Repository navigation
Catalog health: API modernization, image pinning, and CVE remediation #1381
Description
Activity
@vdemeester I'm picking up this issue. Plan is to tackle it in two phases:
Phase 1 — API bump (v1beta1 → v1)
There are 121 tasks still on
v1beta1. I'll submit them in batches grouped by family — easier to review and keeps each PR focused:PR Family Tasks 01 openshift-* 4 02 argocd + deployment/CD 9 03 github-* 11 04 git + gitlab-* 8 05 code-quality (linters) A 9 06 code-quality (linters) B 9 07 CLI tools 11 08 cloud + storage 11 09 security + scanning 11 10 image build 6 11 messaging 6 12 kubernetes + EKS 5 13 developer tools 6 14 build + automation 8 15 testing + publishing + misc 7 All following
copy-then-modifyfrom CONTRIBUTING.md, bumpingpipelines.minVersionto0.50.0, updating tests/README, and pinning hardcoded mutable images by digest where applicable.Phase 2 — Script injection hardening
~85 tasks have
$(params.*)interpolated directly inscript:blocks. Once Phase 1 PRs land, I'll follow up moving those toenv:vars per AGENTS.md guidelines. Same family grouping.Heads up
- Aware of Update helm upgrade from repo to 0.4 #1318, fix(github-add-comment): add 0.8 with bounded results to avoid 4096 byte limit #1386, and feat: fix api endpoint and add optional ssl verification #1324 — will adjust version numbers if any of those merge first.
- Starting with the openshift-* family. Will submit in waves from there.
Happy to adjust the grouping or batch size if you have a preference.
- added 4 commits that reference this issue
on Sep 4, 2026 @gferreir also note that there is this proposal in review : tektoncd/community#1283
I still it is still nice to do this work before we sunset this repository though 👼🏼@vdemeester Thanks for the heads-up on TEP-0168. I read through it — makes sense as the next step for the catalog.
I agree that getting the cleanup done before the sunset is worth it. Tasks already on v1 with pinned images will be in better shape for whatever comes next, whether that's migration to tektoncd-catalog/* repos or just a cleaner archived state.
I'll pick up the pace on the remaining PRs. #1391 is up for review, and I'm working through the next batches (argocd/deployment, github-*, git/gitlab). Goal is to get as many of the 15 Phase 1 PRs submitted in the coming weeks.
If there's a rough timeline for the sunset, that'd help me prioritize which families to push first.
Reacted by Vincent Demeester- added a commit that references this issue
on Sep 18, 2026 - added 7 commits that reference this issue
on Sep 21, 2026 19 remaining items
- added 2 commits that reference this issue
on Sep 22, 2026 - added 10 commits that reference this issue
on Sep 25, 2026 - added a commit that references this issue
on Sep 25, 2026 Phase 1 update — all 121 tasks covered
Following the phased plan proposed earlier in this issue, all 15 PRs for the
v1beta1 → v1API bump are now open:PR Scope Tasks #1391 openshift-* 4 #1392 argocd + deployment/CD 9 #1393 github-* 11 #1394 kubernetes + EKS 5 #1395 CLI tools 11 #1396 code quality B (linters) 9 #1397 messaging 6 #1398 cloud + storage 11 #1399 security + scanning 11 #1400 testing + publishing + misc 7 #1401 build + automation 8 #1402 developer tools 5 #1403 image build 6 #1404 git + gitlab 8 #1405 code quality A (linters) 9 One thing to call out: in #1404,
gitlab-set-statuswas bumped to 0.4 instead of 0.3. PR #1324 (open, stale since 2025) also creates a 0.3 for that task, so skipping to 0.4 avoids a version collision without blocking either PR.Waiting for reviews and approvals on the open PRs so we can move to Phase 2 (script injection hardening).
- added a commit that references this issue
on Oct 1, 2026
Summary
A static + CVE analysis of the catalog's active (non-deprecated) resources surfaces a few concrete, mostly-mechanical maintenance buckets. Full interactive report (foldable, filterable):
Baseline
main@8e41018· 158 active resources (150 deprecated excluded).Findings
v1/ StepAction not onv1beta1@sha256:latest/ untagged images$(params)inscript:env)tests/run.yamlspec.descriptionProposed work (in rough priority)
:latestimages to current digestsplumbing/test-runner,goreleaser,gradle,gke-deploy, …) — usually a digest bumpv1/v1beta1(batched, copy-then-modify per task)$(params)-in-scripttasks, move interpolation toenvspec.descriptionandtests/run.yamlMethodology
catalog-health-analyzer.py(in the gist): parses primary manifests, resolves image digests (skopeo/crane), runs trivy for HIGH/CRITICAL. Re-run with--cve. Numbers excludetekton.dev/deprecatedresources by default.