Skip to content

Catalog health: API modernization, image pinning, and CVE remediation #1381

Description

@vdemeester

Summary

A static + CVE analysis of the catalog's active (non-deprecated) resources surfaces a few concrete, mostly-mechanical maintenance buckets. Full interactive report (foldable, filterable):

Baseline main@8e41018 · 158 active resources (150 deprecated excluded).

Findings

Area Count Notes
API version outdated 123 Task not on v1 / StepAction not on v1beta1
Mutable-tag images 46 not pinned to @sha256
:latest / untagged images 10 should pin
CVEs (HIGH/CRITICAL) 1,772 C / 18,437 H across 87 scanned images; high counts ≈ stale pins
$(params) in script: 79 hardening review (prefer env)
Privileged securityContext 5 mostly legitimate (buildah/buildkit) — review only
Missing tests/run.yaml (see report)
Missing spec.description (see report)

Note: $(params)-in-script and privileged are review signals, not automatic bugs — many are legitimate. PipelineResources usage is 0 among active resources (all such tasks are already deprecated).

Proposed work (in rough priority)

  • Supply chain: re-pin the 56 mutable/:latest images to current digests
  • CVEs: refresh the worst offenders (plumbing/test-runner, goreleaser, gradle, gke-deploy, …) — usually a digest bump
  • API: bump 123 outdated primaries to v1 / v1beta1 (batched, copy-then-modify per task)
  • Hardening: review the 79 $(params)-in-script tasks, move interpolation to env
  • Metadata/tests: fill missing spec.description and tests/run.yaml

Methodology

catalog-health-analyzer.py (in the gist): parses primary manifests, resolves image digests (skopeo/crane), runs trivy for HIGH/CRITICAL. Re-run with --cve. Numbers exclude tekton.dev/deprecated resources by default.

Activity

  1. gferreir commented on Sep 2, 2026

    @gferreir
    Contributor

    @vdemeester I'm picking up this issue. Plan is to tackle it in two phases:

    Phase 1 — API bump (v1beta1 → v1)

    There are 121 tasks still on v1beta1. I'll submit them in batches grouped by family — easier to review and keeps each PR focused:

    PR Family Tasks
    01 openshift-* 4
    02 argocd + deployment/CD 9
    03 github-* 11
    04 git + gitlab-* 8
    05 code-quality (linters) A 9
    06 code-quality (linters) B 9
    07 CLI tools 11
    08 cloud + storage 11
    09 security + scanning 11
    10 image build 6
    11 messaging 6
    12 kubernetes + EKS 5
    13 developer tools 6
    14 build + automation 8
    15 testing + publishing + misc 7

    All following copy-then-modify from CONTRIBUTING.md, bumping pipelines.minVersion to 0.50.0, updating tests/README, and pinning hardcoded mutable images by digest where applicable.

    Phase 2 — Script injection hardening

    ~85 tasks have $(params.*) interpolated directly in script: blocks. Once Phase 1 PRs land, I'll follow up moving those to env: vars per AGENTS.md guidelines. Same family grouping.

    Heads up

    Happy to adjust the grouping or batch size if you have a preference.

  2. vdemeester commented on Sep 14, 2026

    @vdemeester
    MemberAuthor

    @gferreir also note that there is this proposal in review : tektoncd/community#1283
    I still it is still nice to do this work before we sunset this repository though 👼🏼

  3. gferreir commented on Sep 16, 2026

    @gferreir
    Contributor

    @vdemeester Thanks for the heads-up on TEP-0168. I read through it — makes sense as the next step for the catalog.

    I agree that getting the cleanup done before the sunset is worth it. Tasks already on v1 with pinned images will be in better shape for whatever comes next, whether that's migration to tektoncd-catalog/* repos or just a cleaner archived state.

    I'll pick up the pace on the remaining PRs. #1391 is up for review, and I'm working through the next batches (argocd/deployment, github-*, git/gitlab). Goal is to get as many of the 15 Phase 1 PRs submitted in the coming weeks.

    If there's a rough timeline for the sunset, that'd help me prioritize which families to push first.

  4. 19 remaining items

  5. gferreir commented on Sep 25, 2026

    @gferreir
    Contributor

    Phase 1 update — all 121 tasks covered

    Following the phased plan proposed earlier in this issue, all 15 PRs for the v1beta1 → v1 API bump are now open:

    PR Scope Tasks
    #1391 openshift-* 4
    #1392 argocd + deployment/CD 9
    #1393 github-* 11
    #1394 kubernetes + EKS 5
    #1395 CLI tools 11
    #1396 code quality B (linters) 9
    #1397 messaging 6
    #1398 cloud + storage 11
    #1399 security + scanning 11
    #1400 testing + publishing + misc 7
    #1401 build + automation 8
    #1402 developer tools 5
    #1403 image build 6
    #1404 git + gitlab 8
    #1405 code quality A (linters) 9

    One thing to call out: in #1404, gitlab-set-status was bumped to 0.4 instead of 0.3. PR #1324 (open, stale since 2025) also creates a 0.3 for that task, so skipping to 0.4 avoids a version collision without blocking either PR.

    Waiting for reviews and approvals on the open PRs so we can move to Phase 2 (script injection hardening).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions