From 6b3062544fda41e47ac62821770ceb8382b62d2c Mon Sep 17 00:00:00 2001 From: Rob Nester Date: Fri, 2 Oct 2026 10:21:23 -0400 Subject: [PATCH] Fix shell interpolation in task reports Pass `HOMEDIR` through the environment before formatting report output so parameter values are not inserted into shell command text in either published task variant. Co-Authored-By: Codex Ref: EC-2048 --- .../0.1/verify-conforma-konflux-ta.yaml | 5 ++++- .../0.1/verify-enterprise-contract.yaml | 5 ++++- 2 files changed, 8 insertions(+), 2 deletions(-) diff --git a/tasks/verify-conforma-konflux-ta/0.1/verify-conforma-konflux-ta.yaml b/tasks/verify-conforma-konflux-ta/0.1/verify-conforma-konflux-ta.yaml index 52b31c69..9521a983 100644 --- a/tasks/verify-conforma-konflux-ta/0.1/verify-conforma-konflux-ta.yaml +++ b/tasks/verify-conforma-konflux-ta/0.1/verify-conforma-konflux-ta.yaml @@ -571,6 +571,9 @@ spec: imagePullPolicy: IfNotPresent onError: continue # progress even if the step fails so we can see the debug logs command: [sh, -c] + env: + - name: HOMEDIR + value: "$(params.HOMEDIR)" args: # Format the JSON output to wrap lines at 8000 characters per line. # The report can get very large, so add some line breaks @@ -578,7 +581,7 @@ spec: # in the UI, easier to copy/paste, and less likely to cause problems # with logging systems or other consumers of the data (assuming they # correctly parse the full output). - - "jq . $(params.HOMEDIR)/report-json.json | awk '{gsub(/^ +/, \"\"); acc += length; if (acc >= 8000) { printf \"\\n\"; acc=length } printf $0 }'" + - "jq . \"${HOMEDIR}/report-json.json\" | awk '{gsub(/^ +/, \"\"); acc += length; if (acc >= 8000) { printf \"\\n\"; acc=length } printf $0 }'" - name: summary image: quay.io/conforma/cli:latest@sha256:af5bf40b0544d6d1d45bcdd8236f6393399ab6e7c5e83b815a23100d8389e945 diff --git a/tasks/verify-enterprise-contract/0.1/verify-enterprise-contract.yaml b/tasks/verify-enterprise-contract/0.1/verify-enterprise-contract.yaml index 49ea0c90..ea399c59 100644 --- a/tasks/verify-enterprise-contract/0.1/verify-enterprise-contract.yaml +++ b/tasks/verify-enterprise-contract/0.1/verify-enterprise-contract.yaml @@ -475,6 +475,9 @@ spec: imagePullPolicy: IfNotPresent onError: continue # progress even if the step fails so we can see the debug logs command: [sh, -c] + env: + - name: HOMEDIR + value: "$(params.HOMEDIR)" args: # Format the JSON output to wrap lines at 8000 characters per line. # The report can get very large, so add some line breaks @@ -482,7 +485,7 @@ spec: # in the UI, easier to copy/paste, and less likely to cause problems # with logging systems or other consumers of the data (assuming they # correctly parse the full output). - - "jq . $(params.HOMEDIR)/report-json.json | awk '{gsub(/^ +/, \"\"); acc += length; if (acc >= 8000) { printf \"\\n\"; acc=length } printf $0 }'" + - "jq . \"${HOMEDIR}/report-json.json\" | awk '{gsub(/^ +/, \"\"); acc += length; if (acc >= 8000) { printf \"\\n\"; acc=length } printf $0 }'" - name: summary computeResources: