay > \"clair-result-$2.json\"; }\n}\n\nrun_clair_on_arch() {\n local arch=\"$1\"\n local sha_file=\"image-manifest-$arch.sha\"\n\n if [ -e \"$sha_file\" ]; then\n local arch_sha\n arch_sha=$(<\"$sha_file\")\n local digest=\"${imagewithouttag}@${arch_sha}\"\n\n echo \"Running clair-action on $arch image manifest...\"\n clair_report \"$digest\" \"$arch\" || true\n\n digests_processed+=(\"\\\"$arch_sha\\\"\")\n fi\n}\n\nplatform=\"${IMAGE_PLATFORM}\"\n\n# If a platform is specified, extract the architecture and run clair-action on the corresponding image manifest\nif [ -n \"$platform\" ]; then\n arch=\"${platform#*/}\"\n if [ \"$arch\" = \"x86_64\" ] || [ \"$arch\" = \"local\" ] || [ \"$arch\" = \"localhost\" ]; then\n arch=\"amd64\"\n fi\n # Validate against supported arch list. If it's not a known arch, fallback to amd64\n case \"$arch\" in\n amd64|ppc64le|arm64|s390x)\n ;;\n *)\n echo \"Error: Unsupported or malformed architecture: '$arch' (parsed from platform: '$platform')\"\n exit 0\n ;;\n esac\n\n run_clair_on_arch \"$arch\"\n\n# If no platform is specified, run clair-action on all available image manifests\nelse\n for sha_file in image-manifest-*.sha; do\n if [ -e \"$sha_file\" ]; then\n arch=$(basename \"$sha_file\" | sed 's/image-manifest-//;s/.sha//')\n run_clair_on_arch \"$arch\"\n fi\n done\nfi\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\n\nimages_processed=\"${images_processed_template/\\[%s]/[$digests_processed_string]}\"\necho \"$images_processed\" > images-processed.json\n","environment":{"container":"get-vulnerabilities","image":"oci://quay.io/konflux-ci/clair-in-ci@sha256:6ed1dbb16de5a87f42df0d11cfb5b6bb0571a56e793b2c702c03e010846d34d5"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\n\nset -o errexit\nset -o nounset\nset -o pipefail\n\nif [ \"$SKIP_OCI_ATTACH_REPORT\" = \"true\" ]; then\n echo 'OCI attach report skipped by parameter.'\n echo '{}' > reports.json\n exit 0\nfi\n\nif ! compgen -G \"clair-report-*.json\" > /dev/null; then\n echo 'No Clair reports generated. Skipping upload.'\n echo '{}' > reports.json\n exit 0\nfi\n\necho \"Selecting auth\"\nselect-oci-auth \"$IMAGE_URL\" > \"$HOME/auth.json\"\n\nrepository=\"${IMAGE_URL/:*/}\"\n\narch() {\n report_file=\"$1\"\n arch=\"${report_file/*-}\"\n echo \"${arch/.json/}\"\n}\n\nMEDIA_TYPE='application/vnd.redhat.clair-report+json'\n\nreports_json=\"\"\nfor f in clair-report-*.json; do\n digest=$(cat \"image-manifest-$(arch \"$f\").sha\")\n image_ref=\"${repository}@${digest}\"\n mkdir -p /tmp/auth && select-oci-auth \"${image_ref}\" > /tmp/auth/config.json\n export DOCKER_CONFIG=/tmp/auth\n echo \"Attaching $f to ${image_ref}\"\n if ! report_digest=\"$(retry oras attach --no-tty --format go-template='{{.digest}}' --registry-config \\\n \"/tmp/auth/config.json\" --artifact-type \"${MEDIA_TYPE}\" \"${image_ref}\" \"$f:${MEDIA_TYPE}\")\"\n then\n echo \"Failed to attach ${f} to ${image_ref}\"\n exit 1\n fi\n # shellcheck disable=SC2016\n reports_json=\"$(yq --output-format json --indent=0 eval-all '. as $i ireduce ({}; . * $i)' <(echo \"${reports_json}\") <(echo \"${digest}: ${report_digest}\"))\"\ndone\necho \"${reports_json}\" > reports.json\n","environment":{"container":"oci-attach-report","image":"oci://quay.io/konflux-ci/task-runner@sha256:1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\nclair_result_files=$(ls /tekton/home/clair-result-*.json)\nif [ -z \"$clair_result_files\" ]; then\n echo \"Previous step [get-vulnerabilities] failed: No clair-result files found in /tekton/home.\"\nfi\n\nmissing_vulnerabilities_files=\"\"\nfor file in $clair_result_files; do\n file_suffix=$(basename \"$file\" | sed 's/clair-result-//;s/.json//')\n if [ ! -s \"$file\" ]; then\n echo \"Previous step [get-vulnerabilities] failed: $file is empty.\"\n else\n /usr/bin/conftest test --no-fail \"$file\" \\\n --policy /project/clair/vulnerabilities-check.rego --namespace required_checks \\\n --output=json | tee \"/tekton/home/clair-vulnerabilities-${file_suffix}.json\" || true\n fi\n\n #check for missing \"clair-vulnerabilities-<arch>/image-index\" file and create a string\n if [ ! -f \"/tekton/home/clair-vulnerabilities-$file_suffix.json\" ]; then\n missing_vulnerabilities_files+=\"${missing_vulnerabilities_files:+, }/tekton/home/clair-vulnerabilities-$file_suffix.json\"\n fi\ndone\n\nif [ -n \"$missing_vulnerabilities_files\" ]; then\n note=\"Task clair-scan failed: $missing_vulnerabilities_files did not generate. For details, check Tekton task log.\"\n TEST_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"$missing_vulnerabilities_files did not generate correctly. For details, check conftest command in Tekton task log.\"\n echo \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n\nscan_result='{\"vulnerabilities\":{\"critical\":0, \"high\":0, \"medium\":0, \"low\":0, \"unknown\":0}, \"unpatched_vulnerabilities\":{\"critical\":0, \"high\":0, \"medium\":0, \"low\":0, \"unknown\":0}}'\nfor file in /tekton/home/clair-vulnerabilities-*.json; do\n result=$(jq -rce \\\n '{\n vulnerabilities:{\n critical: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_critical_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n high: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_high_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n medium: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_medium_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n low: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_low_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n unknown: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unknown_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0)\n },\n unpatched_vulnerabilities:{\n critical: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_critical_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n high: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_high_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n medium: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_medium_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n low: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_low_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n unknown: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_unknown_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0)\n }\n }' \"$file\")\n\n scan_result=$(jq -s -rce \\\n '.[0].vulnerabilities.critical += .[1].vulnerabilities.critical |\n .[0].vulnerabilities.high += .[1].vulnerabilities.high |\n .[0].vulnerabilities.medium += .[1].vulnerabilities.medium |\n .[0].vulnerabilities.low += .[1].vulnerabilities.low |\n .[0].vulnerabilities.unknown += .[1].vulnerabilities.unknown |\n .[0].unpatched_vulnerabilities.critical += .[1].unpatched_vulnerabilities.critical |\n .[0].unpatched_vulnerabilities.high += .[1].unpatched_vulnerabilities.high |\n .[0].unpatched_vulnerabilities.medium += .[1].unpatched_vulnerabilities.medium |\n .[0].unpatched_vulnerabilities.low += .[1].unpatched_vulnerabilities.low |\n .[0].unpatched_vulnerabilities.unknown += .[1].unpatched_vulnerabilities.unknown |\n .[0]' <<<\"$scan_result $result\")\ndone\n\necho \"$scan_result\" | tee \"/tekton/results/SCAN_OUTPUT\"\n\ntee \"/tekton/results/IMAGES_PROCESSED\" < /tekton/home/images-processed.json\n# shellcheck disable=SC2154\ncat /tekton/home/reports.json > \"/tekton/results/REPORTS\"\n\nnote=\"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.\"\nTEST_OUTPUT=$(make_result_json -r \"SUCCESS\" -t \"$note\")\necho \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n","environment":{"container":"conftest-vulnerabilities","image":"oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b"}}]},{"after":["build-image-index"],"finishedOn":"2026-09-08T21:28:15Z","invocation":{"configSource":{"digest":{"sha256":"f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174"},"entryPoint":"clair-scan","uri":"quay.io/konflux-ci/tekton-catalog/task-clair-scan"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/52123453-b303-47e1-8de8-61d3053d0dfe","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-5fa12cfc7ee74dd1-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"clair-scan","tekton.dev/task":"clair-scan"}},"parameters":{"ca-trust-config-map-key":"ca-bundle.crt","ca-trust-config-map-name":"trusted-ca","docker-auth":"","image-digest":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","image-platform":"linux/s390x","image-url":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","skip-oci-attach-report":"false"}},"name":"clair-scan","ref":{"params":[{"name":"name","value":"clair-scan"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3.2@sha256:f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"IMAGES_PROCESSED","type":"string","value":"{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n"},{"name":"REPORTS","type":"string","value":"{\"sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f\":\"sha256:4ee1c56ed661708d789dc3aebecccb33dc0716884c4c16d23a1bd0e18b128b66\"}\n"},{"name":"SCAN_OUTPUT","type":"string","value":"{\"vulnerabilities\":{\"critical\":0,\"high\":0,\"medium\":0,\"low\":0,\"unknown\":0},\"unpatched_vulnerabilities\":{\"critical\":0,\"high\":9,\"medium\":80,\"low\":59,\"unknown\":3}}\n"},{"name":"TEST_OUTPUT","type":"string","value":"{\"result\":\"SUCCESS\",\"timestamp\":\"2026-09-08T21:28:14+00:00\",\"note\":\"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.\",\"namespace\":\"default\",\"successes\":0,\"failures\":0,\"warnings\":0}\n"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:27Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\necho \"Inspecting raw image manifest $imageanddigest.\"\n\n# Get the arch and image manifests by inspecting the image. This is mainly for identifying image indexes\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_URL\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\nimage_manifests=$(get_image_manifests -i \"${imageanddigest}\")\nif [ -n \"$image_manifests\" ]; then\n echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"' | while read -r arch arch_sha; do\n echo \"$arch_sha\" > \"/tekton/home/image-manifest-${arch}.sha\"\n done\nelse\n echo \"Failed to get image manifests from image \\\"$imageanddigest\\\"\"\n note=\"Task clair-scan failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n","environment":{"container":"get-image-manifests","image":"oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\n\nset -o errexit\nset -o nounset\nset -o pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\n\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_URL\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\n\n# the quay report format used by the Conftest rules in the\n# conftest-vulnerabilities step doesn't contain the \"issued\" date which\n# we require in the policy rules, so we resort to running clair-action\n# twice to produce both quay and clair formatted output\nclair_report() {\n { retry clair-action report --image-ref=\"$1\" --db-path=/tmp/matcher.db --docker-config-dir=/tmp/auth --format=clair | tee \"clair-report-$2.json\"; } && \\\n { retry clair-action convert --file-path=\"clair-report-$2.json\" --format=quay > \"clair-result-$2.json\"; }\n}\n\nrun_clair_on_arch() {\n local arch=\"$1\"\n local sha_file=\"image-manifest-$arch.sha\"\n\n if [ -e \"$sha_file\" ]; then\n local arch_sha\n arch_sha=$(<\"$sha_file\")\n local digest=\"${imagewithouttag}@${arch_sha}\"\n\n echo \"Running clair-action on $arch image manifest...\"\n clair_report \"$digest\" \"$arch\" || true\n\n digests_processed+=(\"\\\"$arch_sha\\\"\")\n fi\n}\n\nplatform=\"${IMAGE_PLATFORM}\"\n\n# If a platform is specified, extract the architecture and run clair-action on the corresponding image manifest\nif [ -n \"$platform\" ]; then\n arch=\"${platform#*/}\"\n if [ \"$arch\" = \"x86_64\" ] || [ \"$arch\" = \"local\" ] || [ \"$arch\" = \"localhost\" ]; then\n arch=\"amd64\"\n fi\n # Validate against supported arch list. If it's not a known arch, fallback to amd64\n case \"$arch\" in\n amd64|ppc64le|arm64|s390x)\n ;;\n *)\n echo \"Error: Unsupported or malformed architecture: '$arch' (parsed from platform: '$platform')\"\n exit 0\n ;;\n esac\n\n run_clair_on_arch \"$arch\"\n\n# If no platform is specified, run clair-action on all available image manifests\nelse\n for sha_file in image-manifest-*.sha; do\n if [ -e \"$sha_file\" ]; then\n arch=$(basename \"$sha_file\" | sed 's/image-manifest-//;s/.sha//')\n run_clair_on_arch \"$arch\"\n fi\n done\nfi\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\n\nimages_processed=\"${images_processed_template/\\[%s]/[$digests_processed_string]}\"\necho \"$images_processed\" > images-processed.json\n","environment":{"container":"get-vulnerabilities","image":"oci://quay.io/konflux-ci/clair-in-ci@sha256:6ed1dbb16de5a87f42df0d11cfb5b6bb0571a56e793b2c702c03e010846d34d5"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\n\nset -o errexit\nset -o nounset\nset -o pipefail\n\nif [ \"$SKIP_OCI_ATTACH_REPORT\" = \"true\" ]; then\n echo 'OCI attach report skipped by parameter.'\n echo '{}' > reports.json\n exit 0\nfi\n\nif ! compgen -G \"clair-report-*.json\" > /dev/null; then\n echo 'No Clair reports generated. Skipping upload.'\n echo '{}' > reports.json\n exit 0\nfi\n\necho \"Selecting auth\"\nselect-oci-auth \"$IMAGE_URL\" > \"$HOME/auth.json\"\n\nrepository=\"${IMAGE_URL/:*/}\"\n\narch() {\n report_file=\"$1\"\n arch=\"${report_file/*-}\"\n echo \"${arch/.json/}\"\n}\n\nMEDIA_TYPE='application/vnd.redhat.clair-report+json'\n\nreports_json=\"\"\nfor f in clair-report-*.json; do\n digest=$(cat \"image-manifest-$(arch \"$f\").sha\")\n image_ref=\"${repository}@${digest}\"\n mkdir -p /tmp/auth && select-oci-auth \"${image_ref}\" > /tmp/auth/config.json\n export DOCKER_CONFIG=/tmp/auth\n echo \"Attaching $f to ${image_ref}\"\n if ! report_digest=\"$(retry oras attach --no-tty --format go-template='{{.digest}}' --registry-config \\\n \"/tmp/auth/config.json\" --artifact-type \"${MEDIA_TYPE}\" \"${image_ref}\" \"$f:${MEDIA_TYPE}\")\"\n then\n echo \"Failed to attach ${f} to ${image_ref}\"\n exit 1\n fi\n # shellcheck disable=SC2016\n reports_json=\"$(yq --output-format json --indent=0 eval-all '. as $i ireduce ({}; . * $i)' <(echo \"${reports_json}\") <(echo \"${digest}: ${report_digest}\"))\"\ndone\necho \"${reports_json}\" > reports.json\n","environment":{"container":"oci-attach-report","image":"oci://quay.io/konflux-ci/task-runner@sha256:1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\nclair_result_files=$(ls /tekton/home/clair-result-*.json)\nif [ -z \"$clair_result_files\" ]; then\n echo \"Previous step [get-vulnerabilities] failed: No clair-result files found in /tekton/home.\"\nfi\n\nmissing_vulnerabilities_files=\"\"\nfor file in $clair_result_files; do\n file_suffix=$(basename \"$file\" | sed 's/clair-result-//;s/.json//')\n if [ ! -s \"$file\" ]; then\n echo \"Previous step [get-vulnerabilities] failed: $file is empty.\"\n else\n /usr/bin/conftest test --no-fail \"$file\" \\\n --policy /project/clair/vulnerabilities-check.rego --namespace required_checks \\\n --output=json | tee \"/tekton/home/clair-vulnerabilities-${file_suffix}.json\" || true\n fi\n\n #check for missing \"clair-vulnerabilities-<arch>/image-index\" file and create a string\n if [ ! -f \"/tekton/home/clair-vulnerabilities-$file_suffix.json\" ]; then\n missing_vulnerabilities_files+=\"${missing_vulnerabilities_files:+, }/tekton/home/clair-vulnerabilities-$file_suffix.json\"\n fi\ndone\n\nif [ -n \"$missing_vulnerabilities_files\" ]; then\n note=\"Task clair-scan failed: $missing_vulnerabilities_files did not generate. For details, check Tekton task log.\"\n TEST_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"$missing_vulnerabilities_files did not generate correctly. For details, check conftest command in Tekton task log.\"\n echo \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n\nscan_result='{\"vulnerabilities\":{\"critical\":0, \"high\":0, \"medium\":0, \"low\":0, \"unknown\":0}, \"unpatched_vulnerabilities\":{\"critical\":0, \"high\":0, \"medium\":0, \"low\":0, \"unknown\":0}}'\nfor file in /tekton/home/clair-vulnerabilities-*.json; do\n result=$(jq -rce \\\n '{\n vulnerabilities:{\n critical: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_critical_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n high: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_high_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n medium: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_medium_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n low: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_low_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n unknown: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unknown_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0)\n },\n unpatched_vulnerabilities:{\n critical: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_critical_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n high: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_high_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n medium: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_medium_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n low: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_low_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n unknown: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_unknown_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0)\n }\n }' \"$file\")\n\n scan_result=$(jq -s -rce \\\n '.[0].vulnerabilities.critical += .[1].vulnerabilities.critical |\n .[0].vulnerabilities.high += .[1].vulnerabilities.high |\n .[0].vulnerabilities.medium += .[1].vulnerabilities.medium |\n .[0].vulnerabilities.low += .[1].vulnerabilities.low |\n .[0].vulnerabilities.unknown += .[1].vulnerabilities.unknown |\n .[0].unpatched_vulnerabilities.critical += .[1].unpatched_vulnerabilities.critical |\n .[0].unpatched_vulnerabilities.high += .[1].unpatched_vulnerabilities.high |\n .[0].unpatched_vulnerabilities.medium += .[1].unpatched_vulnerabilities.medium |\n .[0].unpatched_vulnerabilities.low += .[1].unpatched_vulnerabilities.low |\n .[0].unpatched_vulnerabilities.unknown += .[1].unpatched_vulnerabilities.unknown |\n .[0]' <<<\"$scan_result $result\")\ndone\n\necho \"$scan_result\" | tee \"/tekton/results/SCAN_OUTPUT\"\n\ntee \"/tekton/results/IMAGES_PROCESSED\" < /tekton/home/images-processed.json\n# shellcheck disable=SC2154\ncat /tekton/home/reports.json > \"/tekton/results/REPORTS\"\n\nnote=\"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.\"\nTEST_OUTPUT=$(make_result_json -r \"SUCCESS\" -t \"$note\")\necho \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n","environment":{"container":"conftest-vulnerabilities","image":"oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b"}}]},{"after":["build-image-index"],"finishedOn":"2026-09-08T21:28:15Z","invocation":{"configSource":{"digest":{"sha256":"f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174"},"entryPoint":"clair-scan","uri":"quay.io/konflux-ci/tekton-catalog/task-clair-scan"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/c9f3725b-9279-45f8-b879-a55b0204f72a","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-9b8cf839b0c121a7-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"clair-scan","tekton.dev/task":"clair-scan"}},"parameters":{"ca-trust-config-map-key":"ca-bundle.crt","ca-trust-config-map-name":"trusted-ca","docker-auth":"","image-digest":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","image-platform":"linux-m2xlarge/arm64","image-url":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","skip-oci-attach-report":"false"}},"name":"clair-scan","ref":{"params":[{"name":"name","value":"clair-scan"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3.2@sha256:f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"IMAGES_PROCESSED","type":"string","value":"{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n"},{"name":"REPORTS","type":"string","value":"{\"sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35\":\"sha256:a05323a823fc519c7d0855b2a6c2572807fc3754d2dd0a822863b3102e568bca\"}\n"},{"name":"SCAN_OUTPUT","type":"string","value":"{\"vulnerabilities\":{\"critical\":0,\"high\":0,\"medium\":0,\"low\":0,\"unknown\":0},\"unpatched_vulnerabilities\":{\"critical\":0,\"high\":9,\"medium\":80,\"low\":59,\"unknown\":3}}\n"},{"name":"TEST_OUTPUT","type":"string","value":"{\"result\":\"SUCCESS\",\"timestamp\":\"2026-09-08T21:28:14+00:00\",\"note\":\"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.\",\"namespace\":\"default\",\"successes\":0,\"failures\":0,\"warnings\":0}\n"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:27Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\necho \"Inspecting raw image manifest $imageanddigest.\"\n\n# Get the arch and image manifests by inspecting the image. This is mainly for identifying image indexes\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_URL\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\nimage_manifests=$(get_image_manifests -i \"${imageanddigest}\")\nif [ -n \"$image_manifests\" ]; then\n echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"' | while read -r arch arch_sha; do\n echo \"$arch_sha\" > \"/tekton/home/image-manifest-${arch}.sha\"\n done\nelse\n echo \"Failed to get image manifests from image \\\"$imageanddigest\\\"\"\n note=\"Task clair-scan failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n","environment":{"container":"get-image-manifests","image":"oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\n\nset -o errexit\nset -o nounset\nset -o pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\n\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_URL\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\n\n# the quay report format used by the Conftest rules in the\n# conftest-vulnerabilities step doesn't contain the \"issued\" date which\n# we require in the policy rules, so we resort to running clair-action\n# twice to produce both quay and clair formatted output\nclair_report() {\n { retry clair-action report --image-ref=\"$1\" --db-path=/tmp/matcher.db --docker-config-dir=/tmp/auth --format=clair | tee \"clair-report-$2.json\"; } && \\\n { retry clair-action convert --file-path=\"clair-report-$2.json\" --format=quay > \"clair-result-$2.json\"; }\n}\n\nrun_clair_on_arch() {\n local arch=\"$1\"\n local sha_file=\"image-manifest-$arch.sha\"\n\n if [ -e \"$sha_file\" ]; then\n local arch_sha\n arch_sha=$(<\"$sha_file\")\n local digest=\"${imagewithouttag}@${arch_sha}\"\n\n echo \"Running clair-action on $arch image manifest...\"\n clair_report \"$digest\" \"$arch\" || true\n\n digests_processed+=(\"\\\"$arch_sha\\\"\")\n fi\n}\n\nplatform=\"${IMAGE_PLATFORM}\"\n\n# If a platform is specified, extract the architecture and run clair-action on the corresponding image manifest\nif [ -n \"$platform\" ]; then\n arch=\"${platform#*/}\"\n if [ \"$arch\" = \"x86_64\" ] || [ \"$arch\" = \"local\" ] || [ \"$arch\" = \"localhost\" ]; then\n arch=\"amd64\"\n fi\n # Validate against supported arch list. If it's not a known arch, fallback to amd64\n case \"$arch\" in\n amd64|ppc64le|arm64|s390x)\n ;;\n *)\n echo \"Error: Unsupported or malformed architecture: '$arch' (parsed from platform: '$platform')\"\n exit 0\n ;;\n esac\n\n run_clair_on_arch \"$arch\"\n\n# If no platform is specified, run clair-action on all available image manifests\nelse\n for sha_file in image-manifest-*.sha; do\n if [ -e \"$sha_file\" ]; then\n arch=$(basename \"$sha_file\" | sed 's/image-manifest-//;s/.sha//')\n run_clair_on_arch \"$arch\"\n fi\n done\nfi\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\n\nimages_processed=\"${images_processed_template/\\[%s]/[$digests_processed_string]}\"\necho \"$images_processed\" > images-processed.json\n","environment":{"container":"get-vulnerabilities","image":"oci://quay.io/konflux-ci/clair-in-ci@sha256:6ed1dbb16de5a87f42df0d11cfb5b6bb0571a56e793b2c702c03e010846d34d5"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\n\nset -o errexit\nset -o nounset\nset -o pipefail\n\nif [ \"$SKIP_OCI_ATTACH_REPORT\" = \"true\" ]; then\n echo 'OCI attach report skipped by parameter.'\n echo '{}' > reports.json\n exit 0\nfi\n\nif ! compgen -G \"clair-report-*.json\" > /dev/null; then\n echo 'No Clair reports generated. Skipping upload.'\n echo '{}' > reports.json\n exit 0\nfi\n\necho \"Selecting auth\"\nselect-oci-auth \"$IMAGE_URL\" > \"$HOME/auth.json\"\n\nrepository=\"${IMAGE_URL/:*/}\"\n\narch() {\n report_file=\"$1\"\n arch=\"${report_file/*-}\"\n echo \"${arch/.json/}\"\n}\n\nMEDIA_TYPE='application/vnd.redhat.clair-report+json'\n\nreports_json=\"\"\nfor f in clair-report-*.json; do\n digest=$(cat \"image-manifest-$(arch \"$f\").sha\")\n image_ref=\"${repository}@${digest}\"\n mkdir -p /tmp/auth && select-oci-auth \"${image_ref}\" > /tmp/auth/config.json\n export DOCKER_CONFIG=/tmp/auth\n echo \"Attaching $f to ${image_ref}\"\n if ! report_digest=\"$(retry oras attach --no-tty --format go-template='{{.digest}}' --registry-config \\\n \"/tmp/auth/config.json\" --artifact-type \"${MEDIA_TYPE}\" \"${image_ref}\" \"$f:${MEDIA_TYPE}\")\"\n then\n echo \"Failed to attach ${f} to ${image_ref}\"\n exit 1\n fi\n # shellcheck disable=SC2016\n reports_json=\"$(yq --output-format json --indent=0 eval-all '. as $i ireduce ({}; . * $i)' <(echo \"${reports_json}\") <(echo \"${digest}: ${report_digest}\"))\"\ndone\necho \"${reports_json}\" > reports.json\n","environment":{"container":"oci-attach-report","image":"oci://quay.io/konflux-ci/task-runner@sha256:1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\nclair_result_files=$(ls /tekton/home/clair-result-*.json)\nif [ -z \"$clair_result_files\" ]; then\n echo \"Previous step [get-vulnerabilities] failed: No clair-result files found in /tekton/home.\"\nfi\n\nmissing_vulnerabilities_files=\"\"\nfor file in $clair_result_files; do\n file_suffix=$(basename \"$file\" | sed 's/clair-result-//;s/.json//')\n if [ ! -s \"$file\" ]; then\n echo \"Previous step [get-vulnerabilities] failed: $file is empty.\"\n else\n /usr/bin/conftest test --no-fail \"$file\" \\\n --policy /project/clair/vulnerabilities-check.rego --namespace required_checks \\\n --output=json | tee \"/tekton/home/clair-vulnerabilities-${file_suffix}.json\" || true\n fi\n\n #check for missing \"clair-vulnerabilities-<arch>/image-index\" file and create a string\n if [ ! -f \"/tekton/home/clair-vulnerabilities-$file_suffix.json\" ]; then\n missing_vulnerabilities_files+=\"${missing_vulnerabilities_files:+, }/tekton/home/clair-vulnerabilities-$file_suffix.json\"\n fi\ndone\n\nif [ -n \"$missing_vulnerabilities_files\" ]; then\n note=\"Task clair-scan failed: $missing_vulnerabilities_files did not generate. For details, check Tekton task log.\"\n TEST_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"$missing_vulnerabilities_files did not generate correctly. For details, check conftest command in Tekton task log.\"\n echo \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n\nscan_result='{\"vulnerabilities\":{\"critical\":0, \"high\":0, \"medium\":0, \"low\":0, \"unknown\":0}, \"unpatched_vulnerabilities\":{\"critical\":0, \"high\":0, \"medium\":0, \"low\":0, \"unknown\":0}}'\nfor file in /tekton/home/clair-vulnerabilities-*.json; do\n result=$(jq -rce \\\n '{\n vulnerabilities:{\n critical: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_critical_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n high: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_high_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n medium: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_medium_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n low: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_low_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n unknown: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unknown_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0)\n },\n unpatched_vulnerabilities:{\n critical: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_critical_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n high: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_high_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n medium: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_medium_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n low: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_low_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n unknown: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_unknown_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0)\n }\n }' \"$file\")\n\n scan_result=$(jq -s -rce \\\n '.[0].vulnerabilities.critical += .[1].vulnerabilities.critical |\n .[0].vulnerabilities.high += .[1].vulnerabilities.high |\n .[0].vulnerabilities.medium += .[1].vulnerabilities.medium |\n .[0].vulnerabilities.low += .[1].vulnerabilities.low |\n .[0].vulnerabilities.unknown += .[1].vulnerabilities.unknown |\n .[0].unpatched_vulnerabilities.critical += .[1].unpatched_vulnerabilities.critical |\n .[0].unpatched_vulnerabilities.high += .[1].unpatched_vulnerabilities.high |\n .[0].unpatched_vulnerabilities.medium += .[1].unpatched_vulnerabilities.medium |\n .[0].unpatched_vulnerabilities.low += .[1].unpatched_vulnerabilities.low |\n .[0].unpatched_vulnerabilities.unknown += .[1].unpatched_vulnerabilities.unknown |\n .[0]' <<<\"$scan_result $result\")\ndone\n\necho \"$scan_result\" | tee \"/tekton/results/SCAN_OUTPUT\"\n\ntee \"/tekton/results/IMAGES_PROCESSED\" < /tekton/home/images-processed.json\n# shellcheck disable=SC2154\ncat /tekton/home/reports.json > \"/tekton/results/REPORTS\"\n\nnote=\"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.\"\nTEST_OUTPUT=$(make_result_json -r \"SUCCESS\" -t \"$note\")\necho \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n","environment":{"container":"conftest-vulnerabilities","image":"oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b"}}]},{"after":["build-image-index","prefetch-dependencies"],"finishedOn":"2026-09-08T21:28:06Z","invocation":{"configSource":{"digest":{"sha256":"99e2263ad98c00b1b44012a325bf0b114684c9f6152fe259ada44e2561a8479e"},"entryPoint":"sast-snyk-check-oci-ta","uri":"quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/40e99c4e-f6c4-40c6-99fe-8ab588258fca","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-b310c749efc05df4-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"sast-snyk-check","tekton.dev/task":"sast-snyk-check-oci-ta"}},"parameters":{"ARGS":"","CACHI2_ARTIFACT":"","EXTRA_ARTIFACT_FILTER":"(^|/)(Dockerfile|Containerfile|[^/]+\\.(sh|bash|zsh|ksh|py|rb|pl|js|mjs|cjs|ts|ps1))$","FETCH_EXTRA_ARTIFACTS":"false","IGNORE_FILE_PATHS":"","IMP_FINDINGS_ONLY":"true","KFP_GIT_URL":"SITE_DEFAULT","PROJECT_NAME":"","RECORD_EXCLUDED":"false","SNYK_SECRET":"snyk-secret","SOURCE_ARTIFACT":"oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735","TARGET_DIRS":".","caTrustConfigMapKey":"ca-bundle.crt","caTrustConfigMapName":"trusted-ca","image-digest":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","image-url":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25"}},"name":"sast-snyk-check","ref":{"params":[{"name":"name","value":"sast-snyk-check-oci-ta"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.5@sha256:99e2263ad98c00b1b44012a325bf0b114684c9f6152fe259ada44e2561a8479e"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"TEST_OUTPUT","type":"string","value":"{\"result\":\"FAILURE\",\"timestamp\":\"2026-09-08T21:28:03+00:00\",\"note\":\"For details, check Tekton task log.\",\"namespace\":\"default\",\"successes\":0,\"failures\":1,\"warnings\":0}\n"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:28Z","status":"Succeeded","steps":[{"annotations":null,"arguments":["use","oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source"],"entryPoint":"","environment":{"container":"use-trusted-artifact","image":"oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:15c5eeb451924ddfc9d8680319130fe277df7850728d5c37f13ae3eb9d607249"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -euo pipefail\n\nif [[ \"${FETCH_EXTRA_ARTIFACTS}\" != \"true\" ]]; then\n exit 0\nfi\n\nif [[ -z \"${IMAGE_URL}\" || -z \"${IMAGE_DIGEST}\" ]]; then\n echo \"INFO: image-url/image-digest missing, cannot fetch extra artifacts\"\n exit 0\nfi\n\ndeclare -a oras_opts=()\n# shellcheck source=/dev/null\nsource /usr/local/bin/oras_opts.sh\n\nIMAGE_REF=\"${IMAGE_URL}@${IMAGE_DIGEST}\"\necho \"INFO: Fetching extra artifacts from OCI reference ${IMAGE_REF}\"\n\nauthfile=\"$(mktemp)\"\ntrap 'rm -f \"${authfile}\"' EXIT\n/usr/local/bin/select-oci-auth.sh \"${IMAGE_URL}\" >\"${authfile}\"\n\nretry oras manifest fetch \"${oras_opts[@]}\" --registry-config \"${authfile}\" \"${IMAGE_REF}\" >\"/tmp/manifest.json\"\n\nconfig_media_type=\"$(jq -r '.config.mediaType // \"\"' /tmp/manifest.json)\"\nif [[ \"${config_media_type}\" == \"application/vnd.oci.image.config.v1+json\" ]] || [[ \"${config_media_type}\" == \"application/vnd.docker.container.image.v1+json\" ]]; then\n echo \"INFO: Reference points to a container image config (${config_media_type}); skipping extra artifact fetch\"\n exit 0\nfi\n\nmkdir -p /var/workdir/source\n\nfetched_count=0\nwhile IFS=$'\\t' read -r digest rel_path; do\n [[ -n \"${rel_path}\" ]] || continue\n if ! printf '%s\\n' \"${rel_path}\" | grep -Eq \"${EXTRA_ARTIFACT_FILTER}\"; then\n continue\n fi\n\n dest_path=\"/var/workdir/source/${rel_path}\"\n resolved_dest=\"$(realpath -m \"${dest_path}\")\"\n if [[ ! \"${resolved_dest}\" == /var/workdir/source/* ]]; then\n echo \"WARN: Skipping path outside source root: ${rel_path}\"\n continue\n fi\n\n mkdir -p \"$(dirname \"${resolved_dest}\")\"\n echo \"INFO: Fetching blob ${digest} -> ${rel_path}\"\n retry oras blob fetch \"${oras_opts[@]}\" --registry-config \"${authfile}\" \"${IMAGE_URL}@${digest}\" --output \"${resolved_dest}\"\n fetched_count=$((fetched_count + 1))\ndone < <(jq -r '.layers[] | [.digest, (.annotations[\"org.opencontainers.image.title\"] // \"\")] | @tsv' /tmp/manifest.json)\n\nif [[ \"${fetched_count}\" -eq 0 ]]; then\n echo \"INFO: No files matched EXTRA_ARTIFACT_FILTER\"\nelse\n echo \"INFO: Fetched ${fetched_count} extra artifact file(s) alongside SOURCE_ARTIFACT\"\nfi\n","environment":{"container":"fetch-extra-artifacts","image":"oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:15c5eeb451924ddfc9d8680319130fe277df7850728d5c37f13ae3eb9d607249"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\n\nset -euo pipefail\n# shellcheck source=/dev/null\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\nif [[ -z \"${PROJECT_NAME}\" ]]; then\n PROJECT_NAME=${COMPONENT_LABEL}\nfi\n\necho \"INFO: The PROJECT_NAME used is: ${PROJECT_NAME}\"\n\nif [[ \"${ARGS}\" != *\"--project-name\"* ]]; then\n ARGS=\"$ARGS --project-name=${PROJECT_NAME}\"\nfi\n\n# Installation of Red Hat certificates for cloning Red Hat internal repositories\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nSNYK_TOKEN_PATH=\"/etc/secrets/snyk_token\"\nif [ -f \"${SNYK_TOKEN_PATH}\" ] && [ -s \"${SNYK_TOKEN_PATH}\" ]; then\n # SNYK token is provided\n SNYK_TOKEN=\"$(cat ${SNYK_TOKEN_PATH})\"\n export SNYK_TOKEN\nelse\n # According to shellcheck documentation, the following error can be ignored as it is ignored through indirection: https://www.shellcheck.net/wiki/SC2034\n # shellcheck disable=SC2034\n to_enable_snyk='[here](https://konflux-ci.dev/docs/testing/build/snyk/)'\n note=\"Task sast-snyk-check-oci-ta skipped: If you wish to use the Snyk code SAST task, please create a secret name snyk-secret with the key 'snyk_token' containing the Snyk token by following the steps given ${to_enable_snyk}\"\n TEST_OUTPUT=$(make_result_json -r SKIPPED -t \"$note\")\n echo \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n\n# Wrapper around snyk code test that maps valid non-zero exit codes (1, 3)\n# to 0 so the existing retry function only retries on exit code 2 (error).\n# Exit codes: 0 = success, 1 = vulnerabilities found, 2 = error, 3 = no supported files\n# The real exit code is always preserved in SNYK_EXIT_CODE.\n# Error codes (2+) always override, valid codes (0, 1, 3) only if no previous error.\n_snyk_code_test() {\n snyk code test \"$@\" 1>&2 >>\"${WORK_DIR}/stdout.txt\"\n local ec=$?\n if [[ \"$ec\" -ne 0 ]] && [[ \"$ec\" -ne 1 ]] && [[ \"$ec\" -ne 3 ]]; then\n SNYK_EXIT_CODE=$ec\n fi\n if [[ \"$ec\" -eq 1 ]] || [[ \"$ec\" -eq 3 ]]; then\n return 0\n fi\n return \"$ec\"\n}\n\n_empty_sarif() {\n local snyk_ver\n snyk_ver=$(snyk --version 2>/dev/null | head -1 | tr -d '\\n' || echo \"unknown\")\n jq -n --arg version \"$snyk_ver\" '{\n \"$schema\": \"https://json.schemastore.org/sarif-2.1.0.json\",\n \"version\": \"2.1.0\",\n \"runs\": [{\n \"tool\": {\n \"driver\": {\n \"name\": \"snyk\",\n \"version\": $version,\n \"informationUri\": \"https://snyk.io\"\n }\n },\n \"results\": [],\n \"properties\": {\n \"coverage\": []\n }\n }]\n }'\n}\n\nSNYK_EXIT_CODE=0\nWORK_DIR=\"$(pwd)\"\nSOURCE_CODE_DIR=/var/workdir/source\n\n# We ignore files using snyk ignore if the user set up the IGNORE_FILE_PATHS variable.\n(cd \"${SOURCE_CODE_DIR}\" && IFS=\",\" && for path in $IGNORE_FILE_PATHS; do\n snyk ignore --file-path=\"${path}\"\ndone)\n\nset +e\necho \"INFO: Running 'snyk code test'..\"\n# We do want to expand ARGS (it can be multiple CLI flags, not just one)\n# shellcheck disable=SC2086\n\n# Generate full paths for each directory in TARGET_DIRS\nIFS=\",\" read -ra TARGETS_ARRAY <<<\"$TARGET_DIRS\"\nfor d in \"${TARGETS_ARRAY[@]}\"; do\n potential_path=\"${SOURCE_CODE_DIR}/${d}\"\n resolved_path=$(realpath -m \"$potential_path\")\n\n # Ensure resolved path is still within SOURCE_CODE_DIR\n if [[ ! \"$resolved_path\" == \"$SOURCE_CODE_DIR\"* ]]; then\n echo \"Error: path traversal attempt, '$potential_path' is outside '$SOURCE_CODE_DIR'\"\n exit 1\n fi\n\n # Ensure directory exists\n if [ ! -d \"$resolved_path\" ]; then\n echo \"Warning: Directory $resolved_path does not exist, skipping\"\n continue\n fi\n\n echo \"INFO: Scanning directory: $resolved_path\"\n # We do want to expand ARGS (it can be multiple CLI flags, not just one)\n # shellcheck disable=SC2086\n RETRY_INTERVAL=30 retry _snyk_code_test $ARGS \"$resolved_path\" --max-depth=1 --sarif-file-output=\"${resolved_path}/sast_snyk_check_out_${d//\\//_}.json\"\n\n sarif_out=\"${resolved_path}/sast_snyk_check_out_${d//\\//_}.json\"\n if [[ \"$d\" != \".\" && -f \"$sarif_out\" ]]; then\n prefix=\"${d%/}/\"\n echo \"INFO: Prepending path prefix '${prefix}' to ${sarif_out}\"\n csgrep --mode=sarif --prepend-path-prefix=\"$prefix\" \"$sarif_out\" >\"${sarif_out}.tmp\" && mv \"${sarif_out}.tmp\" \"$sarif_out\"\n fi\n\ndone\n\n# Merge all per-target SARIF outputs into a single valid SARIF file\nshopt -s globstar nullglob\ncd \"${SOURCE_CODE_DIR}\" || exit 1\nsarif_files=(./**/sast_snyk_check_out_*.json)\nif [[ ${#sarif_files[@]} -gt 0 ]]; then\n csgrep --mode=sarif \"${sarif_files[@]}\" >\"${SOURCE_CODE_DIR}/sast_snyk_check_out.json\" 2>\"${WORK_DIR}/csgrep_merge.err\" || {\n echo \"WARN: Failed to merge SARIF files with csgrep, creating empty SARIF\"\n cat \"${WORK_DIR}/csgrep_merge.err\" >&2\n _empty_sarif >\"${SOURCE_CODE_DIR}/sast_snyk_check_out.json\"\n }\nelse\n echo \"WARN: No SARIF output files found, creating empty SARIF\"\n _empty_sarif >\"${SOURCE_CODE_DIR}/sast_snyk_check_out.json\"\nfi\nshopt -u globstar nullglob\ncd \"${WORK_DIR}\" || exit 1\nset -e\ntest_not_skipped=0\nSKIP_MSG=\"We found 0 supported files\"\ngrep -q \"$SKIP_MSG\" \"${WORK_DIR}/stdout.txt\" || test_not_skipped=$?\n\nif [[ \"$SNYK_EXIT_CODE\" -eq 0 ]] || [[ \"$SNYK_EXIT_CODE\" -eq 1 ]]; then\n # Check if the merged SARIF file has content - this could happen if the snyk scan found no findings\n if [ ! -s \"${SOURCE_CODE_DIR}/sast_snyk_check_out.json\" ]; then\n echo \"WARN: No JSON output files were generated by snyk scan\"\n _empty_sarif >\"${SOURCE_CODE_DIR}/sast_snyk_check_out.json\"\n fi\n\n # In order to generate csdiff/v1, we need to add the whole path of the source code as Snyk only provides an URI to embed the context\n (cd \"${SOURCE_CODE_DIR}\" && csgrep --mode=json --embed-context=3 \"${SOURCE_CODE_DIR}\"/sast_snyk_check_out.json) \\\n >sast_snyk_check_out_all_findings.json\n\n echo \"INFO: Initial results:\"\n csgrep --mode=evtstat sast_snyk_check_out_all_findings.json\n csgrep sast_snyk_check_out_all_findings.json\n\n if [[ \"${KFP_GIT_URL}\" == \"SITE_DEFAULT\" ]]; then\n KFP_GIT_URL=\"https://gitlab.cee.redhat.com/osh/known-false-positives.git\"\n fi\n PROBE_URL=\"${KFP_GIT_URL%.git}\" # trims '.git' suffix\n\n # create the KFP clone directory regardless\n KFP_DIR=\"known-false-positives\"\n KFP_CLONED=\"0\"\n mkdir -p \"${KFP_DIR}\"\n\n # We check if the KFP_GIT_URL variable is set to clone and apply the filters or not\n if [[ -n \"${KFP_GIT_URL}\" ]]; then\n # Default location only reachable from internal Konflux instances, check reachable first\n echo -n \"INFO: Probing ${PROBE_URL}... \"\n if curl --fail --head --max-time 60 --no-progress-meter \"${PROBE_URL}\" > >(head -1); then\n echo \"INFO: Trying to clone known-false-positives..\"\n git clone \"${KFP_GIT_URL}\" \"${KFP_DIR}\" && KFP_CLONED=\"1\"\n fi\n fi\n\n if [[ \"${KFP_CLONED}\" -eq \"0\" ]]; then\n echo \"WARN: Failed to clone known-false-positives at ${KFP_GIT_URL}, scan results will not be filtered\"\n mv sast_snyk_check_out_all_findings.json filtered_sast_snyk_check_out.json\n else\n echo \"INFO: Filtering false positives in results files using csfilter-kfp...\"\n\n CMD=(\n csfilter-kfp\n --verbose\n --kfp-dir=\"${KFP_DIR}\"\n --project-nvr=\"${PROJECT_NAME}\"\n )\n\n if [ \"${RECORD_EXCLUDED}\" == \"true\" ]; then\n CMD+=(--record-excluded=\"excluded-findings.json\")\n fi\n\n set +e\n \"${CMD[@]}\" sast_snyk_check_out_all_findings.json >filtered_sast_snyk_check_out.json\n status=$?\n set -e\n if [ \"$status\" -ne 0 ]; then\n echo \"WARN: failed to filter known false positives\" >&2\n else\n echo \"INFO: Succeeded filtering known false positives\" >&2\n fi\n echo \"INFO: Results after filtering:\"\n (set -x && csgrep --mode=evtstat filtered_sast_snyk_check_out.json)\n csgrep filtered_sast_snyk_check_out.json\n fi\n\n # Generation of scan stats\n\n total_files=$(jq '[(.runs[0].properties.coverage // [])[].files] | add' \"${SOURCE_CODE_DIR}\"/sast_snyk_check_out.json)\n supported_files=$(jq '[(.runs[0].properties.coverage // [])[] | select(.type == \"SUPPORTED\") | .files] | add' \"${SOURCE_CODE_DIR}\"/sast_snyk_check_out.json)\n\n # We make sure the values are 0 if no supported/total files are found\n if [ \"$total_files\" = \"null\" ] || [ -z \"$total_files\" ]; then\n total_files=0\n fi\n\n if [ \"$supported_files\" = \"null\" ] || [ -z \"$supported_files\" ]; then\n supported_files=0\n fi\n\n coverage_ratio=0\n if ((total_files > 0)); then\n coverage_ratio=$((supported_files * 100 / total_files))\n fi\n\n # embed stats in results file and convert to SARIF\n csgrep --mode=sarif --set-scan-prop snyk-scanned-files-coverage:\"${coverage_ratio}\" \\\n --set-scan-prop snyk-scanned-files-success:\"${supported_files}\" \\\n --set-scan-prop snyk-scanned-files-total:\"${total_files}\" \\\n filtered_sast_snyk_check_out.json >sast_snyk_check_out.sarif\n\n # Create filtered SARIF for Tekton task result based on IMP_FINDINGS_ONLY parameter\n if [ \"${IMP_FINDINGS_ONLY}\" == \"true\" ]; then\n # Filter to only \"error\" level or higher (high/critical severity) for Tekton task result\n # In SARIF, defects are given a level like \"error\" or \"warning\". Snyk maps \"high\" level findings to \"error\".\n # - \"error\" → importance level 1\n # - \"warning\" (or missing level) → importance level 0\n RESULT_SARIF=\"result_sast_snyk_check_out.sarif\"\n csgrep --mode=sarif --imp-level 1 sast_snyk_check_out.sarif >\"$RESULT_SARIF\"\n else\n # Use all findings for Tekton task result\n RESULT_SARIF=\"sast_snyk_check_out.sarif\"\n fi\n\n TEST_OUTPUT=\n parse_test_output \"sast-snyk-check-oci-ta\" sarif \"$RESULT_SARIF\" || true\n\n# When the test is skipped, the \"SNYK_EXIT_CODE\" is 3 and it can also be 3 in some other situation\nelif [[ \"$test_not_skipped\" -eq 0 ]]; then\n note=\"Task sast-snyk-check-oci-ta success: Snyk code test found zero supported files.\"\n ERROR_OUTPUT=$(make_result_json -r SUCCESS -t \"$note\")\nelse\n echo \"sast-snyk-check test failed because of the following issues:\"\n cat \"${WORK_DIR}/stdout.txt\"\n note=\"Task sast-snyk-check-oci-ta failed: For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\nfi\necho \"${TEST_OUTPUT:-${ERROR_OUTPUT}}\" | tee \"/tekton/results/TEST_OUTPUT\"\n","environment":{"container":"sast-snyk-check","image":"oci://quay.io/konflux-ci/konflux-test@sha256:04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\n\nif [ -z \"${IMAGE_URL}\" ]; then\n echo 'No image-url provided. Skipping upload.'\n exit 0\nfi\n\nUPLOAD_FILES=\"sast_snyk_check_out.sarif excluded-findings.json\"\nfor UPLOAD_FILE in ${UPLOAD_FILES}; do\n if [ ! -f \"${UPLOAD_FILE}\" ]; then\n echo \"No ${UPLOAD_FILE} exists. Skipping upload.\"\n continue\n fi\n if [ \"${UPLOAD_FILE}\" == \"excluded-findings.json\" ]; then\n MEDIA_TYPE=application/json\n else\n MEDIA_TYPE=application/sarif+json\n fi\n echo \"Selecting auth\"\n select-oci-auth \"${IMAGE_URL}\" >\"${HOME}/auth.json\"\n echo \"Attaching to ${IMAGE_URL}\"\n if ! retry oras attach --no-tty --registry-config \"$HOME/auth.json\" --artifact-type \"${MEDIA_TYPE}\" \"${IMAGE_URL}@${IMAGE_DIGEST}\" \"${UPLOAD_FILE}:${MEDIA_TYPE}\"; then\n echo \"Failed to attach to ${IMAGE_URL}\"\n fi\ndone\n","environment":{"container":"upload","image":"oci://quay.io/konflux-ci/oras@sha256:1cc659b4d30536ec98300ac551739ef36dee345a7dcfe06129fd78abdc3688ac"}}]},{"after":["build-image-index"],"finishedOn":"2026-09-08T21:27:58Z","invocation":{"configSource":{"digest":{"sha256":"9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b"},"entryPoint":"clamav-scan","uri":"quay.io/konflux-ci/tekton-catalog/task-clamav-scan"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/fccb52f7-3e0b-4594-92b9-830eb0cac21a","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"virus, konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-de9669d9fc05ea3e-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"clamav-scan","tekton.dev/task":"clamav-scan"}},"parameters":{"ca-trust-config-map-key":"ca-bundle.crt","ca-trust-config-map-name":"trusted-ca","clamd-max-threads":"8","docker-auth":"","image-arch":"linux/x86_64","image-digest":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","image-url":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","skip-upload":"false"}},"name":"clamav-scan","ref":{"params":[{"name":"name","value":"clamav-scan"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.3.3@sha256:9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"IMAGES_PROCESSED","type":"string","value":"{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n"},{"name":"TEST_OUTPUT","type":"string","value":"{\"timestamp\":\"1788902874\",\"namespace\":\"required_checks\",\"successes\":2,\"failures\":0,\"warnings\":0,\"result\":\"SUCCESS\",\"note\":\"All checks passed successfully\"}\n"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:28Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\n# Start clamd in background\n/start-clamd.sh\n\n# Bootstrap .docker config in overridden HOME.\n# This prevents 'oc' CLI failures in clean environments where ~/.docker does not exist.\nif [ ! -d ~/.docker ]; then\n mkdir -p ~/.docker\n echo '{}' > ~/.docker/config.json\nfi\n\nimagewithouttag=$(echo \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\" | tr -d '\\n')\n\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\n\n# check if image is attestation one, skip the clamav scan in such case\nif [[ $imageanddigest == *.att ]]\nthen\n echo \"$imageanddigest is an attestation image. Skipping ClamAV scan.\"\n exit 0\nfi\n\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\nmkdir logs\nmkdir content\ncd content\necho \"Detecting artifact type for ${imageanddigest}.\"\necho '{\"artifact\":{\"pullspec\":\"'\"${imageanddigest}\"'\",\"type\":\"unknown\",\"mediaType\":\"\"}}' > /work/logs/artifact-meta.json\n\n# Function to scan content and process results with ClamAV and EC\n# Parameters:\n# $1: destination - path to the content to scan\n# $2: suffix - suffix for log file names (e.g., \"oci\", \"amd64\")\n# $3: digest - digest to add to digests_processed array\n# $4: scan_message - optional message describing what is being scanned\nscan_and_process() {\n local destination=\"$1\"\n local suffix=\"$2\"\n local digest=\"$3\"\n local scan_message=\"${4:-Scanning content}\"\n\n db_version=$(clamdscan --version | sed 's|.*/\\(.*\\)/.*|\\1|')\n\n echo \"$scan_message. This operation may take a while.\"\n clamdscan \"${destination}\" -vi --multiscan --fdpass \\\n | tee \"/work/logs/clamscan-result-${suffix}.log\" || true\n\n echo \"Executed-on: Scan was executed on clamsdcan version - $(clamdscan --version) Database version: $db_version\" | tee -a \"/work/logs/clamscan-result-${suffix}.log\"\n\n digests_processed+=(\"\\\"$digest\\\"\")\n\n if [[ -e \"/work/logs/clamscan-result-${suffix}.log\" ]]; then\n # OPA/EC requires structured data input, add clamAV log into json\n jq -Rs '{ output: . }' \"/work/logs/clamscan-result-${suffix}.log\" > \"/work/logs/clamscan-result-log-${suffix}.json\"\n\n EC_EXPERIMENTAL=1 ec test \\\n --namespace required_checks \\\n --policy /project/clamav/virus-check.rego \\\n -o json \\\n \"/work/logs/clamscan-result-log-${suffix}.json\" || true\n\n # workaround: due to a bug in ec-cli, we cannot generate json and appstudio output at the same time, running it again\n EC_EXPERIMENTAL=1 ec test \\\n --namespace required_checks \\\n --policy /project/clamav/virus-check.rego \\\n -o appstudio \\\n \"/work/logs/clamscan-result-log-${suffix}.json\" | tee \"/work/logs/clamscan-ec-test-${suffix}.json\" || true\n\n cat \"/work/logs/clamscan-ec-test-${suffix}.json\"\n fi\n}\n\n# Skip extract only when every real file is a known weight type.\nis_weight_filename() {\n local base=\"$1\"\n case \"$base\" in\n *.safetensors|*.gguf|*.ggml|*.pt|*.pth|*.onnx|*.onnx_data|*.onnx_data_*) return 0 ;;\n *) return 1 ;;\n esac\n}\n\n# 2000MiB: slightly under ClamAV's ~2GiB MaxFileSize (0.2 used --max-filesize=2000M).\nCLAMAV_SKIP_BLOB_BYTES=2097152000\n\n# listing = stdout of: oc image extract --dry-run\nis_weight_only_layer() {\n local listing=\"$1\"\n local mode entry base\n # Fail closed: empty stdout is not evidence the layer is weight-only.\n [[ -z \"${listing}\" ]] && return 1\n while IFS= read -r line; do\n [ -z \"$line\" ] && continue\n mode=$(awk '{print $2}' <<< \"$line\")\n [[ \"$mode\" == d* ]] && continue\n [[ \"$line\" == *\" -> \"* ]] && return 1\n entry=$(awk '{print $NF}' <<< \"$line\")\n base=$(basename \"$entry\")\n [[ \"$base\" == .wh.* ]] && continue\n is_weight_filename \"$base\" || return 1\n done <<< \"$listing\"\n return 0\n}\n\n# title/path from the OCI layer descriptor (olot ModelCars). Empty is not a skip.\nlayer_annotation_is_weight() {\n local title=\"$1\" inpath=\"$2\" base candidate\n for candidate in \"$title\" \"$inpath\"; do\n [ -z \"$candidate\" ] && continue\n base=$(basename \"$candidate\")\n is_weight_filename \"$base\" && return 0\n done\n return 1\n}\n\n# Detect artifact type: container image vs OCI artifact\n# First, try to get image manifests (works for container images)\n# Use subshell to prevent get_image_manifests() from exiting the main script if it fails\n# (get_image_manifests uses exit 1 when Architecture field is missing, which happens for OCI artifacts)\nimage_manifests=$(bash -c '. /utils.sh; get_image_manifests -i \"'\"${imageanddigest}\"'\"' 2>/dev/null || echo \"\")\n\n# If get_image_manifests failed, check if it's an OCI artifact by inspecting manifest media type\nif [ -z \"$image_manifests\" ]; then\n echo \"get_image_manifests returned empty, checking if this is an OCI artifact...\"\n raw_manifest=$(skopeo inspect --raw --authfile ~/.docker/config.json \"docker://${imageanddigest}\" 2>/dev/null || true)\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.type = \"inspected\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n\n if [ -n \"$raw_manifest\" ]; then\n media_type=$(echo \"$raw_manifest\" | jq -r '.mediaType // .config.mediaType // empty' 2>/dev/null || echo \"\")\n artifact_type=$(echo \"$raw_manifest\" | jq -r '.artifactType // empty' 2>/dev/null || echo \"\")\n config_media_type=$(echo \"$raw_manifest\" | jq -r '.config.mediaType // empty' 2>/dev/null || echo \"\")\n\n # Determine if this is an OCI artifact (not a container image)\n # OCI artifacts typically have:\n # - An empty/scratch config (config.mediaType contains \"empty\" or \"scratch\")\n # - An explicit artifactType field that is not a container image type\n is_oci_artifact=false\n\n # Check if config is empty/scratch (typical for OCI artifacts like python wheels, helm charts, etc.)\n if echo \"$config_media_type\" | grep -qiE \"(empty|scratch)\"; then\n is_oci_artifact=true\n fi\n\n # Check if artifactType is set and is not a container image type\n if [ -n \"$artifact_type\" ] && ! echo \"$artifact_type\" | grep -qE \"application/vnd\\.(oci|docker)\\.(image|container)\"; then\n is_oci_artifact=true\n fi\n\n if [ \"$is_oci_artifact\" = true ]; then\n # This is an OCI artifact (e.g., python wheels, helm charts, etc.)\n echo \"Detected OCI artifact (artifactType: ${artifact_type:-unset}, config.mediaType: ${config_media_type:-unset}). Downloading for scanning...\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"${media_type:-unknown}\\\"\"' | .artifact.artifactType = '\"\\\"${artifact_type:-unknown}\\\"\"' | .artifact.type = \"oci\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n destination=\"content-oci\"\n mkdir -p \"$destination\"\n\n # Download OCI artifact using skopeo copy\n echo \"Downloading OCI artifact using skopeo copy\"\n if ! retry skopeo copy --authfile ~/.docker/config.json \"docker://${imageanddigest}\" \"dir:${destination}\" 2>&1; then\n echo \"Failed to download OCI artifact \\\"$imageanddigest\\\". Skipping ClamAV scan!\"\n note=\"Task clamav-scan failed: Failed to download OCI artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n\n # Scan and process OCI artifact\n scan_and_process \"${destination}\" \"oci\" \"$IMAGE_DIGEST\" \"Scanning OCI artifact\"\n\n # Skip the container image processing path\n image_manifests=\"\"\n elif echo \"$media_type\" | grep -qE \"(application/vnd\\.(docker|oci)\\.(distribution|image)\\.manifest|application/vnd\\.docker\\.distribution\\.manifest)\"; then\n # This looks like a container image manifest, but get_image_manifests failed\n echo \"Detected container image manifest type: $media_type, but get_image_manifests failed. This may indicate an error.\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"$media_type\\\"\"' | .artifact.type = \"image\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n note=\"Task clamav-scan failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n else\n # Likely an OCI artifact with non-standard media type\n echo \"Detected OCI artifact (media type: ${media_type:-unknown}). Downloading for scanning...\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"${media_type:-unknown}\\\"\"' | .artifact.type = \"oci\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n destination=\"content-oci\"\n mkdir -p \"$destination\"\n\n # Download OCI artifact using skopeo copy\n echo \"Downloading OCI artifact using skopeo copy\"\n if ! retry skopeo copy --authfile ~/.docker/config.json \"docker://${imageanddigest}\" \"dir:${destination}\" 2>&1; then\n echo \"Failed to download OCI artifact \\\"$imageanddigest\\\". Skipping ClamAV scan!\"\n note=\"Task clamav-scan failed: Failed to download OCI artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n\n # Scan and process OCI artifact\n scan_and_process \"${destination}\" \"oci\" \"$IMAGE_DIGEST\" \"Scanning OCI artifact\"\n\n # Skip the container image processing path\n image_manifests=\"\"\n fi\n else\n echo \"Failed to inspect artifact \\\"$imageanddigest\\\". Unable to determine type.\"\n note=\"Task clamav-scan failed: Failed to inspect artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\nfi\n\n# Process container images (existing logic)\nif [ -n \"$image_manifests\" ]; then\n echo \"Detected container image. Processing image manifests.\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.type = \"image\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n # Proceed only if a specific arch is provided.\n # This typically occurs when using Tekton Matrix to launch multiple TaskRuns to scan all architectures of a multi-arch image in parallel.\n if [ -n \"$IMAGE_ARCH\" ]; then\n arch=\"${IMAGE_ARCH#*/}\"\n if [ \"${arch}\" = \"x86_64\" ]; then\n arch=\"amd64\"\n fi\n\n # Check if arch is supported; if not (e.g., it's 'local', see link below), default to amd64.\n # https://github.com/redhat-appstudio/infra-deployments/blob/main/components/multi-platform-controller/production/stone-prd-rh01/host-config.yaml#L9-L14\n case \"$arch\" in\n amd64|ppc64le|arm64|s390x)\n ;;\n *)\n arch=\"amd64\"\n ;;\n esac\n\n image_manifests=$(echo \"$image_manifests\" | jq -c --arg arch \"$arch\" '{($arch): .[$arch]}')\n fi\n\n while read -r arch arch_sha; do\n destination=\"content-${arch}\"\n mkdir -p \"$destination\"\n arch_imageanddigest=\"${imagewithouttag}@${arch_sha}\"\n\n echo \"Inspecting layers for arch $arch\"\n skip_log=\"\"\n layers=$(skopeo inspect --raw --authfile ~/.docker/config.json \\\n \"docker://${arch_imageanddigest}\" | jq -c '\n .layers[]? | {\n digest: (.digest // \"\"),\n size: ((.size // 0) | if type == \"number\" then . else 0 end),\n title: (.annotations[\"org.opencontainers.image.title\"] // \"\"),\n inpath: (.annotations[\"olot.layer.content.inlayerpath\"] // \"\")\n }') || layers=\"\"\n\n if [ -z \"${layers}\" ]; then\n echo \"Could not list layers; extracting full image\"\n if ! retry oc image extract --confirm --only-files=true \\\n --registry-config ~/.docker/config.json \"$arch_imageanddigest\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"; then\n echo \"Unable to extract image for arch $arch. Skipping ClamAV scan!\"\n exit 0\n fi\n else\n skip_log=\"/work/logs/skipped-layers-${arch}.log\"\n : > \"$skip_log\"\n while IFS= read -r layer_json; do\n [ -z \"$layer_json\" ] && continue\n digest=$(jq -r '.digest' <<< \"$layer_json\")\n size=$(jq -r '.size' <<< \"$layer_json\")\n title=$(jq -r '.title' <<< \"$layer_json\")\n inpath=$(jq -r '.inpath' <<< \"$layer_json\")\n [ -z \"$digest\" ] && continue\n\n if layer_annotation_is_weight \"$title\" \"$inpath\"; then\n echo \"Skipping unscannable weight layer ${digest} (manifest ${title:-$inpath})\" | tee -a \"$skip_log\"\n continue\n fi\n\n if { [ -n \"$title\" ] || [ -n \"$inpath\" ]; } && [ \"${size}\" -ge \"${CLAMAV_SKIP_BLOB_BYTES}\" ]; then\n echo \"Skipping unscannable layer ${digest} (manifest ${title:-$inpath}, size ${size})\" | tee -a \"$skip_log\"\n continue\n fi\n\n if [ -z \"$title\" ] && [ -z \"$inpath\" ]; then\n echo \"Listing layer ${digest}\"\n if listing=$(retry oc image extract --dry-run --confirm \\\n --registry-config ~/.docker/config.json \\\n \"${arch_imageanddigest}[~${digest}]\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"); then\n if is_weight_only_layer \"${listing}\"; then\n echo \"Skipping unscannable weight layer ${digest}\" | tee -a \"$skip_log\"\n continue\n fi\n else\n echo \"Failed to list layer ${digest}; extracting it\"\n fi\n fi\n\n if ! retry oc image extract --confirm --only-files=true \\\n --registry-config ~/.docker/config.json \\\n \"${arch_imageanddigest}[~${digest}]\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"; then\n echo \"Unable to extract layer ${digest} for arch $arch. Skipping ClamAV scan!\"\n exit 0\n fi\n done <<< \"$layers\"\n fi\n\n # Scan and process container image for this architecture\n scan_and_process \"${destination}\" \"$arch\" \"$arch_sha\" \"Scanning image for arch $arch\"\n\n if [ -s \"${skip_log}\" ]; then\n cat \"$skip_log\" >> \"/work/logs/clamscan-result-${arch}.log\"\n fi\n done < <(echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"')\nfi\n\njq -s -rce '\n reduce .[] as $item ({\"timestamp\":\"0\",\"namespace\":\"\",\"successes\":0,\"failures\":0,\"warnings\":0,\"result\":\"\",\"note\":\"\"};\n {\n \"timestamp\" : (if .timestamp < $item.timestamp then $item.timestamp else .timestamp end),\n \"namespace\" : $item.namespace,\n \"successes\" : (.successes + $item.successes),\n \"failures\" : (.failures + $item.failures),\n \"warnings\" : (.warnings + $item.warnings),\n \"result\" : (if .result == \"\" or ($item.result == \"SKIPPED\" and .result == \"SUCCESS\") or ($item.result == \"WARNING\" and (.result == \"SUCCESS\" or .result == \"SKIPPED\")) or ($item.result == \"FAILURE\" and .result != \"ERROR\") or $item.result == \"ERROR\" then $item.result else .result end),\n \"note\" : (if .result == \"\" or ($item.result == \"SKIPPED\" and .result == \"SUCCESS\") or ($item.result == \"WARNING\" and (.result == \"SUCCESS\" or .result == \"SKIPPED\")) or ($item.result == \"FAILURE\" and .result != \"ERROR\") or $item.result == \"ERROR\" then $item.note else .note end)\n })' /work/logs/clamscan-ec-test-*.json | tee \"/tekton/results/TEST_OUTPUT\"\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\n\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\necho \"${images_processed_template/\\[%s]/[$digests_processed_string]}\" | tee \"/tekton/results/IMAGES_PROCESSED\"\n","environment":{"container":"extract-and-scan-image","image":"oci://quay.io/konflux-ci/clamav-db@sha256:60297bb97fd977731706a64e252d969b81234422b0da065d9b9a57e9b103e74c"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -e\n\n# Skip upload if requested e.g. read-only CI tests where push access is denied\nif [ \"$SKIP_UPLOAD\" == \"true\" ]; then\n echo \"Upload skipped by parameter.\"\n exit 0\nfi\n\n# Don't return a glob expression when no matches are found\nshopt -s nullglob\n\ncd logs\n\nfor UPLOAD_FILE in clamscan-result*.log; do\n MEDIA_TYPE=text/vnd.clamav\n args+=(\"${UPLOAD_FILE}:${MEDIA_TYPE}\")\ndone\nfor UPLOAD_FILE in clamscan-ec-test*.json; do\n MEDIA_TYPE=application/vnd.konflux.test_output+json\n args+=(\"${UPLOAD_FILE}:${MEDIA_TYPE}\")\ndone\n\nif [ ${#args[@]} -eq 0 ]; then\n echo \"No files found. Skipping upload.\"\n exit 0;\nfi\n\necho \"Selecting auth\"\nselect-oci-auth \"$IMAGE_URL\" > \"$HOME/auth.json\"\necho \"Attaching to ${IMAGE_URL}\"\n retry oras attach --no-tty --registry-config \"$HOME/auth.json\" --artifact-type application/vnd.clamav \"${IMAGE_URL}@${IMAGE_DIGEST}\" \"${args[@]}\"\n","environment":{"container":"upload","image":"oci://quay.io/konflux-ci/task-runner@sha256:1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab"}}]},{"after":["build-image-index"],"finishedOn":"2026-09-08T21:27:58Z","invocation":{"configSource":{"digest":{"sha256":"9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b"},"entryPoint":"clamav-scan","uri":"quay.io/konflux-ci/tekton-catalog/task-clamav-scan"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/abbcb159-67ef-4265-8f2e-a547fa899ad7","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"virus, konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-e66ae890756fcd77-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"clamav-scan","tekton.dev/task":"clamav-scan"}},"parameters":{"ca-trust-config-map-key":"ca-bundle.crt","ca-trust-config-map-name":"trusted-ca","clamd-max-threads":"8","docker-auth":"","image-arch":"linux/ppc64le","image-digest":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","image-url":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","skip-upload":"false"}},"name":"clamav-scan","ref":{"params":[{"name":"name","value":"clamav-scan"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.3.3@sha256:9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"IMAGES_PROCESSED","type":"string","value":"{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n"},{"name":"TEST_OUTPUT","type":"string","value":"{\"timestamp\":\"1788902875\",\"namespace\":\"required_checks\",\"successes\":2,\"failures\":0,\"warnings\":0,\"result\":\"SUCCESS\",\"note\":\"All checks passed successfully\"}\n"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:28Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\n# Start clamd in background\n/start-clamd.sh\n\n# Bootstrap .docker config in overridden HOME.\n# This prevents 'oc' CLI failures in clean environments where ~/.docker does not exist.\nif [ ! -d ~/.docker ]; then\n mkdir -p ~/.docker\n echo '{}' > ~/.docker/config.json\nfi\n\nimagewithouttag=$(echo \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\" | tr -d '\\n')\n\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\n\n# check if image is attestation one, skip the clamav scan in such case\nif [[ $imageanddigest == *.att ]]\nthen\n echo \"$imageanddigest is an attestation image. Skipping ClamAV scan.\"\n exit 0\nfi\n\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\nmkdir logs\nmkdir content\ncd content\necho \"Detecting artifact type for ${imageanddigest}.\"\necho '{\"artifact\":{\"pullspec\":\"'\"${imageanddigest}\"'\",\"type\":\"unknown\",\"mediaType\":\"\"}}' > /work/logs/artifact-meta.json\n\n# Function to scan content and process results with ClamAV and EC\n# Parameters:\n# $1: destination - path to the content to scan\n# $2: suffix - suffix for log file names (e.g., \"oci\", \"amd64\")\n# $3: digest - digest to add to digests_processed array\n# $4: scan_message - optional message describing what is being scanned\nscan_and_process() {\n local destination=\"$1\"\n local suffix=\"$2\"\n local digest=\"$3\"\n local scan_message=\"${4:-Scanning content}\"\n\n db_version=$(clamdscan --version | sed 's|.*/\\(.*\\)/.*|\\1|')\n\n echo \"$scan_message. This operation may take a while.\"\n clamdscan \"${destination}\" -vi --multiscan --fdpass \\\n | tee \"/work/logs/clamscan-result-${suffix}.log\" || true\n\n echo \"Executed-on: Scan was executed on clamsdcan version - $(clamdscan --version) Database version: $db_version\" | tee -a \"/work/logs/clamscan-result-${suffix}.log\"\n\n digests_processed+=(\"\\\"$digest\\\"\")\n\n if [[ -e \"/work/logs/clamscan-result-${suffix}.log\" ]]; then\n # OPA/EC requires structured data input, add clamAV log into json\n jq -Rs '{ output: . }' \"/work/logs/clamscan-result-${suffix}.log\" > \"/work/logs/clamscan-result-log-${suffix}.json\"\n\n EC_EXPERIMENTAL=1 ec test \\\n --namespace required_checks \\\n --policy /project/clamav/virus-check.rego \\\n -o json \\\n \"/work/logs/clamscan-result-log-${suffix}.json\" || true\n\n # workaround: due to a bug in ec-cli, we cannot generate json and appstudio output at the same time, running it again\n EC_EXPERIMENTAL=1 ec test \\\n --namespace required_checks \\\n --policy /project/clamav/virus-check.rego \\\n -o appstudio \\\n \"/work/logs/clamscan-result-log-${suffix}.json\" | tee \"/work/logs/clamscan-ec-test-${suffix}.json\" || true\n\n cat \"/work/logs/clamscan-ec-test-${suffix}.json\"\n fi\n}\n\n# Skip extract only when every real file is a known weight type.\nis_weight_filename() {\n local base=\"$1\"\n case \"$base\" in\n *.safetensors|*.gguf|*.ggml|*.pt|*.pth|*.onnx|*.onnx_data|*.onnx_data_*) return 0 ;;\n *) return 1 ;;\n esac\n}\n\n# 2000MiB: slightly under ClamAV's ~2GiB MaxFileSize (0.2 used --max-filesize=2000M).\nCLAMAV_SKIP_BLOB_BYTES=2097152000\n\n# listing = stdout of: oc image extract --dry-run\nis_weight_only_layer() {\n local listing=\"$1\"\n local mode entry base\n # Fail closed: empty stdout is not evidence the layer is weight-only.\n [[ -z \"${listing}\" ]] && return 1\n while IFS= read -r line; do\n [ -z \"$line\" ] && continue\n mode=$(awk '{print $2}' <<< \"$line\")\n [[ \"$mode\" == d* ]] && continue\n [[ \"$line\" == *\" -> \"* ]] && return 1\n entry=$(awk '{print $NF}' <<< \"$line\")\n base=$(basename \"$entry\")\n [[ \"$base\" == .wh.* ]] && continue\n is_weight_filename \"$base\" || return 1\n done <<< \"$listing\"\n return 0\n}\n\n# title/path from the OCI layer descriptor (olot ModelCars). Empty is not a skip.\nlayer_annotation_is_weight() {\n local title=\"$1\" inpath=\"$2\" base candidate\n for candidate in \"$title\" \"$inpath\"; do\n [ -z \"$candidate\" ] && continue\n base=$(basename \"$candidate\")\n is_weight_filename \"$base\" && return 0\n done\n return 1\n}\n\n# Detect artifact type: container image vs OCI artifact\n# First, try to get image manifests (works for container images)\n# Use subshell to prevent get_image_manifests() from exiting the main script if it fails\n# (get_image_manifests uses exit 1 when Architecture field is missing, which happens for OCI artifacts)\nimage_manifests=$(bash -c '. /utils.sh; get_image_manifests -i \"'\"${imageanddigest}\"'\"' 2>/dev/null || echo \"\")\n\n# If get_image_manifests failed, check if it's an OCI artifact by inspecting manifest media type\nif [ -z \"$image_manifests\" ]; then\n echo \"get_image_manifests returned empty, checking if this is an OCI artifact...\"\n raw_manifest=$(skopeo inspect --raw --authfile ~/.docker/config.json \"docker://${imageanddigest}\" 2>/dev/null || true)\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.type = \"inspected\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n\n if [ -n \"$raw_manifest\" ]; then\n media_type=$(echo \"$raw_manifest\" | jq -r '.mediaType // .config.mediaType // empty' 2>/dev/null || echo \"\")\n artifact_type=$(echo \"$raw_manifest\" | jq -r '.artifactType // empty' 2>/dev/null || echo \"\")\n config_media_type=$(echo \"$raw_manifest\" | jq -r '.config.mediaType // empty' 2>/dev/null || echo \"\")\n\n # Determine if this is an OCI artifact (not a container image)\n # OCI artifacts typically have:\n # - An empty/scratch config (config.mediaType contains \"empty\" or \"scratch\")\n # - An explicit artifactType field that is not a container image type\n is_oci_artifact=false\n\n # Check if config is empty/scratch (typical for OCI artifacts like python wheels, helm charts, etc.)\n if echo \"$config_media_type\" | grep -qiE \"(empty|scratch)\"; then\n is_oci_artifact=true\n fi\n\n # Check if artifactType is set and is not a container image type\n if [ -n \"$artifact_type\" ] && ! echo \"$artifact_type\" | grep -qE \"application/vnd\\.(oci|docker)\\.(image|container)\"; then\n is_oci_artifact=true\n fi\n\n if [ \"$is_oci_artifact\" = true ]; then\n # This is an OCI artifact (e.g., python wheels, helm charts, etc.)\n echo \"Detected OCI artifact (artifactType: ${artifact_type:-unset}, config.mediaType: ${config_media_type:-unset}). Downloading for scanning...\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"${media_type:-unknown}\\\"\"' | .artifact.artifactType = '\"\\\"${artifact_type:-unknown}\\\"\"' | .artifact.type = \"oci\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n destination=\"content-oci\"\n mkdir -p \"$destination\"\n\n # Download OCI artifact using skopeo copy\n echo \"Downloading OCI artifact using skopeo copy\"\n if ! retry skopeo copy --authfile ~/.docker/config.json \"docker://${imageanddigest}\" \"dir:${destination}\" 2>&1; then\n echo \"Failed to download OCI artifact \\\"$imageanddigest\\\". Skipping ClamAV scan!\"\n note=\"Task clamav-scan failed: Failed to download OCI artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n\n # Scan and process OCI artifact\n scan_and_process \"${destination}\" \"oci\" \"$IMAGE_DIGEST\" \"Scanning OCI artifact\"\n\n # Skip the container image processing path\n image_manifests=\"\"\n elif echo \"$media_type\" | grep -qE \"(application/vnd\\.(docker|oci)\\.(distribution|image)\\.manifest|application/vnd\\.docker\\.distribution\\.manifest)\"; then\n # This looks like a container image manifest, but get_image_manifests failed\n echo \"Detected container image manifest type: $media_type, but get_image_manifests failed. This may indicate an error.\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"$media_type\\\"\"' | .artifact.type = \"image\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n note=\"Task clamav-scan failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n else\n # Likely an OCI artifact with non-standard media type\n echo \"Detected OCI artifact (media type: ${media_type:-unknown}). Downloading for scanning...\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"${media_type:-unknown}\\\"\"' | .artifact.type = \"oci\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n destination=\"content-oci\"\n mkdir -p \"$destination\"\n\n # Download OCI artifact using skopeo copy\n echo \"Downloading OCI artifact using skopeo copy\"\n if ! retry skopeo copy --authfile ~/.docker/config.json \"docker://${imageanddigest}\" \"dir:${destination}\" 2>&1; then\n echo \"Failed to download OCI artifact \\\"$imageanddigest\\\". Skipping ClamAV scan!\"\n note=\"Task clamav-scan failed: Failed to download OCI artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n\n # Scan and process OCI artifact\n scan_and_process \"${destination}\" \"oci\" \"$IMAGE_DIGEST\" \"Scanning OCI artifact\"\n\n # Skip the container image processing path\n image_manifests=\"\"\n fi\n else\n echo \"Failed to inspect artifact \\\"$imageanddigest\\\". Unable to determine type.\"\n note=\"Task clamav-scan failed: Failed to inspect artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\nfi\n\n# Process container images (existing logic)\nif [ -n \"$image_manifests\" ]; then\n echo \"Detected container image. Processing image manifests.\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.type = \"image\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n # Proceed only if a specific arch is provided.\n # This typically occurs when using Tekton Matrix to launch multiple TaskRuns to scan all architectures of a multi-arch image in parallel.\n if [ -n \"$IMAGE_ARCH\" ]; then\n arch=\"${IMAGE_ARCH#*/}\"\n if [ \"${arch}\" = \"x86_64\" ]; then\n arch=\"amd64\"\n fi\n\n # Check if arch is supported; if not (e.g., it's 'local', see link below), default to amd64.\n # https://github.com/redhat-appstudio/infra-deployments/blob/main/components/multi-platform-controller/production/stone-prd-rh01/host-config.yaml#L9-L14\n case \"$arch\" in\n amd64|ppc64le|arm64|s390x)\n ;;\n *)\n arch=\"amd64\"\n ;;\n esac\n\n image_manifests=$(echo \"$image_manifests\" | jq -c --arg arch \"$arch\" '{($arch): .[$arch]}')\n fi\n\n while read -r arch arch_sha; do\n destination=\"content-${arch}\"\n mkdir -p \"$destination\"\n arch_imageanddigest=\"${imagewithouttag}@${arch_sha}\"\n\n echo \"Inspecting layers for arch $arch\"\n skip_log=\"\"\n layers=$(skopeo inspect --raw --authfile ~/.docker/config.json \\\n \"docker://${arch_imageanddigest}\" | jq -c '\n .layers[]? | {\n digest: (.digest // \"\"),\n size: ((.size // 0) | if type == \"number\" then . else 0 end),\n title: (.annotations[\"org.opencontainers.image.title\"] // \"\"),\n inpath: (.annotations[\"olot.layer.content.inlayerpath\"] // \"\")\n }') || layers=\"\"\n\n if [ -z \"${layers}\" ]; then\n echo \"Could not list layers; extracting full image\"\n if ! retry oc image extract --confirm --only-files=true \\\n --registry-config ~/.docker/config.json \"$arch_imageanddigest\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"; then\n echo \"Unable to extract image for arch $arch. Skipping ClamAV scan!\"\n exit 0\n fi\n else\n skip_log=\"/work/logs/skipped-layers-${arch}.log\"\n : > \"$skip_log\"\n while IFS= read -r layer_json; do\n [ -z \"$layer_json\" ] && continue\n digest=$(jq -r '.digest' <<< \"$layer_json\")\n size=$(jq -r '.size' <<< \"$layer_json\")\n title=$(jq -r '.title' <<< \"$layer_json\")\n inpath=$(jq -r '.inpath' <<< \"$layer_json\")\n [ -z \"$digest\" ] && continue\n\n if layer_annotation_is_weight \"$title\" \"$inpath\"; then\n echo \"Skipping unscannable weight layer ${digest} (manifest ${title:-$inpath})\" | tee -a \"$skip_log\"\n continue\n fi\n\n if { [ -n \"$title\" ] || [ -n \"$inpath\" ]; } && [ \"${size}\" -ge \"${CLAMAV_SKIP_BLOB_BYTES}\" ]; then\n echo \"Skipping unscannable layer ${digest} (manifest ${title:-$inpath}, size ${size})\" | tee -a \"$skip_log\"\n continue\n fi\n\n if [ -z \"$title\" ] && [ -z \"$inpath\" ]; then\n echo \"Listing layer ${digest}\"\n if listing=$(retry oc image extract --dry-run --confirm \\\n --registry-config ~/.docker/config.json \\\n \"${arch_imageanddigest}[~${digest}]\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"); then\n if is_weight_only_layer \"${listing}\"; then\n echo \"Skipping unscannable weight layer ${digest}\" | tee -a \"$skip_log\"\n continue\n fi\n else\n echo \"Failed to list layer ${digest}; extracting it\"\n fi\n fi\n\n if ! retry oc image extract --confirm --only-files=true \\\n --registry-config ~/.docker/config.json \\\n \"${arch_imageanddigest}[~${digest}]\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"; then\n echo \"Unable to extract layer ${digest} for arch $arch. Skipping ClamAV scan!\"\n exit 0\n fi\n done <<< \"$layers\"\n fi\n\n # Scan and process container image for this architecture\n scan_and_process \"${destination}\" \"$arch\" \"$arch_sha\" \"Scanning image for arch $arch\"\n\n if [ -s \"${skip_log}\" ]; then\n cat \"$skip_log\" >> \"/work/logs/clamscan-result-${arch}.log\"\n fi\n done < <(echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"')\nfi\n\njq -s -rce '\n reduce .[] as $item ({\"timestamp\":\"0\",\"namespace\":\"\",\"successes\":0,\"failures\":0,\"warnings\":0,\"result\":\"\",\"note\":\"\"};\n {\n \"timestamp\" : (if .timestamp < $item.timestamp then $item.timestamp else .timestamp end),\n \"namespace\" : $item.namespace,\n \"successes\" : (.successes + $item.successes),\n \"failures\" : (.failures + $item.failures),\n \"warnings\" : (.warnings + $item.warnings),\n \"result\" : (if .result == \"\" or ($item.result == \"SKIPPED\" and .result == \"SUCCESS\") or ($item.result == \"WARNING\" and (.result == \"SUCCESS\" or .result == \"SKIPPED\")) or ($item.result == \"FAILURE\" and .result != \"ERROR\") or $item.result == \"ERROR\" then $item.result else .result end),\n \"note\" : (if .result == \"\" or ($item.result == \"SKIPPED\" and .result == \"SUCCESS\") or ($item.result == \"WARNING\" and (.result == \"SUCCESS\" or .result == \"SKIPPED\")) or ($item.result == \"FAILURE\" and .result != \"ERROR\") or $item.result == \"ERROR\" then $item.note else .note end)\n })' /work/logs/clamscan-ec-test-*.json | tee \"/tekton/results/TEST_OUTPUT\"\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\n\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\necho \"${images_processed_template/\\[%s]/[$digests_processed_string]}\" | tee \"/tekton/results/IMAGES_PROCESSED\"\n","environment":{"container":"extract-and-scan-image","image":"oci://quay.io/konflux-ci/clamav-db@sha256:60297bb97fd977731706a64e252d969b81234422b0da065d9b9a57e9b103e74c"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -e\n\n# Skip upload if requested e.g. read-only CI tests where push access is denied\nif [ \"$SKIP_UPLOAD\" == \"true\" ]; then\n echo \"Upload skipped by parameter.\"\n exit 0\nfi\n\n# Don't return a glob expression when no matches are found\nshopt -s nullglob\n\ncd logs\n\nfor UPLOAD_FILE in clamscan-result*.log; do\n MEDIA_TYPE=text/vnd.clamav\n args+=(\"${UPLOAD_FILE}:${MEDIA_TYPE}\")\ndone\nfor UPLOAD_FILE in clamscan-ec-test*.json; do\n MEDIA_TYPE=application/vnd.konflux.test_output+json\n args+=(\"${UPLOAD_FILE}:${MEDIA_TYPE}\")\ndone\n\nif [ ${#args[@]} -eq 0 ]; then\n echo \"No files found. Skipping upload.\"\n exit 0;\nfi\n\necho \"Selecting auth\"\nselect-oci-auth \"$IMAGE_URL\" > \"$HOME/auth.json\"\necho \"Attaching to ${IMAGE_URL}\"\n retry oras attach --no-tty --registry-config \"$HOME/auth.json\" --artifact-type application/vnd.clamav \"${IMAGE_URL}@${IMAGE_DIGEST}\" \"${args[@]}\"\n","environment":{"container":"upload","image":"oci://quay.io/konflux-ci/task-runner@sha256:1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab"}}]},{"after":["build-image-index"],"finishedOn":"2026-09-08T21:28:00Z","invocation":{"configSource":{"digest":{"sha256":"9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b"},"entryPoint":"clamav-scan","uri":"quay.io/konflux-ci/tekton-catalog/task-clamav-scan"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/dc2be385-3a0d-474c-8b56-32f808581eb4","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"virus, konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-93c77cf31f239c13-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"clamav-scan","tekton.dev/task":"clamav-scan"}},"parameters":{"ca-trust-config-map-key":"ca-bundle.crt","ca-trust-config-map-name":"trusted-ca","clamd-max-threads":"8","docker-auth":"","image-arch":"linux/s390x","image-digest":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","image-url":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","skip-upload":"false"}},"name":"clamav-scan","ref":{"params":[{"name":"name","value":"clamav-scan"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.3.3@sha256:9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"IMAGES_PROCESSED","type":"string","value":"{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n"},{"name":"TEST_OUTPUT","type":"string","value":"{\"timestamp\":\"1788902876\",\"namespace\":\"required_checks\",\"successes\":2,\"failures\":0,\"warnings\":0,\"result\":\"SUCCESS\",\"note\":\"All checks passed successfully\"}\n"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:28Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\n# Start clamd in background\n/start-clamd.sh\n\n# Bootstrap .docker config in overridden HOME.\n# This prevents 'oc' CLI failures in clean environments where ~/.docker does not exist.\nif [ ! -d ~/.docker ]; then\n mkdir -p ~/.docker\n echo '{}' > ~/.docker/config.json\nfi\n\nimagewithouttag=$(echo \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\" | tr -d '\\n')\n\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\n\n# check if image is attestation one, skip the clamav scan in such case\nif [[ $imageanddigest == *.att ]]\nthen\n echo \"$imageanddigest is an attestation image. Skipping ClamAV scan.\"\n exit 0\nfi\n\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\nmkdir logs\nmkdir content\ncd content\necho \"Detecting artifact type for ${imageanddigest}.\"\necho '{\"artifact\":{\"pullspec\":\"'\"${imageanddigest}\"'\",\"type\":\"unknown\",\"mediaType\":\"\"}}' > /work/logs/artifact-meta.json\n\n# Function to scan content and process results with ClamAV and EC\n# Parameters:\n# $1: destination - path to the content to scan\n# $2: suffix - suffix for log file names (e.g., \"oci\", \"amd64\")\n# $3: digest - digest to add to digests_processed array\n# $4: scan_message - optional message describing what is being scanned\nscan_and_process() {\n local destination=\"$1\"\n local suffix=\"$2\"\n local digest=\"$3\"\n local scan_message=\"${4:-Scanning content}\"\n\n db_version=$(clamdscan --version | sed 's|.*/\\(.*\\)/.*|\\1|')\n\n echo \"$scan_message. This operation may take a while.\"\n clamdscan \"${destination}\" -vi --multiscan --fdpass \\\n | tee \"/work/logs/clamscan-result-${suffix}.log\" || true\n\n echo \"Executed-on: Scan was executed on clamsdcan version - $(clamdscan --version) Database version: $db_version\" | tee -a \"/work/logs/clamscan-result-${suffix}.log\"\n\n digests_processed+=(\"\\\"$digest\\\"\")\n\n if [[ -e \"/work/logs/clamscan-result-${suffix}.log\" ]]; then\n # OPA/EC requires structured data input, add clamAV log into json\n jq -Rs '{ output: . }' \"/work/logs/clamscan-result-${suffix}.log\" > \"/work/logs/clamscan-result-log-${suffix}.json\"\n\n EC_EXPERIMENTAL=1 ec test \\\n --namespace required_checks \\\n --policy /project/clamav/virus-check.rego \\\n -o json \\\n \"/work/logs/clamscan-result-log-${suffix}.json\" || true\n\n # workaround: due to a bug in ec-cli, we cannot generate json and appstudio output at the same time, running it again\n EC_EXPERIMENTAL=1 ec test \\\n --namespace required_checks \\\n --policy /project/clamav/virus-check.rego \\\n -o appstudio \\\n \"/work/logs/clamscan-result-log-${suffix}.json\" | tee \"/work/logs/clamscan-ec-test-${suffix}.json\" || true\n\n cat \"/work/logs/clamscan-ec-test-${suffix}.json\"\n fi\n}\n\n# Skip extract only when every real file is a known weight type.\nis_weight_filename() {\n local base=\"$1\"\n case \"$base\" in\n *.safetensors|*.gguf|*.ggml|*.pt|*.pth|*.onnx|*.onnx_data|*.onnx_data_*) return 0 ;;\n *) return 1 ;;\n esac\n}\n\n# 2000MiB: slightly under ClamAV's ~2GiB MaxFileSize (0.2 used --max-filesize=2000M).\nCLAMAV_SKIP_BLOB_BYTES=2097152000\n\n# listing = stdout of: oc image extract --dry-run\nis_weight_only_layer() {\n local listing=\"$1\"\n local mode entry base\n # Fail closed: empty stdout is not evidence the layer is weight-only.\n [[ -z \"${listing}\" ]] && return 1\n while IFS= read -r line; do\n [ -z \"$line\" ] && continue\n mode=$(awk '{print $2}' <<< \"$line\")\n [[ \"$mode\" == d* ]] && continue\n [[ \"$line\" == *\" -> \"* ]] && return 1\n entry=$(awk '{print $NF}' <<< \"$line\")\n base=$(basename \"$entry\")\n [[ \"$base\" == .wh.* ]] && continue\n is_weight_filename \"$base\" || return 1\n done <<< \"$listing\"\n return 0\n}\n\n# title/path from the OCI layer descriptor (olot ModelCars). Empty is not a skip.\nlayer_annotation_is_weight() {\n local title=\"$1\" inpath=\"$2\" base candidate\n for candidate in \"$title\" \"$inpath\"; do\n [ -z \"$candidate\" ] && continue\n base=$(basename \"$candidate\")\n is_weight_filename \"$base\" && return 0\n done\n return 1\n}\n\n# Detect artifact type: container image vs OCI artifact\n# First, try to get image manifests (works for container images)\n# Use subshell to prevent get_image_manifests() from exiting the main script if it fails\n# (get_image_manifests uses exit 1 when Architecture field is missing, which happens for OCI artifacts)\nimage_manifests=$(bash -c '. /utils.sh; get_image_manifests -i \"'\"${imageanddigest}\"'\"' 2>/dev/null || echo \"\")\n\n# If get_image_manifests failed, check if it's an OCI artifact by inspecting manifest media type\nif [ -z \"$image_manifests\" ]; then\n echo \"get_image_manifests returned empty, checking if this is an OCI artifact...\"\n raw_manifest=$(skopeo inspect --raw --authfile ~/.docker/config.json \"docker://${imageanddigest}\" 2>/dev/null || true)\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.type = \"inspected\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n\n if [ -n \"$raw_manifest\" ]; then\n media_type=$(echo \"$raw_manifest\" | jq -r '.mediaType // .config.mediaType // empty' 2>/dev/null || echo \"\")\n artifact_type=$(echo \"$raw_manifest\" | jq -r '.artifactType // empty' 2>/dev/null || echo \"\")\n config_media_type=$(echo \"$raw_manifest\" | jq -r '.config.mediaType // empty' 2>/dev/null || echo \"\")\n\n # Determine if this is an OCI artifact (not a container image)\n # OCI artifacts typically have:\n # - An empty/scratch config (config.mediaType contains \"empty\" or \"scratch\")\n # - An explicit artifactType field that is not a container image type\n is_oci_artifact=false\n\n # Check if config is empty/scratch (typical for OCI artifacts like python wheels, helm charts, etc.)\n if echo \"$config_media_type\" | grep -qiE \"(empty|scratch)\"; then\n is_oci_artifact=true\n fi\n\n # Check if artifactType is set and is not a container image type\n if [ -n \"$artifact_type\" ] && ! echo \"$artifact_type\" | grep -qE \"application/vnd\\.(oci|docker)\\.(image|container)\"; then\n is_oci_artifact=true\n fi\n\n if [ \"$is_oci_artifact\" = true ]; then\n # This is an OCI artifact (e.g., python wheels, helm charts, etc.)\n echo \"Detected OCI artifact (artifactType: ${artifact_type:-unset}, config.mediaType: ${config_media_type:-unset}). Downloading for scanning...\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"${media_type:-unknown}\\\"\"' | .artifact.artifactType = '\"\\\"${artifact_type:-unknown}\\\"\"' | .artifact.type = \"oci\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n destination=\"content-oci\"\n mkdir -p \"$destination\"\n\n # Download OCI artifact using skopeo copy\n echo \"Downloading OCI artifact using skopeo copy\"\n if ! retry skopeo copy --authfile ~/.docker/config.json \"docker://${imageanddigest}\" \"dir:${destination}\" 2>&1; then\n echo \"Failed to download OCI artifact \\\"$imageanddigest\\\". Skipping ClamAV scan!\"\n note=\"Task clamav-scan failed: Failed to download OCI artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n\n # Scan and process OCI artifact\n scan_and_process \"${destination}\" \"oci\" \"$IMAGE_DIGEST\" \"Scanning OCI artifact\"\n\n # Skip the container image processing path\n image_manifests=\"\"\n elif echo \"$media_type\" | grep -qE \"(application/vnd\\.(docker|oci)\\.(distribution|image)\\.manifest|application/vnd\\.docker\\.distribution\\.manifest)\"; then\n # This looks like a container image manifest, but get_image_manifests failed\n echo \"Detected container image manifest type: $media_type, but get_image_manifests failed. This may indicate an error.\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"$media_type\\\"\"' | .artifact.type = \"image\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n note=\"Task clamav-scan failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n else\n # Likely an OCI artifact with non-standard media type\n echo \"Detected OCI artifact (media type: ${media_type:-unknown}). Downloading for scanning...\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"${media_type:-unknown}\\\"\"' | .artifact.type = \"oci\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n destination=\"content-oci\"\n mkdir -p \"$destination\"\n\n # Download OCI artifact using skopeo copy\n echo \"Downloading OCI artifact using skopeo copy\"\n if ! retry skopeo copy --authfile ~/.docker/config.json \"docker://${imageanddigest}\" \"dir:${destination}\" 2>&1; then\n echo \"Failed to download OCI artifact \\\"$imageanddigest\\\". Skipping ClamAV scan!\"\n note=\"Task clamav-scan failed: Failed to download OCI artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n\n # Scan and process OCI artifact\n scan_and_process \"${destination}\" \"oci\" \"$IMAGE_DIGEST\" \"Scanning OCI artifact\"\n\n # Skip the container image processing path\n image_manifests=\"\"\n fi\n else\n echo \"Failed to inspect artifact \\\"$imageanddigest\\\". Unable to determine type.\"\n note=\"Task clamav-scan failed: Failed to inspect artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\nfi\n\n# Process container images (existing logic)\nif [ -n \"$image_manifests\" ]; then\n echo \"Detected container image. Processing image manifests.\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.type = \"image\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n # Proceed only if a specific arch is provided.\n # This typically occurs when using Tekton Matrix to launch multiple TaskRuns to scan all architectures of a multi-arch image in parallel.\n if [ -n \"$IMAGE_ARCH\" ]; then\n arch=\"${IMAGE_ARCH#*/}\"\n if [ \"${arch}\" = \"x86_64\" ]; then\n arch=\"amd64\"\n fi\n\n # Check if arch is supported; if not (e.g., it's 'local', see link below), default to amd64.\n # https://github.com/redhat-appstudio/infra-deployments/blob/main/components/multi-platform-controller/production/stone-prd-rh01/host-config.yaml#L9-L14\n case \"$arch\" in\n amd64|ppc64le|arm64|s390x)\n ;;\n *)\n arch=\"amd64\"\n ;;\n esac\n\n image_manifests=$(echo \"$image_manifests\" | jq -c --arg arch \"$arch\" '{($arch): .[$arch]}')\n fi\n\n while read -r arch arch_sha; do\n destination=\"content-${arch}\"\n mkdir -p \"$destination\"\n arch_imageanddigest=\"${imagewithouttag}@${arch_sha}\"\n\n echo \"Inspecting layers for arch $arch\"\n skip_log=\"\"\n layers=$(skopeo inspect --raw --authfile ~/.docker/config.json \\\n \"docker://${arch_imageanddigest}\" | jq -c '\n .layers[]? | {\n digest: (.digest // \"\"),\n size: ((.size // 0) | if type == \"number\" then . else 0 end),\n title: (.annotations[\"org.opencontainers.image.title\"] // \"\"),\n inpath: (.annotations[\"olot.layer.content.inlayerpath\"] // \"\")\n }') || layers=\"\"\n\n if [ -z \"${layers}\" ]; then\n echo \"Could not list layers; extracting full image\"\n if ! retry oc image extract --confirm --only-files=true \\\n --registry-config ~/.docker/config.json \"$arch_imageanddigest\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"; then\n echo \"Unable to extract image for arch $arch. Skipping ClamAV scan!\"\n exit 0\n fi\n else\n skip_log=\"/work/logs/skipped-layers-${arch}.log\"\n : > \"$skip_log\"\n while IFS= read -r layer_json; do\n [ -z \"$layer_json\" ] && continue\n digest=$(jq -r '.digest' <<< \"$layer_json\")\n size=$(jq -r '.size' <<< \"$layer_json\")\n title=$(jq -r '.title' <<< \"$layer_json\")\n inpath=$(jq -r '.inpath' <<< \"$layer_json\")\n [ -z \"$digest\" ] && continue\n\n if layer_annotation_is_weight \"$title\" \"$inpath\"; then\n echo \"Skipping unscannable weight layer ${digest} (manifest ${title:-$inpath})\" | tee -a \"$skip_log\"\n continue\n fi\n\n if { [ -n \"$title\" ] || [ -n \"$inpath\" ]; } && [ \"${size}\" -ge \"${CLAMAV_SKIP_BLOB_BYTES}\" ]; then\n echo \"Skipping unscannable layer ${digest} (manifest ${title:-$inpath}, size ${size})\" | tee -a \"$skip_log\"\n continue\n fi\n\n if [ -z \"$title\" ] && [ -z \"$inpath\" ]; then\n echo \"Listing layer ${digest}\"\n if listing=$(retry oc image extract --dry-run --confirm \\\n --registry-config ~/.docker/config.json \\\n \"${arch_imageanddigest}[~${digest}]\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"); then\n if is_weight_only_layer \"${listing}\"; then\n echo \"Skipping unscannable weight layer ${digest}\" | tee -a \"$skip_log\"\n continue\n fi\n else\n echo \"Failed to list layer ${digest}; extracting it\"\n fi\n fi\n\n if ! retry oc image extract --confirm --only-files=true \\\n --registry-config ~/.docker/config.json \\\n \"${arch_imageanddigest}[~${digest}]\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"; then\n echo \"Unable to extract layer ${digest} for arch $arch. Skipping ClamAV scan!\"\n exit 0\n fi\n done <<< \"$layers\"\n fi\n\n # Scan and process container image for this architecture\n scan_and_process \"${destination}\" \"$arch\" \"$arch_sha\" \"Scanning image for arch $arch\"\n\n if [ -s \"${skip_log}\" ]; then\n cat \"$skip_log\" >> \"/work/logs/clamscan-result-${arch}.log\"\n fi\n done < <(echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"')\nfi\n\njq -s -rce '\n reduce .[] as $item ({\"timestamp\":\"0\",\"namespace\":\"\",\"successes\":0,\"failures\":0,\"warnings\":0,\"result\":\"\",\"note\":\"\"};\n {\n \"timestamp\" : (if .timestamp < $item.timestamp then $item.timestamp else .timestamp end),\n \"namespace\" : $item.namespace,\n \"successes\" : (.successes + $item.successes),\n \"failures\" : (.failures + $item.failures),\n \"warnings\" : (.warnings + $item.warnings),\n \"result\" : (if .result == \"\" or ($item.result == \"SKIPPED\" and .result == \"SUCCESS\") or ($item.result == \"WARNING\" and (.result == \"SUCCESS\" or .result == \"SKIPPED\")) or ($item.result == \"FAILURE\" and .result != \"ERROR\") or $item.result == \"ERROR\" then $item.result else .result end),\n \"note\" : (if .result == \"\" or ($item.result == \"SKIPPED\" and .result == \"SUCCESS\") or ($item.result == \"WARNING\" and (.result == \"SUCCESS\" or .result == \"SKIPPED\")) or ($item.result == \"FAILURE\" and .result != \"ERROR\") or $item.result == \"ERROR\" then $item.note else .note end)\n })' /work/logs/clamscan-ec-test-*.json | tee \"/tekton/results/TEST_OUTPUT\"\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\n\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\necho \"${images_processed_template/\\[%s]/[$digests_processed_string]}\" | tee \"/tekton/results/IMAGES_PROCESSED\"\n","environment":{"container":"extract-and-scan-image","image":"oci://quay.io/konflux-ci/clamav-db@sha256:60297bb97fd977731706a64e252d969b81234422b0da065d9b9a57e9b103e74c"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -e\n\n# Skip upload if requested e.g. read-only CI tests where push access is denied\nif [ \"$SKIP_UPLOAD\" == \"true\" ]; then\n echo \"Upload skipped by parameter.\"\n exit 0\nfi\n\n# Don't return a glob expression when no matches are found\nshopt -s nullglob\n\ncd logs\n\nfor UPLOAD_FILE in clamscan-result*.log; do\n MEDIA_TYPE=text/vnd.clamav\n args+=(\"${UPLOAD_FILE}:${MEDIA_TYPE}\")\ndone\nfor UPLOAD_FILE in clamscan-ec-test*.json; do\n MEDIA_TYPE=application/vnd.konflux.test_output+json\n args+=(\"${UPLOAD_FILE}:${MEDIA_TYPE}\")\ndone\n\nif [ ${#args[@]} -eq 0 ]; then\n echo \"No files found. Skipping upload.\"\n exit 0;\nfi\n\necho \"Selecting auth\"\nselect-oci-auth \"$IMAGE_URL\" > \"$HOME/auth.json\"\necho \"Attaching to ${IMAGE_URL}\"\n retry oras attach --no-tty --registry-config \"$HOME/auth.json\" --artifact-type application/vnd.clamav \"${IMAGE_URL}@${IMAGE_DIGEST}\" \"${args[@]}\"\n","environment":{"container":"upload","image":"oci://quay.io/konflux-ci/task-runner@sha256:1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab"}}]},{"after":["build-image-index"],"finishedOn":"2026-09-08T21:27:59Z","invocation":{"configSource":{"digest":{"sha256":"9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b"},"entryPoint":"clamav-scan","uri":"quay.io/konflux-ci/tekton-catalog/task-clamav-scan"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/a9e01aea-22db-4eab-945d-bfc0ff017616","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"virus, konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-1ce322344973ba0c-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"clamav-scan","tekton.dev/task":"clamav-scan"}},"parameters":{"ca-trust-config-map-key":"ca-bundle.crt","ca-trust-config-map-name":"trusted-ca","clamd-max-threads":"8","docker-auth":"","image-arch":"linux-m2xlarge/arm64","image-digest":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","image-url":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","skip-upload":"false"}},"name":"clamav-scan","ref":{"params":[{"name":"name","value":"clamav-scan"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.3.3@sha256:9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"IMAGES_PROCESSED","type":"string","value":"{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n"},{"name":"TEST_OUTPUT","type":"string","value":"{\"timestamp\":\"1788902875\",\"namespace\":\"required_checks\",\"successes\":2,\"failures\":0,\"warnings\":0,\"result\":\"SUCCESS\",\"note\":\"All checks passed successfully\"}\n"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:28Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\n# Start clamd in background\n/start-clamd.sh\n\n# Bootstrap .docker config in overridden HOME.\n# This prevents 'oc' CLI failures in clean environments where ~/.docker does not exist.\nif [ ! -d ~/.docker ]; then\n mkdir -p ~/.docker\n echo '{}' > ~/.docker/config.json\nfi\n\nimagewithouttag=$(echo \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\" | tr -d '\\n')\n\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\n\n# check if image is attestation one, skip the clamav scan in such case\nif [[ $imageanddigest == *.att ]]\nthen\n echo \"$imageanddigest is an attestation image. Skipping ClamAV scan.\"\n exit 0\nfi\n\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\nmkdir logs\nmkdir content\ncd content\necho \"Detecting artifact type for ${imageanddigest}.\"\necho '{\"artifact\":{\"pullspec\":\"'\"${imageanddigest}\"'\",\"type\":\"unknown\",\"mediaType\":\"\"}}' > /work/logs/artifact-meta.json\n\n# Function to scan content and process results with ClamAV and EC\n# Parameters:\n# $1: destination - path to the content to scan\n# $2: suffix - suffix for log file names (e.g., \"oci\", \"amd64\")\n# $3: digest - digest to add to digests_processed array\n# $4: scan_message - optional message describing what is being scanned\nscan_and_process() {\n local destination=\"$1\"\n local suffix=\"$2\"\n local digest=\"$3\"\n local scan_message=\"${4:-Scanning content}\"\n\n db_version=$(clamdscan --version | sed 's|.*/\\(.*\\)/.*|\\1|')\n\n echo \"$scan_message. This operation may take a while.\"\n clamdscan \"${destination}\" -vi --multiscan --fdpass \\\n | tee \"/work/logs/clamscan-result-${suffix}.log\" || true\n\n echo \"Executed-on: Scan was executed on clamsdcan version - $(clamdscan --version) Database version: $db_version\" | tee -a \"/work/logs/clamscan-result-${suffix}.log\"\n\n digests_processed+=(\"\\\"$digest\\\"\")\n\n if [[ -e \"/work/logs/clamscan-result-${suffix}.log\" ]]; then\n # OPA/EC requires structured data input, add clamAV log into json\n jq -Rs '{ output: . }' \"/work/logs/clamscan-result-${suffix}.log\" > \"/work/logs/clamscan-result-log-${suffix}.json\"\n\n EC_EXPERIMENTAL=1 ec test \\\n --namespace required_checks \\\n --policy /project/clamav/virus-check.rego \\\n -o json \\\n \"/work/logs/clamscan-result-log-${suffix}.json\" || true\n\n # workaround: due to a bug in ec-cli, we cannot generate json and appstudio output at the same time, running it again\n EC_EXPERIMENTAL=1 ec test \\\n --namespace required_checks \\\n --policy /project/clamav/virus-check.rego \\\n -o appstudio \\\n \"/work/logs/clamscan-result-log-${suffix}.json\" | tee \"/work/logs/clamscan-ec-test-${suffix}.json\" || true\n\n cat \"/work/logs/clamscan-ec-test-${suffix}.json\"\n fi\n}\n\n# Skip extract only when every real file is a known weight type.\nis_weight_filename() {\n local base=\"$1\"\n case \"$base\" in\n *.safetensors|*.gguf|*.ggml|*.pt|*.pth|*.onnx|*.onnx_data|*.onnx_data_*) return 0 ;;\n *) return 1 ;;\n esac\n}\n\n# 2000MiB: slightly under ClamAV's ~2GiB MaxFileSize (0.2 used --max-filesize=2000M).\nCLAMAV_SKIP_BLOB_BYTES=2097152000\n\n# listing = stdout of: oc image extract --dry-run\nis_weight_only_layer() {\n local listing=\"$1\"\n local mode entry base\n # Fail closed: empty stdout is not evidence the layer is weight-only.\n [[ -z \"${listing}\" ]] && return 1\n while IFS= read -r line; do\n [ -z \"$line\" ] && continue\n mode=$(awk '{print $2}' <<< \"$line\")\n [[ \"$mode\" == d* ]] && continue\n [[ \"$line\" == *\" -> \"* ]] && return 1\n entry=$(awk '{print $NF}' <<< \"$line\")\n base=$(basename \"$entry\")\n [[ \"$base\" == .wh.* ]] && continue\n is_weight_filename \"$base\" || return 1\n done <<< \"$listing\"\n return 0\n}\n\n# title/path from the OCI layer descriptor (olot ModelCars). Empty is not a skip.\nlayer_annotation_is_weight() {\n local title=\"$1\" inpath=\"$2\" base candidate\n for candidate in \"$title\" \"$inpath\"; do\n [ -z \"$candidate\" ] && continue\n base=$(basename \"$candidate\")\n is_weight_filename \"$base\" && return 0\n done\n return 1\n}\n\n# Detect artifact type: container image vs OCI artifact\n# First, try to get image manifests (works for container images)\n# Use subshell to prevent get_image_manifests() from exiting the main script if it fails\n# (get_image_manifests uses exit 1 when Architecture field is missing, which happens for OCI artifacts)\nimage_manifests=$(bash -c '. /utils.sh; get_image_manifests -i \"'\"${imageanddigest}\"'\"' 2>/dev/null || echo \"\")\n\n# If get_image_manifests failed, check if it's an OCI artifact by inspecting manifest media type\nif [ -z \"$image_manifests\" ]; then\n echo \"get_image_manifests returned empty, checking if this is an OCI artifact...