pod: component-prefetch-npm-on-p084051d2f64777793272c7182a890cd5-pod | init container: prepare 2026/08/18 04:51:09 Entrypoint initialization pod: component-prefetch-npm-on-p084051d2f64777793272c7182a890cd5-pod | init container: place-scripts 2026/08/18 04:51:12 Decoded script /tekton/scripts/script-0-v74w7 pod: component-prefetch-npm-on-p084051d2f64777793272c7182a890cd5-pod | container step-clone: INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt '/mnt/trusted-ca/ca-bundle.crt' -> '/etc/pki/ca-trust/source/anchors/ca-bundle.crt' time="2026-08-18T04:51:19Z" level=info msg="[param] url: https://github.com/redhat-appstudio-qe/nodejs-npm-sample-repo" time="2026-08-18T04:51:19Z" level=info msg="[param] revision: aa33e42b1cf41070296feb29de7afb6b8ace7d32" time="2026-08-18T04:51:19Z" level=info msg="[param] depth: 1" time="2026-08-18T04:51:19Z" level=info msg="[param] short-commit-length: 7" time="2026-08-18T04:51:19Z" level=info msg="[param] subdirectory: source" time="2026-08-18T04:51:19Z" level=info msg="[param] delete-existing: true" time="2026-08-18T04:51:19Z" level=info msg="[param] target-branch: main" time="2026-08-18T04:51:19Z" level=info msg="[param] merge-commit-author-name: Konflux CI Git Clone" time="2026-08-18T04:51:19Z" level=info msg="[param] merge-commit-author-email: git-clone@konflux-ci.dev" time="2026-08-18T04:51:19Z" level=info msg="[param] output-dir: /workspace/output" time="2026-08-18T04:51:19Z" level=info msg="[param] retry-max-attempts: 10" time="2026-08-18T04:51:19Z" level=info msg="[param] basic-auth-directory: /workspace/basic-auth" pod: component-prefetch-npm-on-p0c35f9aba40fdd2f8c362a11b72725e9-pod | init container: prepare 2026/08/18 04:54:12 Entrypoint initialization pod: component-prefetch-npm-on-p0c35f9aba40fdd2f8c362a11b72725e9-pod | init container: place-scripts 2026/08/18 04:54:18 Decoded script /tekton/scripts/script-0-sddtz 2026/08/18 04:54:18 Decoded script /tekton/scripts/script-1-88grj 2026/08/18 04:54:18 Decoded script /tekton/scripts/script-2-p9d8t 2026/08/18 04:54:18 Decoded script /tekton/scripts/script-3-4pgbp 2026/08/18 04:54:18 Decoded script /tekton/scripts/script-4-z4mn5 2026/08/18 04:54:18 Decoded script /tekton/scripts/script-5-kntnp pod: component-prefetch-npm-on-p0c35f9aba40fdd2f8c362a11b72725e9-pod | container step-introspect: Artifact type will be determined by introspection. Checking the media type of the OCI artifact... [retry] executing: skopeo inspect --raw --retry-times 3 docker://quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm:on-pr-aa33e42b1cf41070296feb29de7afb6b8ace7d32 The media type of the OCI artifact is application/vnd.docker.distribution.manifest.v2+json. Looking for image labels that indicate this might be an operator bundle... [retry] executing: skopeo inspect --retry-times 3 docker://quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm:on-pr-aa33e42b1cf41070296feb29de7afb6b8ace7d32 Found 0 matching labels. Expecting 3 or more to identify this image as an operator bundle. Introspection concludes that this artifact is of type "application". pod: component-prefetch-npm-on-p0c35f9aba40fdd2f8c362a11b72725e9-pod | container step-generate-container-auth: Selecting auth for quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm:on-pr-aa33e42b1cf41070296feb29de7afb6b8ace7d32 Using token for quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm Auth json written to "/auth/auth.json". pod: component-prefetch-npm-on-p0c35f9aba40fdd2f8c362a11b72725e9-pod | container step-set-skip-for-bundles: 2026/08/18 04:54:58 INFO Step was skipped due to when expressions were evaluated to false. pod: component-prefetch-npm-on-p0c35f9aba40fdd2f8c362a11b72725e9-pod | container step-app-check: time="2026-08-18T04:54:58Z" level=info msg="certification library version" version="1.20.0 " time="2026-08-18T04:54:59Z" level=info msg="running checks for quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm:on-pr-aa33e42b1cf41070296feb29de7afb6b8ace7d32 for platform amd64" time="2026-08-18T04:54:59Z" level=info msg="target image" image="quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm:on-pr-aa33e42b1cf41070296feb29de7afb6b8ace7d32" time="2026-08-18T04:55:15Z" level=info msg="warning: licenses directory does not exist or all of its children are empty directories: error when checking for /licenses: stat /tmp/preflight-1269113418/fs/licenses: no such file or directory" check=HasLicense time="2026-08-18T04:55:15Z" level=info msg="check completed" check=HasLicense result=FAILED time="2026-08-18T04:55:15Z" level=info msg="check completed" check=HasUniqueTag result=PASSED time="2026-08-18T04:55:15Z" level=info msg="check completed" check=LayerCountAcceptable result=PASSED time="2026-08-18T04:55:15Z" level=info msg="check completed" check=HasNoProhibitedPackages result=PASSED time="2026-08-18T04:55:15Z" level=info msg="check completed" check=HasRequiredLabel result=PASSED time="2026-08-18T04:55:15Z" level=info msg="USER 1001 specified that is non-root" check=RunAsNonRoot time="2026-08-18T04:55:15Z" level=info msg="check completed" check=RunAsNonRoot result=PASSED time="2026-08-18T04:55:28Z" level=info msg="check completed" check=HasModifiedFiles result=PASSED time="2026-08-18T04:55:29Z" level=info msg="check completed" check=BasedOnUbi result=PASSED time="2026-08-18T04:55:29Z" level=info msg="This image's tag on-pr-aa33e42b1cf41070296feb29de7afb6b8ace7d32 will be paired with digest sha256:03cc0170eef936909ad71cff9139bc47ef4abefcd9fba74599fa1c95c89f4ff0 once this image has been published in accordance with Red Hat Certification policy. You may then add or remove any supplemental tags through your Red Hat Connect portal as you see fit." { "image": "quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm:on-pr-aa33e42b1cf41070296feb29de7afb6b8ace7d32", "passed": false, "test_library": { "name": "github.com/redhat-openshift-ecosystem/openshift-preflight", "version": "1.20.0", "commit": "96798270d2f3299dcce4c385d908b5cd53b7537a" }, "results": { "passed": [ { "name": "HasUniqueTag", "elapsed_time": 0, "description": "Checking if container has a tag other than 'latest', so that the image can be uniquely identified." }, { "name": "LayerCountAcceptable", "elapsed_time": 0, "description": "Checking if container has less than 40 layers. Too many layers within the container images can degrade container performance." }, { "name": "HasNoProhibitedPackages", "elapsed_time": 79, "description": "Checks to ensure that the image in use does not include prohibited packages, such as Red Hat Enterprise Linux (RHEL) kernel packages." }, { "name": "HasRequiredLabel", "elapsed_time": 0, "description": "Checking if the required labels (name, vendor, version, release, summary, description, maintainer) are present in the container metadata" }, { "name": "RunAsNonRoot", "elapsed_time": 0, "description": "Checking if container runs as the root user because a container that does not specify a non-root user will fail the automatic certification, and will be subject to a manual review before the container can be approved for publication" }, { "name": "HasModifiedFiles", "elapsed_time": 13086, "description": "Checks that no files installed via RPM in the base Red Hat layer have been modified" }, { "name": "BasedOnUbi", "elapsed_time": 757, "description": "Checking if the container's base image is based upon the Red Hat Universal Base Image (UBI) or Red Hat Hardened Images (RHHI)" } ], "failed": [ { "name": "HasLicense", "elapsed_time": 0, time="2026-08-18T04:55:29Z" level=info msg="Preflight result: FAILED" "description": "Checking if terms and conditions applicable to the software including open source licensing information are present. The license must be at /licenses", "help": "Check HasLicense encountered an error. Please review the preflight.log file for more information.", "suggestion": "Create a directory named /licenses and include all relevant licensing and/or terms and conditions as text file(s) in that directory.", "knowledgebase_url": "https://access.redhat.com/documentation/en-us/red_hat_software_certification/2026/html-single/red_hat_openshift_software_certification_policy_guide/index#assembly-requirements-for-container-images_openshift-sw-cert-policy-introduction", "check_url": "https://access.redhat.com/documentation/en-us/red_hat_software_certification/2026/html-single/red_hat_openshift_software_certification_policy_guide/index#assembly-requirements-for-container-images_openshift-sw-cert-policy-introduction" } ], "errors": [] } } pod: component-prefetch-npm-on-p0c35f9aba40fdd2f8c362a11b72725e9-pod | container step-app-set-outcome: [retry] executing: skopeo inspect --raw --retry-times 3 docker://quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm:on-pr-aa33e42b1cf41070296feb29de7afb6b8ace7d32 {"result":"FAILURE","timestamp":"1787028930","note":"Task preflight is a FAILURE: Refer to Tekton task logs for more information","successes":7,"failures":1,"warnings":0} pod: component-prefetch-npm-on-p0c35f9aba40fdd2f8c362a11b72725e9-pod | container step-final-outcome: + [[ ! -f /mount/konflux.results.json ]] + tee /tekton/steps/step-final-outcome/results/test-output {"result":"FAILURE","timestamp":"1787028930","note":"Task preflight is a FAILURE: Refer to Tekton task logs for more information","successes":7,"failures":1,"warnings":0} pod: component-prefetch-npm-on-p148f62668be4146811c6cfbb8df5d512-pod | init container: prepare 2026/08/18 04:54:19 Entrypoint initialization pod: component-prefetch-npm-on-p148f62668be4146811c6cfbb8df5d512-pod | init container: place-scripts 2026/08/18 04:54:27 Decoded script /tekton/scripts/script-0-2lxpt 2026/08/18 04:54:27 Decoded script /tekton/scripts/script-1-mnwvf pod: component-prefetch-npm-on-p148f62668be4146811c6cfbb8df5d512-pod | init container: working-dir-initializer pod: component-prefetch-npm-on-p148f62668be4146811c6cfbb8df5d512-pod | container step-sast-unicode-check: + . /utils.sh ++ OPM_RENDER_CACHE=/tmp/konflux-test-opm-cache ++ DEFAULT_INDEX_IMAGE=registry.redhat.io/redhat/redhat-operator-index + trap 'handle_error /tekton/results/TEST_OUTPUT' EXIT + [[ -z '' ]] + PROJECT_NAME=component-prefetch-npm + echo 'INFO: The PROJECT_NAME used is: component-prefetch-npm' + ca_bundle=/mnt/trusted-ca/ca-bundle.crt + '[' -f /mnt/trusted-ca/ca-bundle.crt ']' + echo 'INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt' + cp -vf /mnt/trusted-ca/ca-bundle.crt /etc/pki/ca-trust/source/anchors INFO: The PROJECT_NAME used is: component-prefetch-npm INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt '/mnt/trusted-ca/ca-bundle.crt' -> '/etc/pki/ca-trust/source/anchors/ca-bundle.crt' + update-ca-trust + SCAN_PROP=https://github.com/siddhesh/find-unicode-control.git#c2accbfbba7553a8bc1ebd97089ae08ad8347e58 + FUC_EXIT_CODE=0 + declare -a ALL_TARGETS + OLD_IFS=' ' + IFS=, + for d in $TARGET_DIRS + ALL_TARGETS+=("${SOURCE_CODE_DIR}/source/${d}") + IFS=' ' + LANG=en_US.utf8 + find_unicode_control.py -p bidi -v -d -t /workspace/workspace/source/. + [[ 0 -ne 0 ]] + sed -i raw_sast_unicode_check_out.txt -E -e 's|(.*:[0-9]+)(.*)|\1: warning:\2|' -e 's|^|Error: UNICONTROL_WARNING:\n|' + CSGERP_OPTS=(--mode=json --remove-duplicates --embed-context=3 --set-scan-prop="${SCAN_PROP}" --strip-path-prefix="${SOURCE_CODE_DIR}"/source/) + csgrep --mode=json --remove-duplicates --embed-context=3 --set-scan-prop=https://github.com/siddhesh/find-unicode-control.git#c2accbfbba7553a8bc1ebd97089ae08ad8347e58 --strip-path-prefix=/workspace/workspace/source/ raw_sast_unicode_check_out.txt + csgrep --mode=evtstat processed_sast_unicode_check_out.json + [[ SITE_DEFAULT == \S\I\T\E\_\D\E\F\A\U\L\T ]] + KFP_GIT_URL=https://gitlab.cee.redhat.com/osh/known-false-positives.git + PROBE_URL=https://gitlab.cee.redhat.com/osh/known-false-positives + KFP_DIR=known-false-positives + KFP_CLONED=0 + mkdir known-false-positives + [[ -n https://gitlab.cee.redhat.com/osh/known-false-positives.git ]] + echo -n 'INFO: Probing https://gitlab.cee.redhat.com/osh/known-false-positives... ' + curl --fail --head --max-time 60 --no-progress-meter https://gitlab.cee.redhat.com/osh/known-false-positives ++ head -1 curl: (6) Could not resolve host: gitlab.cee.redhat.com + [[ 0 -eq 0 ]] + echo 'WARN: Failed to clone known-false-positives at https://gitlab.cee.redhat.com/osh/known-false-positives.git, scan results will not be filtered' + mv processed_sast_unicode_check_out.json sast_unicode_check_out.json INFO: Probing https://gitlab.cee.redhat.com/osh/known-false-positives... WARN: Failed to clone known-false-positives at https://gitlab.cee.redhat.com/osh/known-false-positives.git, scan results will not be filtered + csgrep --mode=sarif sast_unicode_check_out.json + [[ 0 -eq 0 ]] + note='Task sast-unicode-check success: No finding was detected' ++ make_result_json -r SUCCESS -t 'Task sast-unicode-check success: No finding was detected' ++ local RESULT= ++ local SUCCESSES=0 ++ local FAILURES=0 ++ local WARNINGS=0 ++ local 'NOTE=For details, check Tekton task log.' ++ local NAMESPACE=default ++ local OUTPUT ++ local OPTIND opt ++ getopts :r:s:f:w:t:n: opt ++ case "${opt}" in ++ RESULT=SUCCESS ++ getopts :r:s:f:w:t:n: opt ++ case "${opt}" in ++ NOTE='Task sast-unicode-check success: No finding was detected' ++ getopts :r:s:f:w:t:n: opt ++ shift 4 ++ '[' -z SUCCESS ']' ++ case "${RESULT}" in ++++ date -u --iso-8601=seconds +++ jq -rce --arg date 2026-08-18T04:55:01+00:00 --arg result SUCCESS --arg note 'Task sast-unicode-check success: No finding was detected' --arg namespace default --arg successes 0 --arg failures 0 --arg warnings 0 --null-input '{ result: $result, timestamp: $date, note: $note, namespace: $namespace, successes: $successes|tonumber, failures: $failures|tonumber, warnings: $warnings|tonumber }' ++ OUTPUT='{"result":"SUCCESS","timestamp":"2026-08-18T04:55:01+00:00","note":"Task sast-unicode-check success: No finding was detected","namespace":"default","successes":0,"failures":0,"warnings":0}' ++ echo '{"result":"SUCCESS","timestamp":"2026-08-18T04:55:01+00:00","note":"Task sast-unicode-check success: No finding was detected","namespace":"default","successes":0,"failures":0,"warnings":0}' + ERROR_OUTPUT='{"result":"SUCCESS","timestamp":"2026-08-18T04:55:01+00:00","note":"Task sast-unicode-check success: No finding was detected","namespace":"default","successes":0,"failures":0,"warnings":0}' + echo '{"result":"SUCCESS","timestamp":"2026-08-18T04:55:01+00:00","note":"Task sast-unicode-check success: No finding was detected","namespace":"default","successes":0,"failures":0,"warnings":0}' + tee /tekton/results/TEST_OUTPUT {"result":"SUCCESS","timestamp":"2026-08-18T04:55:01+00:00","note":"Task sast-unicode-check success: No finding was detected","namespace":"default","successes":0,"failures":0,"warnings":0} + handle_error /tekton/results/TEST_OUTPUT + exit_code=0 + '[' 0 -ne 0 ']' + exit 0 pod: component-prefetch-npm-on-p148f62668be4146811c6cfbb8df5d512-pod | container step-upload: Selecting auth Using token for quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm Attaching to quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm:on-pr-aa33e42b1cf41070296feb29de7afb6b8ace7d32 Executing: oras attach --no-tty --registry-config /home/oras/auth.json --artifact-type application/sarif+json quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm:on-pr-aa33e42b1cf41070296feb29de7afb6b8ace7d32@sha256:03cc0170eef936909ad71cff9139bc47ef4abefcd9fba74599fa1c95c89f4ff0 sast_unicode_check_out.sarif:application/sarif+json Preparing sast_unicode_check_out.sarif Exists 44136fa355b3 application/vnd.oci.empty.v1+json Exists e8cd1c5aaef5 sast_unicode_check_out.sarif Uploading 4da88ca8bc3d application/vnd.oci.image.manifest.v1+json Uploaded 4da88ca8bc3d application/vnd.oci.image.manifest.v1+json Attached to [registry] quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm:on-pr-aa33e42b1cf41070296feb29de7afb6b8ace7d32@sha256:03cc0170eef936909ad71cff9139bc47ef4abefcd9fba74599fa1c95c89f4ff0 Digest: sha256:4da88ca8bc3d9f253548e148344ba186b636c915c378c32ba6f8f48db881c389 No excluded-findings.json exists. Skipping upload. pod: component-prefetch-npm-on-p2ee1c20564fed2428209c09697216707-pod | init container: prepare 2026/08/18 04:54:30 Entrypoint initialization pod: component-prefetch-npm-on-p2ee1c20564fed2428209c09697216707-pod | init container: place-scripts 2026/08/18 04:54:34 Decoded script /tekton/scripts/script-0-4q8hm 2026/08/18 04:54:34 Decoded script /tekton/scripts/script-1-w5wl2 pod: component-prefetch-npm-on-p2ee1c20564fed2428209c09697216707-pod | init container: working-dir-initializer pod: component-prefetch-npm-on-p2ee1c20564fed2428209c09697216707-pod | container step-sast-snyk-check: INFO: The PROJECT_NAME used is: component-prefetch-npm INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt '/mnt/trusted-ca/ca-bundle.crt' -> '/etc/pki/ca-trust/source/anchors/ca-bundle.crt' {"result":"SKIPPED","timestamp":"2026-08-18T04:55:02+00:00","note":"Task sast-snyk-check skipped: If you wish to use the Snyk code SAST task, please create a secret name snyk-secret with the key 'snyk_token' containing the Snyk token by following the steps given [here](https://konflux-ci.dev/docs/testing/build/snyk/)","namespace":"default","successes":0,"failures":0,"warnings":0} pod: component-prefetch-npm-on-p2ee1c20564fed2428209c09697216707-pod | container step-upload: No sast_snyk_check_out.sarif exists. Skipping upload. No excluded-findings.json exists. Skipping upload. pod: component-prefetch-npm-on-p3cc86a503b108fdeedb6a06d4e33b0e1-pod | init container: prepare 2026/08/18 04:54:42 Entrypoint initialization pod: component-prefetch-npm-on-p3cc86a503b108fdeedb6a06d4e33b0e1-pod | init container: place-scripts 2026/08/18 04:54:46 Decoded script /tekton/scripts/script-0-2vncf 2026/08/18 04:54:46 Decoded script /tekton/scripts/script-1-2r9wl pod: component-prefetch-npm-on-p3cc86a503b108fdeedb6a06d4e33b0e1-pod | init container: working-dir-initializer pod: component-prefetch-npm-on-p3cc86a503b108fdeedb6a06d4e33b0e1-pod | container step-sast-shell-check: + source /utils.sh ++ OPM_RENDER_CACHE=/tmp/konflux-test-opm-cache ++ DEFAULT_INDEX_IMAGE=registry.redhat.io/redhat/redhat-operator-index + trap 'handle_error /tekton/results/TEST_OUTPUT' EXIT + [[ -z '' ]] + PROJECT_NAME=component-prefetch-npm + echo 'INFO: The PROJECT_NAME used is: component-prefetch-npm' + ca_bundle=/mnt/trusted-ca/ca-bundle.crt + '[' -f /mnt/trusted-ca/ca-bundle.crt ']' INFO: The PROJECT_NAME used is: component-prefetch-npm INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt + echo 'INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt' + cp -vf /mnt/trusted-ca/ca-bundle.crt /etc/pki/ca-trust/source/anchors + update-ca-trust '/mnt/trusted-ca/ca-bundle.crt' -> '/etc/pki/ca-trust/source/anchors/ca-bundle.crt' ++ rpm -q --queryformat '%{NAME}-%{VERSION}-%{RELEASE}\n' ShellCheck + PACKAGE_VERSION=ShellCheck-0.10.0-3.el9 + OUTPUT_FILE=shellcheck-results.json + SOURCE_CODE_DIR=/workspace/workspace/source + declare -a ALL_TARGETS + IFS=, + read -ra TARGET_ARRAY + for d in "${TARGET_ARRAY[@]}" + potential_path=/workspace/workspace/source/. ++ realpath -m /workspace/workspace/source/. + resolved_path=/workspace/workspace/source + [[ /workspace/workspace/source == \/\w\o\r\k\s\p\a\c\e\/\w\o\r\k\s\p\a\c\e\/\s\o\u\r\c\e* ]] + ALL_TARGETS+=("$resolved_path") + '[' -z '' ']' + '[' -r /sys/fs/cgroup/cpu.max ']' + read -r quota period + '[' 800000 '!=' max ']' + '[' -n 100000 ']' + '[' 100000 -gt 0 ']' + export SC_JOBS=8 + SC_JOBS=8 INFO: Setting SC_JOBS=8 based on cgroups v2 max for run-shellcheck.sh + echo 'INFO: Setting SC_JOBS=8 based on cgroups v2 max for run-shellcheck.sh' + [[ true == \t\r\u\e ]] + export SC_SKIP_JINJA=1 + SC_SKIP_JINJA=1 + /usr/share/csmock/scripts/run-shellcheck.sh /workspace/workspace/source Looking for shell scripts................ done + timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/applypatch-msg.sample + timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/commit-msg.sample + timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/post-update.sample + timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/prepare-commit-msg.sample + timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/pre-applypatch.sample + timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/pre-commit.sample + timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/pre-merge-commit.sample + timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/pre-push.sample + timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/pre-rebase.sample + timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/pre-receive.sample + timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/push-to-checkout.sample + timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/sendemail-validate.sample + timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/update.sample + CSGREP_OPTS=(--mode=json --strip-path-prefix="$SOURCE_CODE_DIR"/ --remove-duplicates --embed-context=3 --set-scan-prop="ShellCheck:${PACKAGE_VERSION}") + [[ true == \t\r\u\e ]] + CSGREP_EVENT_FILTER='\[SC(1020|1035|1054|1066|1068|1073|1080|1083|1099|1113|1115|1127|1128|1143|2043|2050|' + CSGREP_EVENT_FILTER+='2055|2057|2066|2069|2071|2077|2078|2091|2092|2157|2171|2193|2194|2195|2215|2216|' + CSGREP_EVENT_FILTER+='2218|2224|2225|2242|2256|2258|2261)\]$' + CSGREP_OPTS+=(--event="$CSGREP_EVENT_FILTER") + csgrep --mode=json --strip-path-prefix=/workspace/workspace/source/ --remove-duplicates --embed-context=3 --set-scan-prop=ShellCheck:ShellCheck-0.10.0-3.el9 '--event=\[SC(1020|1035|1054|1066|1068|1073|1080|1083|1099|1113|1115|1127|1128|1143|2043|2050|2055|2057|2066|2069|2071|2077|2078|2091|2092|2157|2171|2193|2194|2195|2215|2216|2218|2224|2225|2242|2256|2258|2261)\]$' ./shellcheck-results/empty.json ./shellcheck-results/sc-104.json ./shellcheck-results/sc-107.json ./shellcheck-results/sc-108.json ./shellcheck-results/sc-110.json ./shellcheck-results/sc-116.json ./shellcheck-results/sc-119.json ./shellcheck-results/sc-137.json ./shellcheck-results/sc-149.json ./shellcheck-results/sc-151.json ./shellcheck-results/sc-153.json + [[ SITE_DEFAULT == \S\I\T\E\_\D\E\F\A\U\L\T ]] + KFP_GIT_URL=https://gitlab.cee.redhat.com/osh/known-false-positives.git + PROBE_URL=https://gitlab.cee.redhat.com/osh/known-false-positives + KFP_DIR=known-false-positives + KFP_CLONED=0 + mkdir known-false-positives + [[ -n https://gitlab.cee.redhat.com/osh/known-false-positives.git ]] + echo -n 'INFO: Probing https://gitlab.cee.redhat.com/osh/known-false-positives... ' + curl --fail --head --max-time 60 --no-progress-meter https://gitlab.cee.redhat.com/osh/known-false-positives ++ head -1 curl: (6) Could not resolve host: gitlab.cee.redhat.com INFO: Probing https://gitlab.cee.redhat.com/osh/known-false-positives... WARN: Failed to clone known-false-positives at https://gitlab.cee.redhat.com/osh/known-false-positives.git, scan results will not be filtered ShellCheck results have been saved to