\"\n raw_manifest=$(skopeo inspect --raw --authfile ~/.docker/config.json \"docker://${imageanddigest}\" 2>/dev/null || true)\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.type = \"inspected\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n\n if [ -n \"$raw_manifest\" ]; then\n media_type=$(echo \"$raw_manifest\" | jq -r '.mediaType // .config.mediaType // empty' 2>/dev/null || echo \"\")\n artifact_type=$(echo \"$raw_manifest\" | jq -r '.artifactType // empty' 2>/dev/null || echo \"\")\n config_media_type=$(echo \"$raw_manifest\" | jq -r '.config.mediaType // empty' 2>/dev/null || echo \"\")\n\n # Determine if this is an OCI artifact (not a container image)\n # OCI artifacts typically have:\n # - An empty/scratch config (config.mediaType contains \"empty\" or \"scratch\")\n # - An explicit artifactType field that is not a container image type\n is_oci_artifact=false\n\n # Check if config is empty/scratch (typical for OCI artifacts like python wheels, helm charts, etc.)\n if echo \"$config_media_type\" | grep -qiE \"(empty|scratch)\"; then\n is_oci_artifact=true\n fi\n\n # Check if artifactType is set and is not a container image type\n if [ -n \"$artifact_type\" ] && ! echo \"$artifact_type\" | grep -qE \"application/vnd\\.(oci|docker)\\.(image|container)\"; then\n is_oci_artifact=true\n fi\n\n if [ \"$is_oci_artifact\" = true ]; then\n # This is an OCI artifact (e.g., python wheels, helm charts, etc.)\n echo \"Detected OCI artifact (artifactType: ${artifact_type:-unset}, config.mediaType: ${config_media_type:-unset}). Downloading for scanning...\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"${media_type:-unknown}\\\"\"' | .artifact.artifactType = '\"\\\"${artifact_type:-unknown}\\\"\"' | .artifact.type = \"oci\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n destination=\"content-oci\"\n mkdir -p \"$destination\"\n\n # Download OCI artifact using skopeo copy\n echo \"Downloading OCI artifact using skopeo copy\"\n if ! retry skopeo copy --authfile ~/.docker/config.json \"docker://${imageanddigest}\" \"dir:${destination}\" 2>&1; then\n echo \"Failed to download OCI artifact \\\"$imageanddigest\\\". Skipping ClamAV scan!\"\n note=\"Task clamav-scan failed: Failed to download OCI artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n\n # Scan and process OCI artifact\n scan_and_process \"${destination}\" \"oci\" \"$IMAGE_DIGEST\" \"Scanning OCI artifact\"\n\n # Skip the container image processing path\n image_manifests=\"\"\n elif echo \"$media_type\" | grep -qE \"(application/vnd\\.(docker|oci)\\.(distribution|image)\\.manifest|application/vnd\\.docker\\.distribution\\.manifest)\"; then\n # This looks like a container image manifest, but get_image_manifests failed\n echo \"Detected container image manifest type: $media_type, but get_image_manifests failed. This may indicate an error.\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"$media_type\\\"\"' | .artifact.type = \"image\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n note=\"Task clamav-scan failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n else\n # Likely an OCI artifact with non-standard media type\n echo \"Detected OCI artifact (media type: ${media_type:-unknown}). Downloading for scanning...\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"${media_type:-unknown}\\\"\"' | .artifact.type = \"oci\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n destination=\"content-oci\"\n mkdir -p \"$destination\"\n\n # Download OCI artifact using skopeo copy\n echo \"Downloading OCI artifact using skopeo copy\"\n if ! retry skopeo copy --authfile ~/.docker/config.json \"docker://${imageanddigest}\" \"dir:${destination}\" 2>&1; then\n echo \"Failed to download OCI artifact \\\"$imageanddigest\\\". Skipping ClamAV scan!\"\n note=\"Task clamav-scan failed: Failed to download OCI artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n\n # Scan and process OCI artifact\n scan_and_process \"${destination}\" \"oci\" \"$IMAGE_DIGEST\" \"Scanning OCI artifact\"\n\n # Skip the container image processing path\n image_manifests=\"\"\n fi\n else\n echo \"Failed to inspect artifact \\\"$imageanddigest\\\". Unable to determine type.\"\n note=\"Task clamav-scan failed: Failed to inspect artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\nfi\n\n# Process container images (existing logic)\nif [ -n \"$image_manifests\" ]; then\n echo \"Detected container image. Processing image manifests.\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.type = \"image\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n # Proceed only if a specific arch is provided.\n # This typically occurs when using Tekton Matrix to launch multiple TaskRuns to scan all architectures of a multi-arch image in parallel.\n if [ -n \"$IMAGE_ARCH\" ]; then\n arch=\"${IMAGE_ARCH#*/}\"\n if [ \"${arch}\" = \"x86_64\" ]; then\n arch=\"amd64\"\n fi\n\n # Check if arch is supported; if not (e.g., it's 'local', see link below), default to amd64.\n # https://github.com/redhat-appstudio/infra-deployments/blob/main/components/multi-platform-controller/production/stone-prd-rh01/host-config.yaml#L9-L14\n case \"$arch\" in\n amd64|ppc64le|arm64|s390x)\n ;;\n *)\n arch=\"amd64\"\n ;;\n esac\n\n image_manifests=$(echo \"$image_manifests\" | jq -c --arg arch \"$arch\" '{($arch): .[$arch]}')\n fi\n\n while read -r arch arch_sha; do\n destination=\"content-${arch}\"\n mkdir -p \"$destination\"\n arch_imageanddigest=\"${imagewithouttag}@${arch_sha}\"\n\n echo \"Inspecting layers for arch $arch\"\n skip_log=\"\"\n layers=$(skopeo inspect --raw --authfile ~/.docker/config.json \\\n \"docker://${arch_imageanddigest}\" | jq -c '\n .layers[]? | {\n digest: (.digest // \"\"),\n size: ((.size // 0) | if type == \"number\" then . else 0 end),\n title: (.annotations[\"org.opencontainers.image.title\"] // \"\"),\n inpath: (.annotations[\"olot.layer.content.inlayerpath\"] // \"\")\n }') || layers=\"\"\n\n if [ -z \"${layers}\" ]; then\n echo \"Could not list layers; extracting full image\"\n if ! retry oc image extract --confirm --only-files=true \\\n --registry-config ~/.docker/config.json \"$arch_imageanddigest\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"; then\n echo \"Unable to extract image for arch $arch. Skipping ClamAV scan!\"\n exit 0\n fi\n else\n skip_log=\"/work/logs/skipped-layers-${arch}.log\"\n : > \"$skip_log\"\n while IFS= read -r layer_json; do\n [ -z \"$layer_json\" ] && continue\n digest=$(jq -r '.digest' <<< \"$layer_json\")\n size=$(jq -r '.size' <<< \"$layer_json\")\n title=$(jq -r '.title' <<< \"$layer_json\")\n inpath=$(jq -r '.inpath' <<< \"$layer_json\")\n [ -z \"$digest\" ] && continue\n\n if layer_annotation_is_weight \"$title\" \"$inpath\"; then\n echo \"Skipping unscannable weight layer ${digest} (manifest ${title:-$inpath})\" | tee -a \"$skip_log\"\n continue\n fi\n\n if { [ -n \"$title\" ] || [ -n \"$inpath\" ]; } && [ \"${size}\" -ge \"${CLAMAV_SKIP_BLOB_BYTES}\" ]; then\n echo \"Skipping unscannable layer ${digest} (manifest ${title:-$inpath}, size ${size})\" | tee -a \"$skip_log\"\n continue\n fi\n\n if [ -z \"$title\" ] && [ -z \"$inpath\" ]; then\n echo \"Listing layer ${digest}\"\n if listing=$(retry oc image extract --dry-run --confirm \\\n --registry-config ~/.docker/config.json \\\n \"${arch_imageanddigest}[~${digest}]\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"); then\n if is_weight_only_layer \"${listing}\"; then\n echo \"Skipping unscannable weight layer ${digest}\" | tee -a \"$skip_log\"\n continue\n fi\n else\n echo \"Failed to list layer ${digest}; extracting it\"\n fi\n fi\n\n if ! retry oc image extract --confirm --only-files=true \\\n --registry-config ~/.docker/config.json \\\n \"${arch_imageanddigest}[~${digest}]\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"; then\n echo \"Unable to extract layer ${digest} for arch $arch. Skipping ClamAV scan!\"\n exit 0\n fi\n done <<< \"$layers\"\n fi\n\n # Scan and process container image for this architecture\n scan_and_process \"${destination}\" \"$arch\" \"$arch_sha\" \"Scanning image for arch $arch\"\n\n if [ -s \"${skip_log}\" ]; then\n cat \"$skip_log\" >> \"/work/logs/clamscan-result-${arch}.log\"\n fi\n done < <(echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"')\nfi\n\njq -s -rce '\n reduce .[] as $item ({\"timestamp\":\"0\",\"namespace\":\"\",\"successes\":0,\"failures\":0,\"warnings\":0,\"result\":\"\",\"note\":\"\"};\n {\n \"timestamp\" : (if .timestamp < $item.timestamp then $item.timestamp else .timestamp end),\n \"namespace\" : $item.namespace,\n \"successes\" : (.successes + $item.successes),\n \"failures\" : (.failures + $item.failures),\n \"warnings\" : (.warnings + $item.warnings),\n \"result\" : (if .result == \"\" or ($item.result == \"SKIPPED\" and .result == \"SUCCESS\") or ($item.result == \"WARNING\" and (.result == \"SUCCESS\" or .result == \"SKIPPED\")) or ($item.result == \"FAILURE\" and .result != \"ERROR\") or $item.result == \"ERROR\" then $item.result else .result end),\n \"note\" : (if .result == \"\" or ($item.result == \"SKIPPED\" and .result == \"SUCCESS\") or ($item.result == \"WARNING\" and (.result == \"SUCCESS\" or .result == \"SKIPPED\")) or ($item.result == \"FAILURE\" and .result != \"ERROR\") or $item.result == \"ERROR\" then $item.note else .note end)\n })' /work/logs/clamscan-ec-test-*.json | tee \"/tekton/results/TEST_OUTPUT\"\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\n\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\necho \"${images_processed_template/\\[%s]/[$digests_processed_string]}\" | tee \"/tekton/results/IMAGES_PROCESSED\"\n","environment":{"container":"extract-and-scan-image","image":"oci://quay.io/konflux-ci/clamav-db@sha256:60297bb97fd977731706a64e252d969b81234422b0da065d9b9a57e9b103e74c"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -e\n\n# Skip upload if requested e.g. read-only CI tests where push access is denied\nif [ \"$SKIP_UPLOAD\" == \"true\" ]; then\n echo \"Upload skipped by parameter.\"\n exit 0\nfi\n\n# Don't return a glob expression when no matches are found\nshopt -s nullglob\n\ncd logs\n\nfor UPLOAD_FILE in clamscan-result*.log; do\n MEDIA_TYPE=text/vnd.clamav\n args+=(\"${UPLOAD_FILE}:${MEDIA_TYPE}\")\ndone\nfor UPLOAD_FILE in clamscan-ec-test*.json; do\n MEDIA_TYPE=application/vnd.konflux.test_output+json\n args+=(\"${UPLOAD_FILE}:${MEDIA_TYPE}\")\ndone\n\nif [ ${#args[@]} -eq 0 ]; then\n echo \"No files found. Skipping upload.\"\n exit 0;\nfi\n\necho \"Selecting auth\"\nselect-oci-auth \"$IMAGE_URL\" > \"$HOME/auth.json\"\necho \"Attaching to ${IMAGE_URL}\"\n retry oras attach --no-tty --registry-config \"$HOME/auth.json\" --artifact-type application/vnd.clamav \"${IMAGE_URL}@${IMAGE_DIGEST}\" \"${args[@]}\"\n","environment":{"container":"upload","image":"oci://quay.io/konflux-ci/task-runner@sha256:1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab"}}]},{"after":["build-image-index"],"finishedOn":"2026-09-08T21:27:33Z","invocation":{"configSource":{"digest":{"sha256":"8b501440a960aec446db2ebc6625a49d0317a9fc7bf0f7bd9b18cb63052db7de"},"entryPoint":"coverity-availability-check","uri":"quay.io/konflux-ci/tekton-catalog/task-coverity-availability-check"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/83002330-c983-4a8f-96cf-c95f2c69f2f7","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-d63c04970b0dcebb-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"coverity-availability-check","tekton.dev/task":"coverity-availability-check"}},"parameters":{"AUTH_TOKEN_COVERITY_IMAGE":"auth-token-coverity-image","COV_LICENSE":"cov-license"}},"name":"coverity-availability-check","ref":{"params":[{"name":"name","value":"coverity-availability-check"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-coverity-availability-check:0.2@sha256:8b501440a960aec446db2ebc6625a49d0317a9fc7bf0f7bd9b18cb63052db7de"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"STATUS","type":"string","value":"failed"},{"name":"TEST_OUTPUT","type":"string","value":"{\"result\":\"FAILURE\",\"timestamp\":\"2026-09-08T21:27:33+00:00\",\"note\":\"Task coverity-availability-check failed: Coverity license expired on 2026-Apr-13 08:00:00 UTC\",\"namespace\":\"default\",\"successes\":0,\"failures\":1,\"warnings\":0}\n"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:28Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -eo pipefail\n# shellcheck source=/dev/null\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\n# Checking Coverity license\nCOV_LICENSE_PATH=/etc/secrets/cov/cov-license\nif [ -f \"${COV_LICENSE_PATH}\" ] && [ -s \"${COV_LICENSE_PATH}\" ]; then\n echo \"Coverity license detected!\"\n\n # Check license expiry\n EXPIRY_DATE=$(sed -n 's/.*<valid-until>\\(.*\\)<\\/valid-until>.*/\\1/p' \"${COV_LICENSE_PATH}\" || true)\n if [ -n \"$EXPIRY_DATE\" ]; then\n # Reformat \"2020-Jan-01 08:00:00 UTC\" -> \"01 Jan 2020 08:00:00 UTC\"\n DATE_PART=\"${EXPIRY_DATE%% *}\"\n TIME_PART=\"${EXPIRY_DATE#* }\"\n IFS=- read -r YEAR MON DAY <<< \"$DATE_PART\"\n EXPIRY_EPOCH=$(date -d \"$DAY $MON $YEAR $TIME_PART\" +%s 2>/dev/null || true)\n if [ -n \"$EXPIRY_EPOCH\" ]; then\n NOW_EPOCH=$(date +%s)\n if [ \"$NOW_EPOCH\" -gt \"$EXPIRY_EPOCH\" ]; then\n echo \"Coverity license expired on ${EXPIRY_DATE}\"\n note=\"Task coverity-availability-check failed: Coverity license expired on ${EXPIRY_DATE}\"\n TEST_OUTPUT=$(make_result_json -r FAILURE -t \"$note\" -f 1)\n echo -n \"failed\" | tee \"/tekton/results/STATUS\"\n echo \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n DAYS_LEFT=$(( (EXPIRY_EPOCH - NOW_EPOCH) / 86400 ))\n if [ \"$DAYS_LEFT\" -lt 14 ]; then\n echo \"WARNING: Coverity license expires in ${DAYS_LEFT} days (${EXPIRY_DATE})\"\n else\n echo \"Coverity license valid until: ${EXPIRY_DATE}\"\n fi\n fi\n fi\nelse\n echo 'No license file for Coverity was detected. Coverity scan will not be executed...'\n echo 'Please, create a secret called 'cov-license' with a key called 'cov-license' and the value containing the Coverity license'\n note=\"Task coverity-availability-check failed: No license file for Coverity was detected. Please, create a secret called 'cov-license' with a key called 'cov-license' and the value containing the Coverity license\"\n TEST_OUTPUT=$(make_result_json -r FAILURE -t \"$note\" -f 1)\n echo -n \"failed\" | tee \"/tekton/results/STATUS\"\n echo \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n\n# Checking authentication token for downloading coverity image\nAUTH_TOKEN_COVERITY_IMAGE_PATH=/etc/secrets/auth/config.json\nif [ -f \"${AUTH_TOKEN_COVERITY_IMAGE_PATH}\" ] && [ -s \"${AUTH_TOKEN_COVERITY_IMAGE_PATH}\" ]; then\n echo \"Authentication token detected!\"\nelse\n echo 'No authentication token for downloading Coverity image detected. Coverity scan will not be executed...'\n echo 'Please, create an imagePullSecret named 'auth-token-coverity-image' with the authentication token for pulling the Coverity image'\n note=\"Task coverity-availability-check failed: No authentication token for downloading Coverity image detected. Please, create an imagePullSecret named 'auth-token-coverity-image' with the authentication token for pulling the Coverity image\"\n TEST_OUTPUT=$(make_result_json -r FAILURE -t \"$note\" -f 1)\n echo -n \"failed\" | tee \"/tekton/results/STATUS\"\n echo \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n\nnote=\"Task coverity-availability-check completed: Coverity availability checks finished succesfully.\"\n# shellcheck disable=SC2034\nTEST_OUTPUT=$(make_result_json -r SUCCESS -s 1 -t \"$note\")\necho -n \"success\" | tee \"/tekton/results/STATUS\"\necho \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n","environment":{"container":"coverity-availability-check","image":"oci://quay.io/konflux-ci/konflux-test@sha256:3bba1fe5ad96bd3811f34b367487192683aa9b1ba343da4885dda565b0a7207e"}}]},{"after":["build-image-index","prefetch-dependencies"],"finishedOn":"2026-09-08T21:27:41Z","invocation":{"configSource":{"digest":{"sha256":"d9b01530ce3c20287714e64980f154e28c0e94d17e2dbfbaf3c8bf77b1844b9e"},"entryPoint":"sast-shell-check-oci-ta","uri":"quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/9e86038e-55f3-4dcf-ba51-f9b430fea229","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-c9e2ddf090055c74-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"sast-shell-check","tekton.dev/task":"sast-shell-check-oci-ta"}},"parameters":{"CACHI2_ARTIFACT":"","IMP_FINDINGS_ONLY":"true","KFP_GIT_URL":"SITE_DEFAULT","PROJECT_NAME":"","RECORD_EXCLUDED":"false","SKIP_JINJA":"true","SOURCE_ARTIFACT":"oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735","TARGET_DIRS":".","caTrustConfigMapKey":"ca-bundle.crt","caTrustConfigMapName":"trusted-ca","image-digest":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","image-url":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25"}},"name":"sast-shell-check","ref":{"params":[{"name":"name","value":"sast-shell-check-oci-ta"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:d9b01530ce3c20287714e64980f154e28c0e94d17e2dbfbaf3c8bf77b1844b9e"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"TEST_OUTPUT","type":"string","value":"{\"result\":\"FAILURE\",\"timestamp\":\"2026-09-08T21:27:39+00:00\",\"note\":\"For details, check Tekton task log.\",\"namespace\":\"default\",\"successes\":0,\"failures\":2,\"warnings\":0}\n"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:28Z","status":"Succeeded","steps":[{"annotations":null,"arguments":["use","oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source"],"entryPoint":"","environment":{"container":"use-trusted-artifact","image":"oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:15c5eeb451924ddfc9d8680319130fe277df7850728d5c37f13ae3eb9d607249"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -x\n# shellcheck source=/dev/null\nsource /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\nif [[ -z \"${PROJECT_NAME}\" ]]; then\n PROJECT_NAME=${COMPONENT_LABEL}\nfi\n\necho \"INFO: The PROJECT_NAME used is: ${PROJECT_NAME}\"\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nPACKAGE_VERSION=$(rpm -q --queryformat '%{NAME}-%{VERSION}-%{RELEASE}\\n' ShellCheck)\n\nOUTPUT_FILE=\"shellcheck-results.json\"\nSOURCE_CODE_DIR=/var/workdir/source\n\n# generate full path for each dirname separated by comma\ndeclare -a ALL_TARGETS\nIFS=\",\" read -ra TARGET_ARRAY <<<\"$TARGET_DIRS\"\nfor d in \"${TARGET_ARRAY[@]}\"; do\n potential_path=\"${SOURCE_CODE_DIR}/${d}\"\n\n resolved_path=$(realpath -m \"$potential_path\")\n\n # ensure resolved path is still within SOURCE_CODE_DIR\n if [[ \"$resolved_path\" == \"$SOURCE_CODE_DIR\"* ]]; then\n ALL_TARGETS+=(\"$resolved_path\")\n else\n echo \"Error: path traversal attempt, '$potential_path' is outside '$SOURCE_CODE_DIR'\"\n exit 1\n fi\ndone\n\n# determine number of available CPU cores for shellcheck based on container cgroup v2 CPU limits\n# this calculates the ceiling, so if the cpu limit is 0.5, the number of jobs will be 1.\nif [ -z \"$SC_JOBS\" ] && [ -r \"/sys/fs/cgroup/cpu.max\" ]; then\n read -r quota period </sys/fs/cgroup/cpu.max\n if [ \"$quota\" != \"max\" ] && [ -n \"$period\" ] && [ \"$period\" -gt 0 ]; then\n export SC_JOBS=$(((quota + period - 1) / period))\n echo \"INFO: Setting SC_JOBS=${SC_JOBS} based on cgroups v2 max for run-shellcheck.sh\"\n fi\nfi\n\nif [[ \"${SKIP_JINJA}\" == \"true\" ]]; then\n export SC_SKIP_JINJA=1\nfi\n\n# generate all shellcheck result JSON files to $SC_RESULTS_DIR, which defaults to ./shellcheck-results/\n/usr/share/csmock/scripts/run-shellcheck.sh \"${ALL_TARGETS[@]}\"\n\nCSGREP_OPTS=(\n --mode=json\n --strip-path-prefix=\"$SOURCE_CODE_DIR\"/\n --remove-duplicates\n --embed-context=3\n --set-scan-prop=\"ShellCheck:${PACKAGE_VERSION}\"\n)\nif [[ \"$IMP_FINDINGS_ONLY\" == \"true\" ]]; then\n # predefined list of shellcheck important findings\n CSGREP_EVENT_FILTER='\\[SC(1020|1035|1054|1066|1068|1073|1080|1083|1099|1113|1115|1127|1128|1143|2043|2050|'\n CSGREP_EVENT_FILTER+='2055|2057|2066|2069|2071|2077|2078|2091|2092|2157|2171|2193|2194|2195|2215|2216|'\n CSGREP_EVENT_FILTER+='2218|2224|2225|2242|2256|2258|2261)\\]$'\n CSGREP_OPTS+=(\n --event=\"$CSGREP_EVENT_FILTER\"\n )\nelse\n CSGREP_OPTS+=(\n --event=\"error|warning\"\n )\nfi\n\nif ! csgrep \"${CSGREP_OPTS[@]}\" ./shellcheck-results/*.json >\"$OUTPUT_FILE\"; then\n echo \"Error occurred while running 'run-shellcheck.sh'\"\n note=\"Task sast-shell-check-oci-ta failed: For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 1\nfi\n\nif [[ \"${KFP_GIT_URL}\" == \"SITE_DEFAULT\" ]]; then\n KFP_GIT_URL=\"https://gitlab.cee.redhat.com/osh/known-false-positives.git\"\nfi\nPROBE_URL=\"${KFP_GIT_URL%.git}\" # trims '.git' suffix\n\n# create the KFP clone directory regardless\nKFP_DIR=\"known-false-positives\"\nKFP_CLONED=\"0\"\nmkdir \"${KFP_DIR}\"\n\n# We check if the KFP_GIT_URL variable is set to clone and apply the filters or not\nif [[ -n \"${KFP_GIT_URL}\" ]]; then\n # Default location only reachable from internal Konflux instances, check reachable first\n echo -n \"INFO: Probing ${PROBE_URL}... \"\n if curl --fail --head --max-time 60 --no-progress-meter \"${PROBE_URL}\" > >(head -1); then\n echo \"INFO: Trying to clone known-false-positives..\"\n git clone \"${KFP_GIT_URL}\" \"${KFP_DIR}\" && KFP_CLONED=\"1\"\n fi\nfi\n\nif [[ \"${KFP_CLONED}\" -eq \"0\" ]]; then\n echo \"WARN: Failed to clone known-false-positives at ${KFP_GIT_URL}, scan results will not be filtered\"\nelse\n echo \"INFO: Filtering false positives in results files using csfilter-kfp...\"\n\n # build initial csfilter-kfp command\n csfilter_kfp_cmd=(\n csfilter-kfp\n --verbose\n --kfp-dir=\"${KFP_DIR}\"\n --project-nvr=\"${PROJECT_NAME}\"\n )\n\n if [[ \"${RECORD_EXCLUDED}\" == \"true\" ]]; then\n csfilter_kfp_cmd+=(--record-excluded=\"excluded-findings.json\")\n fi\n\n # Execute the command and capture any errors\n set +e\n \"${csfilter_kfp_cmd[@]}\" \"${OUTPUT_FILE}\" >\"${OUTPUT_FILE}.filtered\" 2>\"${OUTPUT_FILE}.error\"\n status=$?\n set -e\n if [ \"$status\" -ne 0 ]; then\n echo \"WARN: failed to filter known false positives\" >&2\n else\n mv \"${OUTPUT_FILE}.filtered\" \"$OUTPUT_FILE\"\n echo \"INFO: Succeeded filtering known false positives\" >&2\n fi\nfi\n\necho \"ShellCheck results have been saved to $OUTPUT_FILE\"\n\ncsgrep --mode=evtstat \"$OUTPUT_FILE\"\ncsgrep \"$OUTPUT_FILE\"\ncsgrep --mode=sarif \"$OUTPUT_FILE\" >shellcheck-results.sarif\n\nTEST_OUTPUT=\nparse_test_output \"sast-shell-check-oci-ta\" sarif shellcheck-results.sarif || true\necho \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n","environment":{"container":"sast-shell-check","image":"oci://quay.io/konflux-ci/konflux-test@sha256:04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -e\n\nif [ -z \"${IMAGE_URL}\" ] || [ -z \"${IMAGE_DIGEST}\" ]; then\n echo 'No image-url or image-digest param provided. Skipping upload.'\n exit 0\nfi\n\nUPLOAD_FILES=\"shellcheck-results.sarif excluded-findings.json\"\n\nfor UPLOAD_FILE in ${UPLOAD_FILES}; do\n if [ ! -f \"${UPLOAD_FILE}\" ]; then\n echo \"No ${UPLOAD_FILE} exists. Skipping upload.\"\n continue\n fi\n\n # Determine the media type based on the file extension\n if [[ \"${UPLOAD_FILE}\" == *.json ]]; then\n MEDIA_TYPE=\"application/json\"\n else\n MEDIA_TYPE=\"application/sarif+json\"\n fi\n\n echo \"Selecting auth\"\n select-oci-auth \"$IMAGE_URL\" >\"$HOME/auth.json\"\n echo \"Attaching to ${IMAGE_URL}\"\n if ! retry oras attach --no-tty --registry-config \"$HOME/auth.json\" --artifact-type \"${MEDIA_TYPE}\" \"${IMAGE_URL}@${IMAGE_DIGEST}\" \"${UPLOAD_FILE}:${MEDIA_TYPE}\"; then\n echo \"Failed to attach ${UPLOAD_FILE} to ${IMAGE_URL}\"\n exit 1\n fi\ndone\n","environment":{"container":"upload","image":"oci://quay.io/konflux-ci/oras@sha256:1cc659b4d30536ec98300ac551739ef36dee345a7dcfe06129fd78abdc3688ac"}}]},{"after":["build-image-index","prefetch-dependencies"],"finishedOn":"2026-09-08T21:27:52Z","invocation":{"configSource":{"digest":{"sha256":"381750451fbcc86d90fa83579a48e0e6555d7cf374fe2c4af3f9262a17fc3c89"},"entryPoint":"sast-unicode-check-oci-ta","uri":"quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/6892d670-2189-4461-945f-3b495f84a1de","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-ed77e098fa96e2c2-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"sast-unicode-check","tekton.dev/task":"sast-unicode-check-oci-ta"}},"parameters":{"CACHI2_ARTIFACT":"","FIND_UNICODE_CONTROL_ARGS":"-p bidi -v -d -t","KFP_GIT_URL":"SITE_DEFAULT","PROJECT_NAME":"","RECORD_EXCLUDED":"false","SOURCE_ARTIFACT":"oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735","TARGET_DIRS":".","caTrustConfigMapKey":"ca-bundle.crt","caTrustConfigMapName":"trusted-ca","image-digest":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","image-url":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25"}},"name":"sast-unicode-check","ref":{"params":[{"name":"name","value":"sast-unicode-check-oci-ta"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.4@sha256:381750451fbcc86d90fa83579a48e0e6555d7cf374fe2c4af3f9262a17fc3c89"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"TEST_OUTPUT","type":"string","value":"{\"result\":\"SUCCESS\",\"timestamp\":\"2026-09-08T21:27:50+00:00\",\"note\":\"Task sast-unicode-check-oci-ta success: No finding was detected\",\"namespace\":\"default\",\"successes\":0,\"failures\":0,\"warnings\":0}\n"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:28Z","status":"Succeeded","steps":[{"annotations":null,"arguments":["use","oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source"],"entryPoint":"","environment":{"container":"use-trusted-artifact","image":"oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:15c5eeb451924ddfc9d8680319130fe277df7850728d5c37f13ae3eb9d607249"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\nset -exuo pipefail\n\n# shellcheck source=/dev/null\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\nif [[ -z \"${PROJECT_NAME}\" ]]; then\n PROJECT_NAME=${COMPONENT_LABEL}\nfi\n\necho \"INFO: The PROJECT_NAME used is: ${PROJECT_NAME}\"\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nSCAN_PROP=\"https://github.com/siddhesh/find-unicode-control.git#c2accbfbba7553a8bc1ebd97089ae08ad8347e58\"\nFUC_EXIT_CODE=0\n\n# generate full path for each dirname separated by comma\ndeclare -a ALL_TARGETS\nOLD_IFS=\"$IFS\"\nIFS=\",\"\nfor d in $TARGET_DIRS; do\n ALL_TARGETS+=(\"${SOURCE_CODE_DIR}/source/${d}\")\ndone\nIFS=\"$OLD_IFS\"\n\n# shellcheck disable=SC2086\nLANG=en_US.utf8 find_unicode_control.py ${FIND_UNICODE_CONTROL_ARGS} \"${ALL_TARGETS[@]}\" \\\n >raw_sast_unicode_check_out.txt \\\n 2>raw_sast_unicode_check_out.log ||\n FUC_EXIT_CODE=$?\nif [[ \"${FUC_EXIT_CODE}\" -ne 0 ]] && [[ \"${FUC_EXIT_CODE}\" -ne 1 ]]; then\n echo \"Failed to run find-unicode-control command\" >&2\n cat raw_sast_unicode_check_out.log\n note=\"Task sast-unicode-check-oci-ta failed: For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 1\nfi\n\n# Translate the output format\nif ! sed -i raw_sast_unicode_check_out.txt -E -e 's|(.*:[0-9]+)(.*)|\\1: warning:\\2|' -e 's|^|Error: UNICONTROL_WARNING:\\n|'; then\n echo \"Error: failed to translate the unicontrol output format\" >&2\n note=\"Task sast-unicode-check-oci-ta failed: For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 1\nfi\n\n# Process all results as configured with CSGERP_OPTS\nCSGERP_OPTS=(\n --mode=json\n --remove-duplicates\n --embed-context=3\n --set-scan-prop=\"${SCAN_PROP}\"\n --strip-path-prefix=\"${SOURCE_CODE_DIR}\"/source/\n)\n# In order to generate csdiff/v1, we need to add the whole path of the source code as\n# sast-unicode-check only provides an URI to embed the context\nif ! csgrep \"${CSGERP_OPTS[@]}\" raw_sast_unicode_check_out.txt >processed_sast_unicode_check_out.json 2>processed_sast_unicode_check_out.err; then\n echo \"Error occurred while running csgrep with CSGERP_OPTS:\"\n cat processed_sast_unicode_check_out.err\n note=\"Task sast-unicode-check-oci-ta failed: For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 1\nfi\n\ncsgrep --mode=evtstat processed_sast_unicode_check_out.json\ncsgrep processed_sast_unicode_check_out.json\n\nif [[ \"${KFP_GIT_URL}\" == \"SITE_DEFAULT\" ]]; then\n KFP_GIT_URL=\"https://gitlab.cee.redhat.com/osh/known-false-positives.git\"\nfi\nPROBE_URL=\"${KFP_GIT_URL%.git}\" # trims '.git' suffix\n\n# create the KFP clone directory regardless\nKFP_DIR=\"known-false-positives\"\nKFP_CLONED=\"0\"\nmkdir \"${KFP_DIR}\"\n\n# We check if the KFP_GIT_URL variable is set to clone and apply the filters or not\nif [[ -n \"${KFP_GIT_URL}\" ]]; then\n # Default location only reachable from internal Konflux instances, check reachable first\n echo -n \"INFO: Probing ${PROBE_URL}... \"\n if curl --fail --head --max-time 60 --no-progress-meter \"${PROBE_URL}\" > >(head -1); then\n echo \"INFO: Trying to clone known-false-positives..\"\n git clone \"${KFP_GIT_URL}\" \"${KFP_DIR}\" && KFP_CLONED=\"1\"\n fi\nfi\n\n# If KFP clone failed, use the unfiltered results\nif [[ \"${KFP_CLONED}\" -eq \"0\" ]]; then\n echo \"WARN: Failed to clone known-false-positives at ${KFP_GIT_URL}, scan results will not be filtered\"\n mv processed_sast_unicode_check_out.json sast_unicode_check_out.json\nelse\n echo \"INFO: Filtering false positives in results files using csfilter-kfp...\"\n\n # Build initial csfilter-kfp command\n csfilter_kfp_cmd=(\n csfilter-kfp\n --verbose\n --kfp-dir=\"${KFP_DIR}\"\n --project-nvr=\"${PROJECT_NAME}\"\n )\n\n # Append --record-excluded option if RECORD_EXCLUDED is true\n if [[ \"${RECORD_EXCLUDED}\" == \"true\" ]]; then\n csfilter_kfp_cmd+=(--record-excluded=\"excluded-findings.json\")\n fi\n\n # Execute the command and capture any errors\n set +e\n \"${csfilter_kfp_cmd[@]}\" processed_sast_unicode_check_out.json >sast_unicode_check_out.json 2>sast_unicode_check_out.error\n status=$?\n set -e\n if [ \"$status\" -ne 0 ]; then\n echo \"WARN: failed to filter known false positives\" >&2\n mv processed_sast_unicode_check_out.json sast_unicode_check_out.json\n else\n echo \"INFO: Succeeded filtering known false positives\" >&2\n fi\nfi\n\n# Generate sarif report\ncsgrep --mode=sarif sast_unicode_check_out.json >sast_unicode_check_out.sarif\nif [[ \"${FUC_EXIT_CODE}\" -eq 0 ]]; then\n note=\"Task sast-unicode-check-oci-ta success: No finding was detected\"\n ERROR_OUTPUT=$(make_result_json -r SUCCESS -t \"$note\")\nelif [[ \"${FUC_EXIT_CODE}\" -eq 1 ]] && [[ ! -s sast_unicode_check_out.sarif ]]; then\n note=\"Task sast-unicode-check-oci-ta success: Some findings were detected, but filtered by known false positive\"\n ERROR_OUTPUT=$(make_result_json -r SUCCESS -t \"$note\")\nelse\n echo \"sast-unicode-check test failed because of the following issues:\"\n cat sast_unicode_check_out.json\n TEST_OUTPUT=\n parse_test_output \"sast-unicode-check-oci-ta\" sarif sast_unicode_check_out.sarif || true\n note=\"Task sast-unicode-check-oci-ta failed: For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\nfi\necho \"${TEST_OUTPUT:-${ERROR_OUTPUT}}\" | tee \"/tekton/results/TEST_OUTPUT\"\n","environment":{"container":"sast-unicode-check","image":"oci://quay.io/konflux-ci/konflux-test@sha256:04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14"}},{"annotations":null,"arguments":null,"entryPoint":"#!/usr/bin/env bash\n\nif [ -z \"${IMAGE_URL}\" ]; then\n echo 'No image-url param provided. Skipping upload.'\n exit 0\nfi\n\nUPLOAD_FILES=\"sast_unicode_check_out.sarif excluded-findings.json\"\nfor UPLOAD_FILE in ${UPLOAD_FILES}; do\n if [ ! -f \"${UPLOAD_FILE}\" ]; then\n echo \"No ${UPLOAD_FILE} exists. Skipping upload.\"\n continue\n fi\n\n if [ \"${UPLOAD_FILE}\" == \"excluded-findings.json\" ]; then\n MEDIA_TYPE=application/json\n else\n MEDIA_TYPE=application/sarif+json\n fi\n\n echo \"Selecting auth\"\n select-oci-auth \"${IMAGE_URL}\" >\"${HOME}/auth.json\"\n echo \"Attaching to ${IMAGE_URL}\"\n retry oras attach --no-tty --registry-config \"$HOME/auth.json\" --artifact-type \"${MEDIA_TYPE}\" \"${IMAGE_URL}@${IMAGE_DIGEST}\" \"${UPLOAD_FILE}:${MEDIA_TYPE}\"\ndone\n","environment":{"container":"upload","image":"oci://quay.io/konflux-ci/oras@sha256:1cc659b4d30536ec98300ac551739ef36dee345a7dcfe06129fd78abdc3688ac"}}]},{"after":["build-image-index"],"finishedOn":"2026-09-08T21:27:33Z","invocation":{"configSource":{"digest":{"sha256":"ccd3665345d86c6799bc7e2e6ad86b277d9f3a5c40b513e6f2a0af8ad92e7dba"},"entryPoint":"apply-tags","uri":"quay.io/konflux-ci/tekton-catalog/task-apply-tags"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/725fcc7c-b3f3-427e-8b1d-82ce14630493","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"konflux","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-f5158b6e5a84f4e7-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"apply-tags","tekton.dev/task":"apply-tags"}},"parameters":{"ADDITIONAL_TAGS":["rhoai-2.25-58e7f0f6d889933345394152903c95c62e6bd9c3"],"CA_TRUST_CONFIG_MAP_KEY":"ca-bundle.crt","CA_TRUST_CONFIG_MAP_NAME":"trusted-ca","IMAGE_DIGEST":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","IMAGE_URL":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","LOG_LEVEL":"info"}},"name":"apply-tags","ref":{"params":[{"name":"name","value":"apply-tags"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.3.1@sha256:ccd3665345d86c6799bc7e2e6ad86b277d9f3a5c40b513e6f2a0af8ad92e7dba"},{"name":"kind","value":"task"}],"resolver":"bundles"},"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:28Z","status":"Succeeded","steps":[{"annotations":null,"arguments":["--image-url","quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","--digest","sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","--tags","rhoai-2.25-58e7f0f6d889933345394152903c95c62e6bd9c3","--tags-from-image-label","konflux.additional-tags"],"entryPoint":"konflux-build-cli image apply-tags","environment":{"container":"apply-additional-tags","image":"oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f"}}]},{"after":["build-image-index","prefetch-dependencies"],"finishedOn":"2026-09-08T21:27:36Z","invocation":{"configSource":{"digest":{"sha256":"ef00a86cb22259fcfdefa15a5116b63d0f24ee35c95d05ff9815ee8f84beb548"},"entryPoint":"push-dockerfile-oci-ta","uri":"quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/2d97a744-fa45-41d3-b276-5196f162b51f","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/pipelines.minVersion":"0.12.1","tekton.dev/tags":"image-build, appstudio","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-cc9c6f3b286a8eef-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","build.appstudio.redhat.com/build_type":"docker","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"push-dockerfile","tekton.dev/task":"push-dockerfile-oci-ta"}},"parameters":{"ARTIFACT_TYPE":"application/vnd.konflux.dockerfile","CA_TRUST_CONFIG_MAP_KEY":"ca-bundle.crt","CA_TRUST_CONFIG_MAP_NAME":"trusted-ca","CONTEXT":".","DOCKERFILE":"Dockerfiles/agent.Dockerfile.konflux","IMAGE":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","IMAGE_DIGEST":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","LOG_LEVEL":"info","SOURCE_ARTIFACT":"oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735","TAG_SUFFIX":".dockerfile"}},"name":"push-dockerfile","ref":{"params":[{"name":"name","value":"push-dockerfile-oci-ta"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.3.1@sha256:ef00a86cb22259fcfdefa15a5116b63d0f24ee35c95d05ff9815ee8f84beb548"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"IMAGE_REF","type":"string","value":"quay.io/rhoai/odh-kserve-agent-rhel9@sha256:90de7875a003ab5f8ed0a1aeb49e8b9a34b4416d5a171c2932c34a75f0c44239"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:28Z","status":"Succeeded","steps":[{"annotations":null,"arguments":["use","oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source"],"entryPoint":"","environment":{"container":"use-trusted-artifact","image":"oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c"}},{"annotations":null,"arguments":["--source","source","--context",".","--containerfile","Dockerfiles/agent.Dockerfile.konflux","--image-url","quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","--image-digest","sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","--artifact-type","application/vnd.konflux.dockerfile","--tag-suffix",".dockerfile","--result-path-image-ref","/tekton/results/IMAGE_REF","--alternative-filename","Dockerfile"],"entryPoint":"konflux-build-cli image push-containerfile","environment":{"container":"push","image":"oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f"}}]},{"after":["build-image-index"],"finishedOn":"2026-09-08T21:28:33Z","invocation":{"configSource":{"digest":{"sha256":"9ef4dabd53e823e3139b99c8de708be4ee759d63b32982847929df19ab75b2f8"},"entryPoint":"rpms-signature-scan","uri":"quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/998e5fb3-98fd-468f-ba01-3db94e80630e","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-6ba848dd68d4388b-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"rpms-signature-scan","tekton.dev/task":"rpms-signature-scan"}},"parameters":{"ca-trust-config-map-key":"ca-bundle.crt","ca-trust-config-map-name":"trusted-ca","image-digest":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","image-url":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","workdir":"/tmp"}},"name":"rpms-signature-scan","ref":{"params":[{"name":"name","value":"rpms-signature-scan"},{"name":"bundle","value":"quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2.2@sha256:9ef4dabd53e823e3139b99c8de708be4ee759d63b32982847929df19ab75b2f8"},{"name":"kind","value":"task"}],"resolver":"bundles"},"results":[{"name":"IMAGES_PROCESSED","type":"string","value":"{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f\", \"sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b\", \"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\", \"sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35\", \"sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75\"]}}\n"},{"name":"RPMS_DATA","type":"string","value":"{\"keys\": {\"199e2f91fd431d51\": 424, \"unsigned\": 0}}\n"},{"name":"SCAN_LOG","type":"string","value":""},{"name":"TEST_OUTPUT","type":"string","value":"{\"result\":\"SUCCESS\",\"timestamp\":\"2026-09-08T21:28:31+00:00\",\"note\":\"Task rpms-signature-scan completed successfully\",\"namespace\":\"default\",\"successes\":0,\"failures\":0,\"warnings\":0}\n"}],"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:28Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"#!/bin/bash\nset -ex\nset -o pipefail\n\nrpm_verifier \\\n --image-url \"${IMAGE_URL}\" \\\n --image-digest \"${IMAGE_DIGEST}\" \\\n --workdir \"${WORKDIR}\" \\\n 2> >(tee \"${WORKDIR}/stderr\" >&2)\n","environment":{"container":"rpms-signature-scan","image":"oci://quay.io/konflux-ci/tools@sha256:69102586287b89a162f7eaf4cded2db44a0df41da17016aacc4fadffa5490b6b"}},{"annotations":null,"arguments":null,"entryPoint":"#!/bin/bash\nset -ex\n\nsource /utils.sh\nstatus=$(cat \"${WORKDIR}\"/status)\nrpms_data=$(cat \"${WORKDIR}\"/results)\nimages_processed=$(cat \"${WORKDIR}\"/images_processed)\n\nif [ \"$status\" == \"ERROR\" ]; then\n note=\"Task rpms-signature-scan failed to scan images. Refer to Tekton task output for details\"\nelse\n note=\"Task rpms-signature-scan completed successfully\"\nfi\n\nTEST_OUTPUT=$(make_result_json -r \"$status\" -t \"$note\")\n\necho \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\necho \"${rpms_data}\" | tee \"/tekton/results/RPMS_DATA\"\necho \"${images_processed}\" | tee \"/tekton/results/IMAGES_PROCESSED\"\n\nif [ -f \"${WORKDIR}/stderr\" ]; then\n head -c 4000 \"${WORKDIR}/stderr\" | tee \"/tekton/results/SCAN_LOG\"\nelse\n echo \"\" > \"/tekton/results/SCAN_LOG\"\nfi\n","environment":{"container":"output-results","image":"oci://quay.io/konflux-ci/konflux-test@sha256:04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14"}}]},{"after":["build-image-index"],"finishedOn":"2026-09-08T21:27:41Z","invocation":{"configSource":{},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/d16bf159-2c4c-46d6-a636-e756287105c5","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-703b8e79215d52d3-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"fips-check"}},"parameters":{"blocking":"true","image-digest":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","image-platform":"linux/x86_64","image-url":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25"}},"name":"fips-check","ref":{},"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:28Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"ARCH=\"${IMAGE_PLATFORM#*/}\"\nif [ \"${ARCH}\" = \"x86_64\" ]; then ARCH=\"amd64\"; fi\ncase \"${ARCH}\" in\n amd64|ppc64le|arm64|s390x) ;;\n *) ARCH=\"amd64\" ;;\nesac\nIMAGE_WITHOUT_TAG=$(echo \"${IMAGE_URL}\" | sed 's/\\(.*\\):.*/\\1/')\nPLATFORM_DIGEST=$(skopeo inspect --raw \"docker://${IMAGE_WITHOUT_TAG}@${IMAGE_DIGEST}\" | jq -r \".manifests[] | select(.platform.architecture == \\\"${ARCH}\\\") | .digest\")\nif [ -z \"${PLATFORM_DIGEST}\" ]; then\n echo \"Could not find digest for architecture ${ARCH} in ${IMAGE_URL}@${IMAGE_DIGEST}\"\n exit 1\nfi\nprintf '%s' \"${IMAGE_WITHOUT_TAG}@${PLATFORM_DIGEST}\" > /tekton/home/unique_related_images.txt\n","environment":{"container":"prepare-image-list","image":"oci://quay.io/konflux-ci/konflux-test@sha256:04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14"}},{"annotations":null,"arguments":["-s","--","bash","-c","set -euo pipefail\n# shellcheck source=/dev/null\n. /utils.sh\n\nexport RETRY_COUNT=2\nexport RETRY_INTERVAL=5\n\n# Create temporary directory for parallel processing counters\ncounter_dir=$(mktemp -d)\ntrap 'rm -rf \"$counter_dir\"' EXIT\n\n# Function to clean up OCI image and extracted directory\ncleanup_image_artifacts() {\n local image_num=\"$1\"\n local component_label=\"$2\"\n local version_label=\"$3\"\n local release_label=\"$4\"\n # Clean up OCI directory (may already be deleted by inline rm, or may not exist)\n rm -rf \"/tekton/home/${image_num}-${component_label}-${version_label}-${release_label}\" 2>/dev/null || true\n # Clean up extracted directory (may or may not exist depending on failure point)\n rm -rf \"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\" 2>/dev/null || true\n}\n\n# Function to process a single related image\nprocess_image() {\n # shellcheck source=/dev/null\n . /utils.sh\n\n local related_image=\"$1\"\n local image_num=\"$2\"\n local total_images=\"$3\"\n local check_payload_version=\"$4\"\n local image_mirror_map=\"$5\"\n\n related_image=\"${related_image//$'\\n'/}\"\n echo \"Processing related image ${image_num} of ${total_images}: ${related_image}\"\n\n image_accessible=0\n if ! image_labels=$(get_image_labels \"$related_image\"); then\n echo \"Could not inspect original pullspec $related_image. Checking if there's a mirror present\"\n if [ -n \"${image_mirror_map}\" ]; then\n reg_and_repo=$(get_image_registry_and_repository \"${related_image}\")\n mapfile -t mirrors < <(get_image_mirror_list \"${reg_and_repo}\" \"${image_mirror_map}\")\n if [[ -z \"${mirrors[0]}\" ]]; then\n echo \"No mirrors found in image mirror map for ${reg_and_repo}\"\n else\n echo \"Mirrors for $reg_and_repo are:\"\n printf \"%s\\n\" \"${mirrors[@]}\"\n\n for mirror in \"${mirrors[@]}\"; do\n echo \"Attempting to use mirror ${mirror}\"\n replaced_image=$(replace_image_pullspec \"$related_image\" \"$mirror\")\n if ! image_labels=$(get_image_labels \"$replaced_image\"); then\n echo \"Mirror $mirror is inaccessible.\"\n continue\n fi\n image_accessible=1\n echo \"Replacing $related_image with $replaced_image\"\n related_image=\"$replaced_image\"\n break\n done\n fi\n fi\n else\n image_accessible=1\n echo \"Successfully inspected $related_image. Mirror not required.\"\n fi\n\n if [[ $image_accessible -eq 0 ]]; then\n echo -e \"Error: Unable to scan image: Could not inspect image ${related_image} for labels\\n\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n component_label=$(echo \"${image_labels}\" | grep 'com.redhat.component=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n version_label=$(echo \"${image_labels}\" | grep '^version=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n release_label=$(echo \"${image_labels}\" | grep 'release=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n echo \"Component label is ${component_label}\"\n echo \"Version label is ${version_label}\"\n echo \"Release label is ${release_label}\"\n\n # Sanitize component_label to prevent directory path issues\n # Replace problematic characters (/ \\ : * ? \" < > | and whitespace) with hyphens\n sanitized_component_label=$(echo -n \"${component_label}\" | tr '/\\\\:*?\"<>|[:space:]' '-')\n echo \"Sanitized component label for path usage: ${component_label} -> ${sanitized_component_label}\"\n component_label=\"${sanitized_component_label}\"\n\n if [ -z \"${component_label}\" ]; then\n echo -e \"Error: Unable to scan image: Could not get com.redhat.component label for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n\n # Sanitize the image reference to handle Docker references with both tag and digest\n sanitized_related_image=$(get_image_registry_repository_digest \"${related_image}\")\n\n # If no digest is present, fallback to using tag-based sanitization\n if [[ \"${sanitized_related_image}\" != *\"@\"* ]]; then\n echo \"No digest found in sanitized image, using tag-based sanitization\"\n sanitized_related_image=$(get_image_registry_repository_tag \"${related_image}\")\n fi\n echo \"Successfully sanitized image reference: ${sanitized_related_image}. Using sanitized image reference for extraction\"\n\n # Fetch the first available architecture so that the skopeo copy does not fail if the default arch is not available\n first_arch=$(get_first_arch \"${sanitized_related_image}\")\n echo \"Detected architecture for ${sanitized_related_image}: ${first_arch}\"\n\n # Create destination directory for extraction\n extract_dir=\"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\"\n mkdir -p \"${extract_dir}\"\n\n # Extract image filesystem using oc image extract, with fallback to skopeo+umoci\n # oc image extract may fail with large images under high parallelism\n extraction_success=1\n if oc image extract \"${sanitized_related_image}\" \\\n --path=/:\"${extract_dir}\" \\\n --filter-by-os=\".*/${first_arch}\" \\\n --confirm \\\n --preserve-ownership; then\n extraction_success=0\n echo \"Successfully extracted ${related_image} using oc image extract\"\n else\n echo \"oc image extract failed for ${related_image}, falling back to skopeo+umoci\"\n # Clean up partial extraction before fallback\n rm -rf \"${extract_dir}\" 2>/dev/null || true\n mkdir -p \"${extract_dir}\"\n\n # Fallback: use skopeo copy + umoci unpack\n oci_dir=\"/tekton/home/${image_num}-${component_label}-${version_label}-${release_label}\"\n if retry skopeo copy --override-arch \"${first_arch}\" --remove-signatures \\\n \"docker://${sanitized_related_image}\" \\\n \"oci://${oci_dir}:latest\"; then\n if retry umoci raw unpack --rootless \\\n --image \"${oci_dir}:latest\" \\\n \"${extract_dir}\"; then\n extraction_success=0\n echo \"Successfully extracted ${related_image} using skopeo+umoci fallback\"\n else\n echo \"umoci unpack failed for ${related_image}\"\n fi\n # Clean up OCI image regardless of umoci success\n rm -rf \"${oci_dir}\" 2>/dev/null || true\n else\n echo \"skopeo copy failed for ${related_image}\"\n fi\n fi\n\n if [[ \"${extraction_success}\" -ne 0 ]]; then\n echo -e \"Error: Unable to scan image: Could not extract filesystem from ${related_image}\\n\"\n # Clean up any partial extracted directory to prevent resource accumulation\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n\n # Run check-payload on the extracted image\n # The check-payload command fails with exit 1 when the scan for an image is unsuccessful\n # or when the image is not FIPS compliant. Hence, count those as failures and not errors\n if ! check-payload scan local \\\n --path=\"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\" \\\n \"${check_payload_version}\" \\\n --components=\"${component_label}\" \\\n --output-format=csv \\\n --output-file=\"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan failed for ${related_image}\\n\"\n # Clean up extracted directory on scan failure to prevent resource accumulation\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n echo \"1\" >> \"${counter_dir}/failure\"\n return\n fi\n\n if [ -f \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\" ]; then\n if grep -q -- \"---- Successful run\" \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan was successful for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/success\"\n # Clean up extracted directory on successful run to save space\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n elif grep -q -- \"---- Successful run with warnings\" \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan was successful with warnings for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/warnings\"\n # Clean up extracted directory on successful run with warnings to save space\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n fi\n fi\n}\n\nif [ ! -e \"/tekton/home/unique_related_images.txt\" ]; then\n echo \"No relatedImages to process\"\n exit 0\nfi\n\nmapfile -d ' ' -t related_images < <(cat /tekton/home/unique_related_images.txt)\necho \"Related images are :\"\nprintf \"%s\\n\" \"${related_images[@]}\"\n\n# If target OCP version is found, use it to apply the exception list when running check-payload\ncheck_payload_version=\"\"\nif [ -f \"/tekton/home/target_ocp_version.txt\" ]; then\n version=$(cat \"/tekton/home/target_ocp_version.txt\")\n check_payload_version=\"-V=${version}\"\n echo \"Target OCP version found: ${check_payload_version}\"\nfi\n\n# Check if an image to mirror map is defined for unreleased images\nimage_mirror_map=\"\"\nif [ -f \"/tekton/home/related-images-map.txt\" ]; then\n image_mirror_map=$(cat \"/tekton/home/related-images-map.txt\")\n echo \"Image Mirror Map found:\"\n echo \"${image_mirror_map}\" | jq '.'\nfi\n\n# Process images in parallel with MAX_PARALLEL limit\necho \"Processing ${#related_images[@]} images with MAX_PARALLEL=${MAX_PARALLEL}\"\ndeclare -i count=0\nfor related_image in \"${related_images[@]}\"; do\n count+=1\n # Wait if we've reached the parallel limit\n while [ \"$(jobs -r | wc -l)\" -ge \"${MAX_PARALLEL}\" ]; do\n wait -n\n done\n # Launch background job to process image\n process_image \"$related_image\" \"$count\" \"${#related_images[@]}\" \"$check_payload_version\" \"$image_mirror_map\" &\ndone\n\n# Wait for all background jobs to complete\nwait\n\n# Aggregate results from counter files\nsuccess_counter=0\nwarnings_counter=0\nerror_counter=0\nfailure_counter=0\n\nif [ -f \"${counter_dir}/success\" ]; then\n success_counter=$(wc -l < \"${counter_dir}/success\")\nfi\nif [ -f \"${counter_dir}/warnings\" ]; then\n warnings_counter=$(wc -l < \"${counter_dir}/warnings\")\nfi\nif [ -f \"${counter_dir}/error\" ]; then\n error_counter=$(wc -l < \"${counter_dir}/error\")\nfi\nif [ -f \"${counter_dir}/failure\" ]; then\n failure_counter=$(wc -l < \"${counter_dir}/failure\")\nfi\n\necho \"Results: success=${success_counter}, warnings=${warnings_counter}, errors=${error_counter}, failures=${failure_counter}\"\n\nnote=\"Task odh-kserve-agent-v2-25-on-push-xwfsp-fips-check-0 failed: Some images could not be scanned. For details, check Tekton task log.