shellcheck-results.json + [[ 0 -eq 0 ]] + echo 'WARN: Failed to clone known-false-positives at https://gitlab.cee.redhat.com/osh/known-false-positives.git, scan results will not be filtered' + echo 'ShellCheck results have been saved to shellcheck-results.json' + csgrep --mode=evtstat shellcheck-results.json + csgrep --mode=sarif shellcheck-results.json + TEST_OUTPUT= + parse_test_output sast-shell-check sarif shellcheck-results.sarif + TEST_NAME=sast-shell-check + TEST_RESULT_FORMAT=sarif + TEST_RESULT_FILE=shellcheck-results.sarif + '[' -z sast-shell-check ']' + '[' -z sarif ']' + '[' -z shellcheck-results.sarif ']' + '[' '!' -f shellcheck-results.sarif ']' + '[' sarif = sarif ']' +++ jq -rce '(if (.runs[].results | length > 0) then "FAILURE" else "SUCCESS" end)' shellcheck-results.sarif +++ jq -rce '(.runs[].results | length)' shellcheck-results.sarif ++ make_result_json -r SUCCESS -f 0 ++ local RESULT= ++ local SUCCESSES=0 ++ local FAILURES=0 ++ local WARNINGS=0 ++ local 'NOTE=For details, check Tekton task log.' ++ local NAMESPACE=default ++ local OUTPUT ++ local OPTIND opt ++ getopts :r:s:f:w:t:n: opt ++ case "${opt}" in ++ RESULT=SUCCESS ++ getopts :r:s:f:w:t:n: opt ++ case "${opt}" in ++ FAILURES=0 ++ getopts :r:s:f:w:t:n: opt ++ shift 4 ++ '[' -z SUCCESS ']' ++ case "${RESULT}" in ++++ date -u --iso-8601=seconds +++ jq -rce --arg date 2026-08-18T04:55:14+00:00 --arg result SUCCESS --arg note 'For details, check Tekton task log.' --arg namespace default --arg successes 0 --arg failures 0 --arg warnings 0 --null-input '{ result: $result, timestamp: $date, note: $note, namespace: $namespace, successes: $successes|tonumber, failures: $failures|tonumber, warnings: $warnings|tonumber }' ++ OUTPUT='{"result":"SUCCESS","timestamp":"2026-08-18T04:55:14+00:00","note":"For details, check Tekton task log.","namespace":"default","successes":0,"failures":0,"warnings":0}' ++ echo '{"result":"SUCCESS","timestamp":"2026-08-18T04:55:14+00:00","note":"For details, check Tekton task log.","namespace":"default","successes":0,"failures":0,"warnings":0}' + TEST_OUTPUT='{"result":"SUCCESS","timestamp":"2026-08-18T04:55:14+00:00","note":"For details, check Tekton task log.","namespace":"default","successes":0,"failures":0,"warnings":0}' ++ echo '{"result":"SUCCESS","timestamp":"2026-08-18T04:55:14+00:00","note":"For details, check Tekton task log.","namespace":"default","successes":0,"failures":0,"warnings":0}' ++ jq .failures + '[' 0 -gt 0 ']' + echo '{"result":"SUCCESS","timestamp":"2026-08-18T04:55:14+00:00","note":"For details, check Tekton task log.","namespace":"default","successes":0,"failures":0,"warnings":0}' + tee /tekton/results/TEST_OUTPUT {"result":"SUCCESS","timestamp":"2026-08-18T04:55:14+00:00","note":"For details, check Tekton task log.","namespace":"default","successes":0,"failures":0,"warnings":0} + handle_error /tekton/results/TEST_OUTPUT + exit_code=0 + '[' 0 -ne 0 ']' + exit 0 pod: component-prefetch-npm-on-p3cc86a503b108fdeedb6a06d4e33b0e1-pod | container step-upload: Selecting auth Using token for quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm Attaching to quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm:on-pr-34e345fecb59f591b64031e3872fd1daeb854cd3 Executing: oras attach --no-tty --registry-config /home/oras/auth.json --artifact-type application/sarif+json quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm:on-pr-34e345fecb59f591b64031e3872fd1daeb854cd3@sha256:8c8a120a14e06a5f898161864b52f5982c70e4eaa7a7e330654e287fe3924128 shellcheck-results.sarif:application/sarif+json Preparing shellcheck-results.sarif Exists 44136fa355b3 application/vnd.oci.empty.v1+json Exists 74c89a6df4ae shellcheck-results.sarif Uploading 2b0a94389c05 application/vnd.oci.image.manifest.v1+json Uploaded 2b0a94389c05 application/vnd.oci.image.manifest.v1+json Attached to [registry] quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm:on-pr-34e345fecb59f591b64031e3872fd1daeb854cd3@sha256:8c8a120a14e06a5f898161864b52f5982c70e4eaa7a7e330654e287fe3924128 Digest: sha256:2b0a94389c05c2169e3f21b4e4e46d4b4b38aedf4b6b5798f1342abee4136293 No excluded-findings.json exists. Skipping upload. pod: component-prefetch-npm-on-p3cedf95c1622ba9685ca4ec1b08217f9-pod | init container: prepare 2026/08/18 04:53:39 Entrypoint initialization pod: component-prefetch-npm-on-p3cedf95c1622ba9685ca4ec1b08217f9-pod | init container: place-scripts 2026/08/18 04:53:42 Decoded script /tekton/scripts/script-0-9lrk5 2026/08/18 04:53:42 Decoded script /tekton/scripts/script-1-jgwj6 2026/08/18 04:53:42 Decoded script /tekton/scripts/script-2-ghw47 pod: component-prefetch-npm-on-p3cedf95c1622ba9685ca4ec1b08217f9-pod | container step-build: [2026-08-18T04:53:49,919517752+00:00] Update CA trust INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt '/mnt/trusted-ca/ca-bundle.crt' -> '/etc/pki/ca-trust/source/anchors/ca-bundle.crt' Running konflux-build-cli time="2026-08-18T04:53:54Z" level=info msg="[param] image: quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm:on-pr-aa33e42b1cf41070296feb29de7afb6b8ace7d32" time="2026-08-18T04:53:54Z" level=info msg="[param] images: [quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm:on-pr-aa33e42b1cf41070296feb29de7afb6b8ace7d32@sha256:03cc0170eef936909ad71cff9139bc47ef4abefcd9fba74599fa1c95c89f4ff0]" time="2026-08-18T04:53:54Z" level=info msg="[param] buildah-format: docker" time="2026-08-18T04:53:54Z" level=info msg="[param] always-build-index: false" time="2026-08-18T04:53:54Z" level=info msg="[param] additional-tags: [component-prefetch-npm-on-pull-request-krv7z-build-image-index]" time="2026-08-18T04:53:54Z" level=info msg="[param] output-manifest-path: /index-build-data/manifest_data.json" time="2026-08-18T04:53:54Z" level=info msg="[param] result-path-image-digest: /tekton/results/IMAGE_DIGEST" time="2026-08-18T04:53:54Z" level=info msg="[param] result-path-image-url: /tekton/results/IMAGE_URL" time="2026-08-18T04:53:54Z" level=info msg="[param] result-path-image-ref: /tekton/results/IMAGE_REF" time="2026-08-18T04:53:54Z" level=info msg="[param] result-path-images: /tekton/results/IMAGES" time="2026-08-18T04:53:54Z" level=info msg="Creating manifest list: quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm:on-pr-aa33e42b1cf41070296feb29de7afb6b8ace7d32" time="2026-08-18T04:53:55Z" level=info msg="buildah [stdout] c53c15a2f9787a121a20a654bbb6ea0b4fa41235888de95ffc76e26ae994d310" time="2026-08-18T04:53:55Z" level=info msg="Skipping image index generation. Returning results for single image." {"image_digest":"sha256:03cc0170eef936909ad71cff9139bc47ef4abefcd9fba74599fa1c95c89f4ff0","image_url":"quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm:on-pr-aa33e42b1cf41070296feb29de7afb6b8ace7d32","image_ref":"quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm@sha256:03cc0170eef936909ad71cff9139bc47ef4abefcd9fba74599fa1c95c89f4ff0","images":"quay.io/redhat-appstudio-qe/build-e2e-prefetch-npm/component-prefetch-npm@sha256:03cc0170eef936909ad71cff9139bc47ef4abefcd9fba74599fa1c95c89f4ff0"} pod: component-prefetch-npm-on-p3cedf95c1622ba9685ca4ec1b08217f9-pod | container step-create-sbom: The manifest_data.json file does not exist. Skipping the SBOM creation... pod: component-prefetch-npm-on-p3cedf95c1622ba9685ca4ec1b08217f9-pod | container step-upload-sbom: [2026-08-18T04:53:56,725582891+00:00] Update CA trust INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt '/mnt/trusted-ca/ca-bundle.crt' -> '/etc/pki/ca-trust/source/anchors/ca-bundle.crt' The index.spdx.json file does not exists. Skipping the SBOM upload... pod: component-prefetch-npm-on-p4f9327e4584f71c7608874fffb497e7e-pod | init container: prepare