\"\nERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\n\nnote=\"Task odh-kserve-agent-v2-25-on-push-xwfsp-fips-check-0 completed: Check result for task result.\"\nif [[ \"$error_counter\" == 0 ]];\nthen\n if [[ \"${failure_counter}\" -gt 0 ]]; then\n RES=\"FAILURE\"\n elif [[ \"${warnings_counter}\" -gt 0 ]]; then\n RES=\"WARNING\"\n else\n RES=\"SUCCESS\"\n fi\n TEST_OUTPUT=$(make_result_json \\\n -r \"${RES}\" \\\n -s \"${success_counter}\" -f \"${failure_counter}\" -w \"${warnings_counter}\" -t \"$note\")\nfi\necho \"${TEST_OUTPUT:-${ERROR_OUTPUT}}\" | tee \"/tekton/steps/step-run-fips-check/results/TEST_OUTPUT\"\n"],"entryPoint":"/usr/bin/tini","environment":{"container":"run-fips-check","image":"oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b"}},{"annotations":null,"arguments":null,"entryPoint":"echo \"${TEST_OUTPUT}\"\nif echo \"${TEST_OUTPUT}\" | grep -qE '\"result\":\"(FAILURE|ERROR)\"'; then\n if [ \"${BLOCKING}\" = \"true\" ]; then\n echo \"FIPS check failed and blocking is enabled\"\n exit 1\n fi\n echo \"FIPS check failed but blocking is not enabled, continuing\"\nfi\n","environment":{"container":"evaluate-result","image":"oci://quay.io/rhoai-konflux/alpine@sha256:149feff81b1fc443edb5eb8351753344abb5aba4a04a5ade4a760fb9efe48c2e"}}]},{"after":["build-image-index"],"finishedOn":"2026-09-08T21:27:41Z","invocation":{"configSource":{},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/e8495340-f9f9-418c-a72a-d02c1044501c","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-546c798d5d232205-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"fips-check"}},"parameters":{"blocking":"true","image-digest":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","image-platform":"linux/ppc64le","image-url":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25"}},"name":"fips-check","ref":{},"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:28Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"ARCH=\"${IMAGE_PLATFORM#*/}\"\nif [ \"${ARCH}\" = \"x86_64\" ]; then ARCH=\"amd64\"; fi\ncase \"${ARCH}\" in\n amd64|ppc64le|arm64|s390x) ;;\n *) ARCH=\"amd64\" ;;\nesac\nIMAGE_WITHOUT_TAG=$(echo \"${IMAGE_URL}\" | sed 's/\\(.*\\):.*/\\1/')\nPLATFORM_DIGEST=$(skopeo inspect --raw \"docker://${IMAGE_WITHOUT_TAG}@${IMAGE_DIGEST}\" | jq -r \".manifests[] | select(.platform.architecture == \\\"${ARCH}\\\") | .digest\")\nif [ -z \"${PLATFORM_DIGEST}\" ]; then\n echo \"Could not find digest for architecture ${ARCH} in ${IMAGE_URL}@${IMAGE_DIGEST}\"\n exit 1\nfi\nprintf '%s' \"${IMAGE_WITHOUT_TAG}@${PLATFORM_DIGEST}\" > /tekton/home/unique_related_images.txt\n","environment":{"container":"prepare-image-list","image":"oci://quay.io/konflux-ci/konflux-test@sha256:04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14"}},{"annotations":null,"arguments":["-s","--","bash","-c","set -euo pipefail\n# shellcheck source=/dev/null\n. /utils.sh\n\nexport RETRY_COUNT=2\nexport RETRY_INTERVAL=5\n\n# Create temporary directory for parallel processing counters\ncounter_dir=$(mktemp -d)\ntrap 'rm -rf \"$counter_dir\"' EXIT\n\n# Function to clean up OCI image and extracted directory\ncleanup_image_artifacts() {\n local image_num=\"$1\"\n local component_label=\"$2\"\n local version_label=\"$3\"\n local release_label=\"$4\"\n # Clean up OCI directory (may already be deleted by inline rm, or may not exist)\n rm -rf \"/tekton/home/${image_num}-${component_label}-${version_label}-${release_label}\" 2>/dev/null || true\n # Clean up extracted directory (may or may not exist depending on failure point)\n rm -rf \"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\" 2>/dev/null || true\n}\n\n# Function to process a single related image\nprocess_image() {\n # shellcheck source=/dev/null\n . /utils.sh\n\n local related_image=\"$1\"\n local image_num=\"$2\"\n local total_images=\"$3\"\n local check_payload_version=\"$4\"\n local image_mirror_map=\"$5\"\n\n related_image=\"${related_image//$'\\n'/}\"\n echo \"Processing related image ${image_num} of ${total_images}: ${related_image}\"\n\n image_accessible=0\n if ! image_labels=$(get_image_labels \"$related_image\"); then\n echo \"Could not inspect original pullspec $related_image. Checking if there's a mirror present\"\n if [ -n \"${image_mirror_map}\" ]; then\n reg_and_repo=$(get_image_registry_and_repository \"${related_image}\")\n mapfile -t mirrors < <(get_image_mirror_list \"${reg_and_repo}\" \"${image_mirror_map}\")\n if [[ -z \"${mirrors[0]}\" ]]; then\n echo \"No mirrors found in image mirror map for ${reg_and_repo}\"\n else\n echo \"Mirrors for $reg_and_repo are:\"\n printf \"%s\\n\" \"${mirrors[@]}\"\n\n for mirror in \"${mirrors[@]}\"; do\n echo \"Attempting to use mirror ${mirror}\"\n replaced_image=$(replace_image_pullspec \"$related_image\" \"$mirror\")\n if ! image_labels=$(get_image_labels \"$replaced_image\"); then\n echo \"Mirror $mirror is inaccessible.\"\n continue\n fi\n image_accessible=1\n echo \"Replacing $related_image with $replaced_image\"\n related_image=\"$replaced_image\"\n break\n done\n fi\n fi\n else\n image_accessible=1\n echo \"Successfully inspected $related_image. Mirror not required.\"\n fi\n\n if [[ $image_accessible -eq 0 ]]; then\n echo -e \"Error: Unable to scan image: Could not inspect image ${related_image} for labels\\n\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n component_label=$(echo \"${image_labels}\" | grep 'com.redhat.component=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n version_label=$(echo \"${image_labels}\" | grep '^version=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n release_label=$(echo \"${image_labels}\" | grep 'release=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n echo \"Component label is ${component_label}\"\n echo \"Version label is ${version_label}\"\n echo \"Release label is ${release_label}\"\n\n # Sanitize component_label to prevent directory path issues\n # Replace problematic characters (/ \\ : * ? \" < > | and whitespace) with hyphens\n sanitized_component_label=$(echo -n \"${component_label}\" | tr '/\\\\:*?\"<>|[:space:]' '-')\n echo \"Sanitized component label for path usage: ${component_label} -> ${sanitized_component_label}\"\n component_label=\"${sanitized_component_label}\"\n\n if [ -z \"${component_label}\" ]; then\n echo -e \"Error: Unable to scan image: Could not get com.redhat.component label for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n\n # Sanitize the image reference to handle Docker references with both tag and digest\n sanitized_related_image=$(get_image_registry_repository_digest \"${related_image}\")\n\n # If no digest is present, fallback to using tag-based sanitization\n if [[ \"${sanitized_related_image}\" != *\"@\"* ]]; then\n echo \"No digest found in sanitized image, using tag-based sanitization\"\n sanitized_related_image=$(get_image_registry_repository_tag \"${related_image}\")\n fi\n echo \"Successfully sanitized image reference: ${sanitized_related_image}. Using sanitized image reference for extraction\"\n\n # Fetch the first available architecture so that the skopeo copy does not fail if the default arch is not available\n first_arch=$(get_first_arch \"${sanitized_related_image}\")\n echo \"Detected architecture for ${sanitized_related_image}: ${first_arch}\"\n\n # Create destination directory for extraction\n extract_dir=\"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\"\n mkdir -p \"${extract_dir}\"\n\n # Extract image filesystem using oc image extract, with fallback to skopeo+umoci\n # oc image extract may fail with large images under high parallelism\n extraction_success=1\n if oc image extract \"${sanitized_related_image}\" \\\n --path=/:\"${extract_dir}\" \\\n --filter-by-os=\".*/${first_arch}\" \\\n --confirm \\\n --preserve-ownership; then\n extraction_success=0\n echo \"Successfully extracted ${related_image} using oc image extract\"\n else\n echo \"oc image extract failed for ${related_image}, falling back to skopeo+umoci\"\n # Clean up partial extraction before fallback\n rm -rf \"${extract_dir}\" 2>/dev/null || true\n mkdir -p \"${extract_dir}\"\n\n # Fallback: use skopeo copy + umoci unpack\n oci_dir=\"/tekton/home/${image_num}-${component_label}-${version_label}-${release_label}\"\n if retry skopeo copy --override-arch \"${first_arch}\" --remove-signatures \\\n \"docker://${sanitized_related_image}\" \\\n \"oci://${oci_dir}:latest\"; then\n if retry umoci raw unpack --rootless \\\n --image \"${oci_dir}:latest\" \\\n \"${extract_dir}\"; then\n extraction_success=0\n echo \"Successfully extracted ${related_image} using skopeo+umoci fallback\"\n else\n echo \"umoci unpack failed for ${related_image}\"\n fi\n # Clean up OCI image regardless of umoci success\n rm -rf \"${oci_dir}\" 2>/dev/null || true\n else\n echo \"skopeo copy failed for ${related_image}\"\n fi\n fi\n\n if [[ \"${extraction_success}\" -ne 0 ]]; then\n echo -e \"Error: Unable to scan image: Could not extract filesystem from ${related_image}\\n\"\n # Clean up any partial extracted directory to prevent resource accumulation\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n\n # Run check-payload on the extracted image\n # The check-payload command fails with exit 1 when the scan for an image is unsuccessful\n # or when the image is not FIPS compliant. Hence, count those as failures and not errors\n if ! check-payload scan local \\\n --path=\"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\" \\\n \"${check_payload_version}\" \\\n --components=\"${component_label}\" \\\n --output-format=csv \\\n --output-file=\"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan failed for ${related_image}\\n\"\n # Clean up extracted directory on scan failure to prevent resource accumulation\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n echo \"1\" >> \"${counter_dir}/failure\"\n return\n fi\n\n if [ -f \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\" ]; then\n if grep -q -- \"---- Successful run\" \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan was successful for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/success\"\n # Clean up extracted directory on successful run to save space\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n elif grep -q -- \"---- Successful run with warnings\" \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan was successful with warnings for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/warnings\"\n # Clean up extracted directory on successful run with warnings to save space\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n fi\n fi\n}\n\nif [ ! -e \"/tekton/home/unique_related_images.txt\" ]; then\n echo \"No relatedImages to process\"\n exit 0\nfi\n\nmapfile -d ' ' -t related_images < <(cat /tekton/home/unique_related_images.txt)\necho \"Related images are :\"\nprintf \"%s\\n\" \"${related_images[@]}\"\n\n# If target OCP version is found, use it to apply the exception list when running check-payload\ncheck_payload_version=\"\"\nif [ -f \"/tekton/home/target_ocp_version.txt\" ]; then\n version=$(cat \"/tekton/home/target_ocp_version.txt\")\n check_payload_version=\"-V=${version}\"\n echo \"Target OCP version found: ${check_payload_version}\"\nfi\n\n# Check if an image to mirror map is defined for unreleased images\nimage_mirror_map=\"\"\nif [ -f \"/tekton/home/related-images-map.txt\" ]; then\n image_mirror_map=$(cat \"/tekton/home/related-images-map.txt\")\n echo \"Image Mirror Map found:\"\n echo \"${image_mirror_map}\" | jq '.'\nfi\n\n# Process images in parallel with MAX_PARALLEL limit\necho \"Processing ${#related_images[@]} images with MAX_PARALLEL=${MAX_PARALLEL}\"\ndeclare -i count=0\nfor related_image in \"${related_images[@]}\"; do\n count+=1\n # Wait if we've reached the parallel limit\n while [ \"$(jobs -r | wc -l)\" -ge \"${MAX_PARALLEL}\" ]; do\n wait -n\n done\n # Launch background job to process image\n process_image \"$related_image\" \"$count\" \"${#related_images[@]}\" \"$check_payload_version\" \"$image_mirror_map\" &\ndone\n\n# Wait for all background jobs to complete\nwait\n\n# Aggregate results from counter files\nsuccess_counter=0\nwarnings_counter=0\nerror_counter=0\nfailure_counter=0\n\nif [ -f \"${counter_dir}/success\" ]; then\n success_counter=$(wc -l < \"${counter_dir}/success\")\nfi\nif [ -f \"${counter_dir}/warnings\" ]; then\n warnings_counter=$(wc -l < \"${counter_dir}/warnings\")\nfi\nif [ -f \"${counter_dir}/error\" ]; then\n error_counter=$(wc -l < \"${counter_dir}/error\")\nfi\nif [ -f \"${counter_dir}/failure\" ]; then\n failure_counter=$(wc -l < \"${counter_dir}/failure\")\nfi\n\necho \"Results: success=${success_counter}, warnings=${warnings_counter}, errors=${error_counter}, failures=${failure_counter}\"\n\nnote=\"Task odh-kserve-agent-v2-25-on-push-xwfsp-fips-check-1 failed: Some images could not be scanned. For details, check Tekton task log.\"\nERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\n\nnote=\"Task odh-kserve-agent-v2-25-on-push-xwfsp-fips-check-1 completed: Check result for task result.\"\nif [[ \"$error_counter\" == 0 ]];\nthen\n if [[ \"${failure_counter}\" -gt 0 ]]; then\n RES=\"FAILURE\"\n elif [[ \"${warnings_counter}\" -gt 0 ]]; then\n RES=\"WARNING\"\n else\n RES=\"SUCCESS\"\n fi\n TEST_OUTPUT=$(make_result_json \\\n -r \"${RES}\" \\\n -s \"${success_counter}\" -f \"${failure_counter}\" -w \"${warnings_counter}\" -t \"$note\")\nfi\necho \"${TEST_OUTPUT:-${ERROR_OUTPUT}}\" | tee \"/tekton/steps/step-run-fips-check/results/TEST_OUTPUT\"\n"],"entryPoint":"/usr/bin/tini","environment":{"container":"run-fips-check","image":"oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b"}},{"annotations":null,"arguments":null,"entryPoint":"echo \"${TEST_OUTPUT}\"\nif echo \"${TEST_OUTPUT}\" | grep -qE '\"result\":\"(FAILURE|ERROR)\"'; then\n if [ \"${BLOCKING}\" = \"true\" ]; then\n echo \"FIPS check failed and blocking is enabled\"\n exit 1\n fi\n echo \"FIPS check failed but blocking is not enabled, continuing\"\nfi\n","environment":{"container":"evaluate-result","image":"oci://quay.io/rhoai-konflux/alpine@sha256:149feff81b1fc443edb5eb8351753344abb5aba4a04a5ade4a760fb9efe48c2e"}}]},{"after":["build-image-index"],"finishedOn":"2026-09-08T21:27:40Z","invocation":{"configSource":{},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/100f073d-abce-4d9e-a705-ca29cb130d40","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-c80b1b3d661e34a6-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"fips-check"}},"parameters":{"blocking":"true","image-digest":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","image-platform":"linux/s390x","image-url":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25"}},"name":"fips-check","ref":{},"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:28Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"ARCH=\"${IMAGE_PLATFORM#*/}\"\nif [ \"${ARCH}\" = \"x86_64\" ]; then ARCH=\"amd64\"; fi\ncase \"${ARCH}\" in\n amd64|ppc64le|arm64|s390x) ;;\n *) ARCH=\"amd64\" ;;\nesac\nIMAGE_WITHOUT_TAG=$(echo \"${IMAGE_URL}\" | sed 's/\\(.*\\):.*/\\1/')\nPLATFORM_DIGEST=$(skopeo inspect --raw \"docker://${IMAGE_WITHOUT_TAG}@${IMAGE_DIGEST}\" | jq -r \".manifests[] | select(.platform.architecture == \\\"${ARCH}\\\") | .digest\")\nif [ -z \"${PLATFORM_DIGEST}\" ]; then\n echo \"Could not find digest for architecture ${ARCH} in ${IMAGE_URL}@${IMAGE_DIGEST}\"\n exit 1\nfi\nprintf '%s' \"${IMAGE_WITHOUT_TAG}@${PLATFORM_DIGEST}\" > /tekton/home/unique_related_images.txt\n","environment":{"container":"prepare-image-list","image":"oci://quay.io/konflux-ci/konflux-test@sha256:04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14"}},{"annotations":null,"arguments":["-s","--","bash","-c","set -euo pipefail\n# shellcheck source=/dev/null\n. /utils.sh\n\nexport RETRY_COUNT=2\nexport RETRY_INTERVAL=5\n\n# Create temporary directory for parallel processing counters\ncounter_dir=$(mktemp -d)\ntrap 'rm -rf \"$counter_dir\"' EXIT\n\n# Function to clean up OCI image and extracted directory\ncleanup_image_artifacts() {\n local image_num=\"$1\"\n local component_label=\"$2\"\n local version_label=\"$3\"\n local release_label=\"$4\"\n # Clean up OCI directory (may already be deleted by inline rm, or may not exist)\n rm -rf \"/tekton/home/${image_num}-${component_label}-${version_label}-${release_label}\" 2>/dev/null || true\n # Clean up extracted directory (may or may not exist depending on failure point)\n rm -rf \"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\" 2>/dev/null || true\n}\n\n# Function to process a single related image\nprocess_image() {\n # shellcheck source=/dev/null\n . /utils.sh\n\n local related_image=\"$1\"\n local image_num=\"$2\"\n local total_images=\"$3\"\n local check_payload_version=\"$4\"\n local image_mirror_map=\"$5\"\n\n related_image=\"${related_image//$'\\n'/}\"\n echo \"Processing related image ${image_num} of ${total_images}: ${related_image}\"\n\n image_accessible=0\n if ! image_labels=$(get_image_labels \"$related_image\"); then\n echo \"Could not inspect original pullspec $related_image. Checking if there's a mirror present\"\n if [ -n \"${image_mirror_map}\" ]; then\n reg_and_repo=$(get_image_registry_and_repository \"${related_image}\")\n mapfile -t mirrors < <(get_image_mirror_list \"${reg_and_repo}\" \"${image_mirror_map}\")\n if [[ -z \"${mirrors[0]}\" ]]; then\n echo \"No mirrors found in image mirror map for ${reg_and_repo}\"\n else\n echo \"Mirrors for $reg_and_repo are:\"\n printf \"%s\\n\" \"${mirrors[@]}\"\n\n for mirror in \"${mirrors[@]}\"; do\n echo \"Attempting to use mirror ${mirror}\"\n replaced_image=$(replace_image_pullspec \"$related_image\" \"$mirror\")\n if ! image_labels=$(get_image_labels \"$replaced_image\"); then\n echo \"Mirror $mirror is inaccessible.\"\n continue\n fi\n image_accessible=1\n echo \"Replacing $related_image with $replaced_image\"\n related_image=\"$replaced_image\"\n break\n done\n fi\n fi\n else\n image_accessible=1\n echo \"Successfully inspected $related_image. Mirror not required.\"\n fi\n\n if [[ $image_accessible -eq 0 ]]; then\n echo -e \"Error: Unable to scan image: Could not inspect image ${related_image} for labels\\n\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n component_label=$(echo \"${image_labels}\" | grep 'com.redhat.component=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n version_label=$(echo \"${image_labels}\" | grep '^version=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n release_label=$(echo \"${image_labels}\" | grep 'release=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n echo \"Component label is ${component_label}\"\n echo \"Version label is ${version_label}\"\n echo \"Release label is ${release_label}\"\n\n # Sanitize component_label to prevent directory path issues\n # Replace problematic characters (/ \\ : * ? \" < > | and whitespace) with hyphens\n sanitized_component_label=$(echo -n \"${component_label}\" | tr '/\\\\:*?\"<>|[:space:]' '-')\n echo \"Sanitized component label for path usage: ${component_label} -> ${sanitized_component_label}\"\n component_label=\"${sanitized_component_label}\"\n\n if [ -z \"${component_label}\" ]; then\n echo -e \"Error: Unable to scan image: Could not get com.redhat.component label for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n\n # Sanitize the image reference to handle Docker references with both tag and digest\n sanitized_related_image=$(get_image_registry_repository_digest \"${related_image}\")\n\n # If no digest is present, fallback to using tag-based sanitization\n if [[ \"${sanitized_related_image}\" != *\"@\"* ]]; then\n echo \"No digest found in sanitized image, using tag-based sanitization\"\n sanitized_related_image=$(get_image_registry_repository_tag \"${related_image}\")\n fi\n echo \"Successfully sanitized image reference: ${sanitized_related_image}. Using sanitized image reference for extraction\"\n\n # Fetch the first available architecture so that the skopeo copy does not fail if the default arch is not available\n first_arch=$(get_first_arch \"${sanitized_related_image}\")\n echo \"Detected architecture for ${sanitized_related_image}: ${first_arch}\"\n\n # Create destination directory for extraction\n extract_dir=\"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\"\n mkdir -p \"${extract_dir}\"\n\n # Extract image filesystem using oc image extract, with fallback to skopeo+umoci\n # oc image extract may fail with large images under high parallelism\n extraction_success=1\n if oc image extract \"${sanitized_related_image}\" \\\n --path=/:\"${extract_dir}\" \\\n --filter-by-os=\".*/${first_arch}\" \\\n --confirm \\\n --preserve-ownership; then\n extraction_success=0\n echo \"Successfully extracted ${related_image} using oc image extract\"\n else\n echo \"oc image extract failed for ${related_image}, falling back to skopeo+umoci\"\n # Clean up partial extraction before fallback\n rm -rf \"${extract_dir}\" 2>/dev/null || true\n mkdir -p \"${extract_dir}\"\n\n # Fallback: use skopeo copy + umoci unpack\n oci_dir=\"/tekton/home/${image_num}-${component_label}-${version_label}-${release_label}\"\n if retry skopeo copy --override-arch \"${first_arch}\" --remove-signatures \\\n \"docker://${sanitized_related_image}\" \\\n \"oci://${oci_dir}:latest\"; then\n if retry umoci raw unpack --rootless \\\n --image \"${oci_dir}:latest\" \\\n \"${extract_dir}\"; then\n extraction_success=0\n echo \"Successfully extracted ${related_image} using skopeo+umoci fallback\"\n else\n echo \"umoci unpack failed for ${related_image}\"\n fi\n # Clean up OCI image regardless of umoci success\n rm -rf \"${oci_dir}\" 2>/dev/null || true\n else\n echo \"skopeo copy failed for ${related_image}\"\n fi\n fi\n\n if [[ \"${extraction_success}\" -ne 0 ]]; then\n echo -e \"Error: Unable to scan image: Could not extract filesystem from ${related_image}\\n\"\n # Clean up any partial extracted directory to prevent resource accumulation\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n\n # Run check-payload on the extracted image\n # The check-payload command fails with exit 1 when the scan for an image is unsuccessful\n # or when the image is not FIPS compliant. Hence, count those as failures and not errors\n if ! check-payload scan local \\\n --path=\"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\" \\\n \"${check_payload_version}\" \\\n --components=\"${component_label}\" \\\n --output-format=csv \\\n --output-file=\"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan failed for ${related_image}\\n\"\n # Clean up extracted directory on scan failure to prevent resource accumulation\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n echo \"1\" >> \"${counter_dir}/failure\"\n return\n fi\n\n if [ -f \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\" ]; then\n if grep -q -- \"---- Successful run\" \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan was successful for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/success\"\n # Clean up extracted directory on successful run to save space\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n elif grep -q -- \"---- Successful run with warnings\" \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan was successful with warnings for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/warnings\"\n # Clean up extracted directory on successful run with warnings to save space\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n fi\n fi\n}\n\nif [ ! -e \"/tekton/home/unique_related_images.txt\" ]; then\n echo \"No relatedImages to process\"\n exit 0\nfi\n\nmapfile -d ' ' -t related_images < <(cat /tekton/home/unique_related_images.txt)\necho \"Related images are :\"\nprintf \"%s\\n\" \"${related_images[@]}\"\n\n# If target OCP version is found, use it to apply the exception list when running check-payload\ncheck_payload_version=\"\"\nif [ -f \"/tekton/home/target_ocp_version.txt\" ]; then\n version=$(cat \"/tekton/home/target_ocp_version.txt\")\n check_payload_version=\"-V=${version}\"\n echo \"Target OCP version found: ${check_payload_version}\"\nfi\n\n# Check if an image to mirror map is defined for unreleased images\nimage_mirror_map=\"\"\nif [ -f \"/tekton/home/related-images-map.txt\" ]; then\n image_mirror_map=$(cat \"/tekton/home/related-images-map.txt\")\n echo \"Image Mirror Map found:\"\n echo \"${image_mirror_map}\" | jq '.'\nfi\n\n# Process images in parallel with MAX_PARALLEL limit\necho \"Processing ${#related_images[@]} images with MAX_PARALLEL=${MAX_PARALLEL}\"\ndeclare -i count=0\nfor related_image in \"${related_images[@]}\"; do\n count+=1\n # Wait if we've reached the parallel limit\n while [ \"$(jobs -r | wc -l)\" -ge \"${MAX_PARALLEL}\" ]; do\n wait -n\n done\n # Launch background job to process image\n process_image \"$related_image\" \"$count\" \"${#related_images[@]}\" \"$check_payload_version\" \"$image_mirror_map\" &\ndone\n\n# Wait for all background jobs to complete\nwait\n\n# Aggregate results from counter files\nsuccess_counter=0\nwarnings_counter=0\nerror_counter=0\nfailure_counter=0\n\nif [ -f \"${counter_dir}/success\" ]; then\n success_counter=$(wc -l < \"${counter_dir}/success\")\nfi\nif [ -f \"${counter_dir}/warnings\" ]; then\n warnings_counter=$(wc -l < \"${counter_dir}/warnings\")\nfi\nif [ -f \"${counter_dir}/error\" ]; then\n error_counter=$(wc -l < \"${counter_dir}/error\")\nfi\nif [ -f \"${counter_dir}/failure\" ]; then\n failure_counter=$(wc -l < \"${counter_dir}/failure\")\nfi\n\necho \"Results: success=${success_counter}, warnings=${warnings_counter}, errors=${error_counter}, failures=${failure_counter}\"\n\nnote=\"Task odh-kserve-agent-v2-25-on-push-xwfsp-fips-check-2 failed: Some images could not be scanned. For details, check Tekton task log.\"\nERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\n\nnote=\"Task odh-kserve-agent-v2-25-on-push-xwfsp-fips-check-2 completed: Check result for task result.\"\nif [[ \"$error_counter\" == 0 ]];\nthen\n if [[ \"${failure_counter}\" -gt 0 ]]; then\n RES=\"FAILURE\"\n elif [[ \"${warnings_counter}\" -gt 0 ]]; then\n RES=\"WARNING\"\n else\n RES=\"SUCCESS\"\n fi\n TEST_OUTPUT=$(make_result_json \\\n -r \"${RES}\" \\\n -s \"${success_counter}\" -f \"${failure_counter}\" -w \"${warnings_counter}\" -t \"$note\")\nfi\necho \"${TEST_OUTPUT:-${ERROR_OUTPUT}}\" | tee \"/tekton/steps/step-run-fips-check/results/TEST_OUTPUT\"\n"],"entryPoint":"/usr/bin/tini","environment":{"container":"run-fips-check","image":"oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b"}},{"annotations":null,"arguments":null,"entryPoint":"echo \"${TEST_OUTPUT}\"\nif echo \"${TEST_OUTPUT}\" | grep -qE '\"result\":\"(FAILURE|ERROR)\"'; then\n if [ \"${BLOCKING}\" = \"true\" ]; then\n echo \"FIPS check failed and blocking is enabled\"\n exit 1\n fi\n echo \"FIPS check failed but blocking is not enabled, continuing\"\nfi\n","environment":{"container":"evaluate-result","image":"oci://quay.io/rhoai-konflux/alpine@sha256:149feff81b1fc443edb5eb8351753344abb5aba4a04a5ade4a760fb9efe48c2e"}}]},{"after":["build-image-index"],"finishedOn":"2026-09-08T21:27:41Z","invocation":{"configSource":{},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/f96d4cd3-f1c1-4daa-85bf-a5d6f4128155","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-b8c48302b03ceff6-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"fips-check"}},"parameters":{"blocking":"true","image-digest":"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532","image-platform":"linux-m2xlarge/arm64","image-url":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25"}},"name":"fips-check","ref":{},"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:27:28Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"ARCH=\"${IMAGE_PLATFORM#*/}\"\nif [ \"${ARCH}\" = \"x86_64\" ]; then ARCH=\"amd64\"; fi\ncase \"${ARCH}\" in\n amd64|ppc64le|arm64|s390x) ;;\n *) ARCH=\"amd64\" ;;\nesac\nIMAGE_WITHOUT_TAG=$(echo \"${IMAGE_URL}\" | sed 's/\\(.*\\):.*/\\1/')\nPLATFORM_DIGEST=$(skopeo inspect --raw \"docker://${IMAGE_WITHOUT_TAG}@${IMAGE_DIGEST}\" | jq -r \".manifests[] | select(.platform.architecture == \\\"${ARCH}\\\") | .digest\")\nif [ -z \"${PLATFORM_DIGEST}\" ]; then\n echo \"Could not find digest for architecture ${ARCH} in ${IMAGE_URL}@${IMAGE_DIGEST}\"\n exit 1\nfi\nprintf '%s' \"${IMAGE_WITHOUT_TAG}@${PLATFORM_DIGEST}\" > /tekton/home/unique_related_images.txt\n","environment":{"container":"prepare-image-list","image":"oci://quay.io/konflux-ci/konflux-test@sha256:04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14"}},{"annotations":null,"arguments":["-s","--","bash","-c","set -euo pipefail\n# shellcheck source=/dev/null\n. /utils.sh\n\nexport RETRY_COUNT=2\nexport RETRY_INTERVAL=5\n\n# Create temporary directory for parallel processing counters\ncounter_dir=$(mktemp -d)\ntrap 'rm -rf \"$counter_dir\"' EXIT\n\n# Function to clean up OCI image and extracted directory\ncleanup_image_artifacts() {\n local image_num=\"$1\"\n local component_label=\"$2\"\n local version_label=\"$3\"\n local release_label=\"$4\"\n # Clean up OCI directory (may already be deleted by inline rm, or may not exist)\n rm -rf \"/tekton/home/${image_num}-${component_label}-${version_label}-${release_label}\" 2>/dev/null || true\n # Clean up extracted directory (may or may not exist depending on failure point)\n rm -rf \"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\" 2>/dev/null || true\n}\n\n# Function to process a single related image\nprocess_image() {\n # shellcheck source=/dev/null\n . /utils.sh\n\n local related_image=\"$1\"\n local image_num=\"$2\"\n local total_images=\"$3\"\n local check_payload_version=\"$4\"\n local image_mirror_map=\"$5\"\n\n related_image=\"${related_image//$'\\n'/}\"\n echo \"Processing related image ${image_num} of ${total_images}: ${related_image}\"\n\n image_accessible=0\n if ! image_labels=$(get_image_labels \"$related_image\"); then\n echo \"Could not inspect original pullspec $related_image. Checking if there's a mirror present\"\n if [ -n \"${image_mirror_map}\" ]; then\n reg_and_repo=$(get_image_registry_and_repository \"${related_image}\")\n mapfile -t mirrors < <(get_image_mirror_list \"${reg_and_repo}\" \"${image_mirror_map}\")\n if [[ -z \"${mirrors[0]}\" ]]; then\n echo \"No mirrors found in image mirror map for ${reg_and_repo}\"\n else\n echo \"Mirrors for $reg_and_repo are:\"\n printf \"%s\\n\" \"${mirrors[@]}\"\n\n for mirror in \"${mirrors[@]}\"; do\n echo \"Attempting to use mirror ${mirror}\"\n replaced_image=$(replace_image_pullspec \"$related_image\" \"$mirror\")\n if ! image_labels=$(get_image_labels \"$replaced_image\"); then\n echo \"Mirror $mirror is inaccessible.\"\n continue\n fi\n image_accessible=1\n echo \"Replacing $related_image with $replaced_image\"\n related_image=\"$replaced_image\"\n break\n done\n fi\n fi\n else\n image_accessible=1\n echo \"Successfully inspected $related_image. Mirror not required.\"\n fi\n\n if [[ $image_accessible -eq 0 ]]; then\n echo -e \"Error: Unable to scan image: Could not inspect image ${related_image} for labels\\n\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n component_label=$(echo \"${image_labels}\" | grep 'com.redhat.component=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n version_label=$(echo \"${image_labels}\" | grep '^version=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n release_label=$(echo \"${image_labels}\" | grep 'release=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n echo \"Component label is ${component_label}\"\n echo \"Version label is ${version_label}\"\n echo \"Release label is ${release_label}\"\n\n # Sanitize component_label to prevent directory path issues\n # Replace problematic characters (/ \\ : * ? \" < > | and whitespace) with hyphens\n sanitized_component_label=$(echo -n \"${component_label}\" | tr '/\\\\:*?\"<>|[:space:]' '-')\n echo \"Sanitized component label for path usage: ${component_label} -> ${sanitized_component_label}\"\n component_label=\"${sanitized_component_label}\"\n\n if [ -z \"${component_label}\" ]; then\n echo -e \"Error: Unable to scan image: Could not get com.redhat.component label for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n\n # Sanitize the image reference to handle Docker references with both tag and digest\n sanitized_related_image=$(get_image_registry_repository_digest \"${related_image}\")\n\n # If no digest is present, fallback to using tag-based sanitization\n if [[ \"${sanitized_related_image}\" != *\"@\"* ]]; then\n echo \"No digest found in sanitized image, using tag-based sanitization\"\n sanitized_related_image=$(get_image_registry_repository_tag \"${related_image}\")\n fi\n echo \"Successfully sanitized image reference: ${sanitized_related_image}. Using sanitized image reference for extraction\"\n\n # Fetch the first available architecture so that the skopeo copy does not fail if the default arch is not available\n first_arch=$(get_first_arch \"${sanitized_related_image}\")\n echo \"Detected architecture for ${sanitized_related_image}: ${first_arch}\"\n\n # Create destination directory for extraction\n extract_dir=\"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\"\n mkdir -p \"${extract_dir}\"\n\n # Extract image filesystem using oc image extract, with fallback to skopeo+umoci\n # oc image extract may fail with large images under high parallelism\n extraction_success=1\n if oc image extract \"${sanitized_related_image}\" \\\n --path=/:\"${extract_dir}\" \\\n --filter-by-os=\".*/${first_arch}\" \\\n --confirm \\\n --preserve-ownership; then\n extraction_success=0\n echo \"Successfully extracted ${related_image} using oc image extract\"\n else\n echo \"oc image extract failed for ${related_image}, falling back to skopeo+umoci\"\n # Clean up partial extraction before fallback\n rm -rf \"${extract_dir}\" 2>/dev/null || true\n mkdir -p \"${extract_dir}\"\n\n # Fallback: use skopeo copy + umoci unpack\n oci_dir=\"/tekton/home/${image_num}-${component_label}-${version_label}-${release_label}\"\n if retry skopeo copy --override-arch \"${first_arch}\" --remove-signatures \\\n \"docker://${sanitized_related_image}\" \\\n \"oci://${oci_dir}:latest\"; then\n if retry umoci raw unpack --rootless \\\n --image \"${oci_dir}:latest\" \\\n \"${extract_dir}\"; then\n extraction_success=0\n echo \"Successfully extracted ${related_image} using skopeo+umoci fallback\"\n else\n echo \"umoci unpack failed for ${related_image}\"\n fi\n # Clean up OCI image regardless of umoci success\n rm -rf \"${oci_dir}\" 2>/dev/null || true\n else\n echo \"skopeo copy failed for ${related_image}\"\n fi\n fi\n\n if [[ \"${extraction_success}\" -ne 0 ]]; then\n echo -e \"Error: Unable to scan image: Could not extract filesystem from ${related_image}\\n\"\n # Clean up any partial extracted directory to prevent resource accumulation\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n\n # Run check-payload on the extracted image\n # The check-payload command fails with exit 1 when the scan for an image is unsuccessful\n # or when the image is not FIPS compliant. Hence, count those as failures and not errors\n if ! check-payload scan local \\\n --path=\"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\" \\\n \"${check_payload_version}\" \\\n --components=\"${component_label}\" \\\n --output-format=csv \\\n --output-file=\"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan failed for ${related_image}\\n\"\n # Clean up extracted directory on scan failure to prevent resource accumulation\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n echo \"1\" >> \"${counter_dir}/failure\"\n return\n fi\n\n if [ -f \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\" ]; then\n if grep -q -- \"---- Successful run\" \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan was successful for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/success\"\n # Clean up extracted directory on successful run to save space\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n elif grep -q -- \"---- Successful run with warnings\" \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan was successful with warnings for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/warnings\"\n # Clean up extracted directory on successful run with warnings to save space\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n fi\n fi\n}\n\nif [ ! -e \"/tekton/home/unique_related_images.txt\" ]; then\n echo \"No relatedImages to process\"\n exit 0\nfi\n\nmapfile -d ' ' -t related_images < <(cat /tekton/home/unique_related_images.txt)\necho \"Related images are :\"\nprintf \"%s\\n\" \"${related_images[@]}\"\n\n# If target OCP version is found, use it to apply the exception list when running check-payload\ncheck_payload_version=\"\"\nif [ -f \"/tekton/home/target_ocp_version.txt\" ]; then\n version=$(cat \"/tekton/home/target_ocp_version.txt\")\n check_payload_version=\"-V=${version}\"\n echo \"Target OCP version found: ${check_payload_version}\"\nfi\n\n# Check if an image to mirror map is defined for unreleased images\nimage_mirror_map=\"\"\nif [ -f \"/tekton/home/related-images-map.txt\" ]; then\n image_mirror_map=$(cat \"/tekton/home/related-images-map.txt\")\n echo \"Image Mirror Map found:\"\n echo \"${image_mirror_map}\" | jq '.'\nfi\n\n# Process images in parallel with MAX_PARALLEL limit\necho \"Processing ${#related_images[@]} images with MAX_PARALLEL=${MAX_PARALLEL}\"\ndeclare -i count=0\nfor related_image in \"${related_images[@]}\"; do\n count+=1\n # Wait if we've reached the parallel limit\n while [ \"$(jobs -r | wc -l)\" -ge \"${MAX_PARALLEL}\" ]; do\n wait -n\n done\n # Launch background job to process image\n process_image \"$related_image\" \"$count\" \"${#related_images[@]}\" \"$check_payload_version\" \"$image_mirror_map\" &\ndone\n\n# Wait for all background jobs to complete\nwait\n\n# Aggregate results from counter files\nsuccess_counter=0\nwarnings_counter=0\nerror_counter=0\nfailure_counter=0\n\nif [ -f \"${counter_dir}/success\" ]; then\n success_counter=$(wc -l < \"${counter_dir}/success\")\nfi\nif [ -f \"${counter_dir}/warnings\" ]; then\n warnings_counter=$(wc -l < \"${counter_dir}/warnings\")\nfi\nif [ -f \"${counter_dir}/error\" ]; then\n error_counter=$(wc -l < \"${counter_dir}/error\")\nfi\nif [ -f \"${counter_dir}/failure\" ]; then\n failure_counter=$(wc -l < \"${counter_dir}/failure\")\nfi\n\necho \"Results: success=${success_counter}, warnings=${warnings_counter}, errors=${error_counter}, failures=${failure_counter}\"\n\nnote=\"Task odh-kserve-agent-v2-25-on-push-xwfsp-fips-check-3 failed: Some images could not be scanned. For details, check Tekton task log.\"\nERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\n\nnote=\"Task odh-kserve-agent-v2-25-on-push-xwfsp-fips-check-3 completed: Check result for task result.\"\nif [[ \"$error_counter\" == 0 ]];\nthen\n if [[ \"${failure_counter}\" -gt 0 ]]; then\n RES=\"FAILURE\"\n elif [[ \"${warnings_counter}\" -gt 0 ]]; then\n RES=\"WARNING\"\n else\n RES=\"SUCCESS\"\n fi\n TEST_OUTPUT=$(make_result_json \\\n -r \"${RES}\" \\\n -s \"${success_counter}\" -f \"${failure_counter}\" -w \"${warnings_counter}\" -t \"$note\")\nfi\necho \"${TEST_OUTPUT:-${ERROR_OUTPUT}}\" | tee \"/tekton/steps/step-run-fips-check/results/TEST_OUTPUT\"\n"],"entryPoint":"/usr/bin/tini","environment":{"container":"run-fips-check","image":"oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b"}},{"annotations":null,"arguments":null,"entryPoint":"echo \"${TEST_OUTPUT}\"\nif echo \"${TEST_OUTPUT}\" | grep -qE '\"result\":\"(FAILURE|ERROR)\"'; then\n if [ \"${BLOCKING}\" = \"true\" ]; then\n echo \"FIPS check failed and blocking is enabled\"\n exit 1\n fi\n echo \"FIPS check failed but blocking is not enabled, continuing\"\nfi\n","environment":{"container":"evaluate-result","image":"oci://quay.io/rhoai-konflux/alpine@sha256:149feff81b1fc443edb5eb8351753344abb5aba4a04a5ade4a760fb9efe48c2e"}}]},{"after":["build-source-image","sast-shell-check","sast-unicode-check","deprecated-base-image-check","clair-scan","ecosystem-cert-preflight-checks","sast-snyk-check","clamav-scan","apply-tags","push-dockerfile","rpms-signature-scan","sast-coverity-check","coverity-availability-check","fips-check"],"finishedOn":"2026-09-08T21:28:38Z","invocation":{"configSource":{},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipeline.tekton.dev/release":"aa28e09810a679c1282095ae604afb1f5488e162","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/childReadyForDeletion":"true","results.tekton.dev/record":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/ce2b6dd4-2175-4f69-b7ba-32166133e7af","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","results.tekton.dev/result":"rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d","results.tekton.dev/stored":"true","tekton.dev/taskrunSpanContext":"{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-f8973a1dc1f9363e-01\"}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/memberOf":"tasks","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRun":"odh-kserve-agent-v2-25-on-push-xwfsp","tekton.dev/pipelineRunUID":"48d14ba0-ce28-4ff8-a2d2-10f2c712368d","tekton.dev/pipelineTask":"pipeline-success-indicator"}},"parameters":{}},"name":"pipeline-success-indicator","ref":{},"serviceAccountName":"build-pipeline-odh-kserve-agent-v2-25","startedOn":"2026-09-08T21:28:33Z","status":"Succeeded","steps":[{"annotations":null,"arguments":null,"entryPoint":"echo \"Success\"\n","environment":{"container":"noop","image":"oci://quay.io/rhoai-konflux/alpine@sha256:149feff81b1fc443edb5eb8351753344abb5aba4a04a5ade4a760fb9efe48c2e"}}]}]},"buildType":"tekton.dev/v1/PipelineRun","builder":{"id":"https://tekton.dev/chains/v2"},"invocation":{"configSource":{"digest":{"sha1":"ddcd122efdfbc61998906ef968b2b96f32f991b3"},"entryPoint":"pipelines/multi-arch-container-build.yaml","uri":"git+https://github.com/red-hat-data-services/konflux-central.git"},"environment":{"annotations":{"build.appstudio.openshift.io/build-nudge-files":"build/operator-nudging.yaml","build.appstudio.openshift.io/repo":"https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/commit_sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","build.appstudio.redhat.com/target_branch":"rhoai-2.25","kueue.konflux-ci.dev/requests-aws-ip":"1","kueue.konflux-ci.dev/requests-konflux-ci-dev-token":"1","kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64":"1","kueue.konflux-ci.dev/requests-linux-ppc64le":"1","kueue.konflux-ci.dev/requests-linux-s390x":"1","kueue.konflux-ci.dev/requests-linux-x86-64":"1","pipelinesascode.tekton.dev/branch":"rhoai-2.25","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/controller-info":"{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/git-auth-secret":"pac-gitauth-yvnajm","pipelinesascode.tekton.dev/git-provider":"github","pipelinesascode.tekton.dev/installation-id":"54743998","pipelinesascode.tekton.dev/log-url":"https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp","pipelinesascode.tekton.dev/max-keep-runs":"3","pipelinesascode.tekton.dev/on-cel-expression":"event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/scm-reporting-plr-started":"true","pipelinesascode.tekton.dev/secret-created":"true","pipelinesascode.tekton.dev/sender":"maskarb","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/sha-title":"Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112","pipelinesascode.tekton.dev/sha-url":"https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/source-branch":"refs/heads/rhoai-2.25","pipelinesascode.tekton.dev/source-repo-url":"https://github.com/red-hat-data-services/kserve","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","results.tekton.dev/recordSummaryAnnotations":"{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}","test.appstudio.openshift.io/pr-status":"merged"},"labels":{"app.kubernetes.io/managed-by":"pipelinesascode.tekton.dev","app.kubernetes.io/version":"v0.49.0","appstudio.openshift.io/application":"rhoai-v2-25","appstudio.openshift.io/component":"odh-kserve-agent-v2-25","kueue.x-k8s.io/priority-class":"konflux-post-merge-build","kueue.x-k8s.io/queue-name":"pipelines-queue","pipelines.appstudio.openshift.io/type":"build","pipelinesascode.tekton.dev/check-run-id":"102242466639","pipelinesascode.tekton.dev/event-type":"push","pipelinesascode.tekton.dev/original-prname":"odh-kserve-agent-v2-25-on-push","pipelinesascode.tekton.dev/pull-request":"4575","pipelinesascode.tekton.dev/repository":"odh-kserve-agent-v2-24","pipelinesascode.tekton.dev/sha":"58e7f0f6d889933345394152903c95c62e6bd9c3","pipelinesascode.tekton.dev/state":"queued","pipelinesascode.tekton.dev/url-org":"red-hat-data-services","pipelinesascode.tekton.dev/url-repository":"kserve","tekton.dev/pipeline":"odh-kserve-agent-v2-25-on-push-xwfsp"}},"parameters":{"additional-build-secret":"does-not-exist","additional-labels":[],"additional-tags":["rhoai-2.25-58e7f0f6d889933345394152903c95c62e6bd9c3"],"build-args":[],"build-args-file":"","build-image-index":"true","build-platforms":["linux/x86_64","linux/ppc64le","linux/s390x","linux-m2xlarge/arm64"],"build-source-image":"true","buildah-format":"docker","clone-depth":"1","disable-slack-notifications":"false","dockerfile":"Dockerfiles/agent.Dockerfile.konflux","enable-cache-proxy":"true","enable-package-registry-proxy":"true","expected-cluster":"","fetch-git-tags":"false","fips-check-blocking":"true","git-url":"https://github.com/red-hat-data-services/kserve","hermetic":"false","image-expires-after":"","omit-history":"false","output-image":"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25","path-context":".","prefetch-config-file-content":"","prefetch-input":"","prefetch-log-level":"info","privileged-nested":"false","revision":"58e7f0f6d889933345394152903c95c62e6bd9c3","rewrite-timestamp":"false","rhel-subscription-activation-key":"custom-activation-key","rhoai-version":"2.25.11","sast-target-dirs":".","skip-checks":"false","source-date-epoch":"","synk-secret":"synk-secret"}},"materials":[{"digest":{"sha1":"ddcd122efdfbc61998906ef968b2b96f32f991b3"},"uri":"git+https://github.com/red-hat-data-services/konflux-central.git"},{"digest":{"sha256":"25a147defd01e19674714f55d17538c8dbe55d8c305fa157ecc3f9c8977b05b6"},"uri":"oci://registry.access.redhat.com/ubi9/ubi"},{"digest":{"sha1":"c6e2c970f62d8ed9cc3960aa1ad3f6d72dadd68b"},"uri":"git+https://github.com/red-hat-data-services/rhoai-konflux-tasks.git"},{"digest":{"sha256":"85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f"},"uri":"oci://quay.io/konflux-ci/konflux-build-cli"},{"digest":{"sha256":"4be9343579d91c7b501cafe966cff59a601dfeca903c476e3763dd8d7599b900"},"uri":"quay.io/konflux-ci/tekton-catalog/task-init"},{"digest":{"sha256":"61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c"},"uri":"oci://quay.io/konflux-ci/build-trusted-artifacts"},{"digest":{"sha256":"2e8fe30b6d5c8a8a3e6bbc0ea5a55e05b6170d4a399830f25ea43e17881ce544"},"uri":"quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta"},{"digest":{"sha256":"4b01fbf98fa7155f5c21443c285f88853864ae7cc66981cf6b543fc6ba16b81b"},"uri":"oci://quay.io/konflux-ci/task-runner"},{"digest":{"sha256":"887e4fabf1707fc4018275b53fe89c0962ccb61d80d695cce49127096792edae"},"uri":"oci://quay.io/konflux-ci/hermeto"},{"digest":{"sha256":"374f776bcb2048c3adeaf4dbb460c52d001bc6020320df5e878c2d05391302da"},"uri":"quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta"},{"digest":{"sha256":"3eee4ecf87d50cb073318ab96097b9ea2cb6e5e59dd296a212e57017a9059f61"},"uri":"oci://quay.io/konflux-ci/mobster"},{"digest":{"sha256":"ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344"},"uri":"quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta"},{"digest":{"sha256":"135eec87fe80d0751a1ea5e8e47b240147b25ee9a41973cae365540d2e2ee473"},"uri":"oci://quay.io/konflux-ci/mobster"},{"digest":{"sha256":"290c9ec319423ff9ae7b2cb78fa859e1d333abcdd2ef6c001533377812020071"},"uri":"quay.io/konflux-ci/tekton-catalog/task-build-image-index"},{"digest":{"sha256":"38bfc93b0eacecd0aa5228225427524441c30e911b282a6b2eff9fdb0fdd021e"},"uri":"oci://quay.io/konflux-ci/task-runner"},{"digest":{"sha256":"a8416f792207e4b9b8bfea1c9b86ad54ae7bc28384d14de0726cced3dee01ae5"},"uri":"oci://quay.io/konflux-ci/source-container-build"},{"digest":{"sha256":"1808485d95cf77fb7912f6fe69191bead05fc0f2f71e00031941a7ea38a5f665"},"uri":"quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta"},{"digest":{"sha256":"dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b"},"uri":"oci://quay.io/konflux-ci/konflux-test"},{"digest":{"sha256":"0ccc688a77e9b7b0b8973c132a1e840844137e77f887be4a0bec8893b0776872"},"uri":"quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check"},{"digest":{"sha256":"6ed1dbb16de5a87f42df0d11cfb5b6bb0571a56e793b2c702c03e010846d34d5"},"uri":"oci://quay.io/konflux-ci/clair-in-ci"},{"digest":{"sha256":"1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab"},"uri":"oci://quay.io/konflux-ci/task-runner"},{"digest":{"sha256":"f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174"},"uri":"quay.io/konflux-ci/tekton-catalog/task-clair-scan"},{"digest":{"sha256":"15c5eeb451924ddfc9d8680319130fe277df7850728d5c37f13ae3eb9d607249"},"uri":"oci://quay.io/konflux-ci/build-trusted-artifacts"},{"digest":{"sha256":"04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14"},"uri":"oci://quay.io/konflux-ci/konflux-test"},{"digest":{"sha256":"1cc659b4d30536ec98300ac551739ef36dee345a7dcfe06129fd78abdc3688ac"},"uri":"oci://quay.io/konflux-ci/oras"},{"digest":{"sha256":"99e2263ad98c00b1b44012a325bf0b114684c9f6152fe259ada44e2561a8479e"},"uri":"quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta"},{"digest":{"sha256":"60297bb97fd977731706a64e252d969b81234422b0da065d9b9a57e9b103e74c"},"uri":"oci://quay.io/konflux-ci/clamav-db"},{"digest":{"sha256":"9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b"},"uri":"quay.io/konflux-ci/tekton-catalog/task-clamav-scan"},{"digest":{"sha256":"3bba1fe5ad96bd3811f34b367487192683aa9b1ba343da4885dda565b0a7207e"},"uri":"oci://quay.io/konflux-ci/konflux-test"},{"digest":{"sha256":"8b501440a960aec446db2ebc6625a49d0317a9fc7bf0f7bd9b18cb63052db7de"},"uri":"quay.io/konflux-ci/tekton-catalog/task-coverity-availability-check"},{"digest":{"sha256":"d9b01530ce3c20287714e64980f154e28c0e94d17e2dbfbaf3c8bf77b1844b9e"},"uri":"quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta"},{"digest":{"sha256":"381750451fbcc86d90fa83579a48e0e6555d7cf374fe2c4af3f9262a17fc3c89"},"uri":"quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta"},{"digest":{"sha256":"ccd3665345d86c6799bc7e2e6ad86b277d9f3a5c40b513e6f2a0af8ad92e7dba"},"uri":"quay.io/konflux-ci/tekton-catalog/task-apply-tags"},{"digest":{"sha256":"ef00a86cb22259fcfdefa15a5116b63d0f24ee35c95d05ff9815ee8f84beb548"},"uri":"quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta"},{"digest":{"sha256":"69102586287b89a162f7eaf4cded2db44a0df41da17016aacc4fadffa5490b6b"},"uri":"oci://quay.io/konflux-ci/tools"},{"digest":{"sha256":"9ef4dabd53e823e3139b99c8de708be4ee759d63b32982847929df19ab75b2f8"},"uri":"quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan"},{"digest":{"sha256":"149feff81b1fc443edb5eb8351753344abb5aba4a04a5ade4a760fb9efe48c2e"},"uri":"oci://quay.io/rhoai-konflux/alpine"},{"digest":{"sha1":"58e7f0f6d889933345394152903c95c62e6bd9c3"},"uri":"git+https://github.com/red-hat-data-services/kserve.git"}],"metadata":{"buildFinishedOn":"2026-09-08T21:28:38Z","buildStartedOn":"2026-09-08T21:20:56Z","completeness":{"environment":false,"materials":false,"parameters":false},"reproducible":false}}}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment