Success: false Result: FAILURE Violations: 19, Warnings: 7, Successes: 126 Component: dc-metro-map ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Results: ✕ [Violation] cve.cve_results_found ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: CVE scan results were not found Title: CVE scan results found Description: Confirm that CVE scan task results (Clair, TPA, or roxctl) are present in the SLSA Provenance attestation of the build pipeline. To exclude this rule add "cve.cve_results_found" to the `exclude` section of the policy configuration. Solution: Make sure there is a successful task in the build pipeline that runs a CVE scan (Clair, TPA, or roxctl). ✕ [Violation] labels.required_labels ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: The required "org.opencontainers.image.revision" label is missing. Label description: Source control revision identifier for the packaged software. Term: org.opencontainers.image.revision Title: Required labels Description: Check the image for the presence of labels that are required. Use the rule data `required_labels` key to set the list of labels to check, or the `fbc_required_labels` key for fbc images. To exclude this rule add "labels.required_labels:org.opencontainers.image.revision" to the `exclude` section of the policy configuration. Solution: Update the image build process to set the required labels. ✕ [Violation] labels.required_labels ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: The required "org.opencontainers.image.source" label is missing. Label description: URL to get source code for building the image Term: org.opencontainers.image.source Title: Required labels Description: Check the image for the presence of labels that are required. Use the rule data `required_labels` key to set the list of labels to check, or the `fbc_required_labels` key for fbc images. To exclude this rule add "labels.required_labels:org.opencontainers.image.source" to the `exclude` section of the policy configuration. Solution: Update the image build process to set the required labels. ✕ [Violation] slsa_build_scripted_build.image_built_by_trusted_task ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: Image "quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6" not built by a trusted task: Build Task(s) "buildah" are not trusted Title: Image built by trusted Task Description: Verify the digest of the image being validated is reported by a trusted Task in its IMAGE_DIGEST result. To exclude this rule add "slsa_build_scripted_build.image_built_by_trusted_task" to the `exclude` section of the policy configuration. Solution: Make sure the build Pipeline definition uses a trusted Task to build images. ✕ [Violation] tasks.required_tasks_found ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: One of "clamav-scan", "clamav-scan-min" tasks is missing Terms: clamav-scan, clamav-scan-min Title: All required tasks were included in the pipeline Description: Ensure that the set of required tasks are included in the PipelineRun attestation. To exclude this rule add one or more of "tasks.required_tasks_found:clamav-scan", "tasks.required_tasks_found:clamav-scan-min" to the `exclude` section of the policy configuration. Solution: Make sure all required tasks are in the build pipeline. The required task list is contained as https://conforma.dev/docs/cli/configuration.html#_data_sources under the key 'required-tasks'. ✕ [Violation] tasks.required_tasks_found ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: Required task "deprecated-image-check" is missing Term: deprecated-image-check Title: All required tasks were included in the pipeline Description: Ensure that the set of required tasks are included in the PipelineRun attestation. To exclude this rule add "tasks.required_tasks_found:deprecated-image-check" to the `exclude` section of the policy configuration. Solution: Make sure all required tasks are in the build pipeline. The required task list is contained as https://conforma.dev/docs/cli/configuration.html#_data_sources under the key 'required-tasks'. ✕ [Violation] tasks.required_tasks_found ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: One of "prefetch-dependencies", "prefetch-dependencies-oci-ta", "prefetch-dependencies-oci-ta-min" tasks is missing Terms: prefetch-dependencies, prefetch-dependencies-oci-ta, prefetch-dependencies-oci-ta-min Title: All required tasks were included in the pipeline Description: Ensure that the set of required tasks are included in the PipelineRun attestation. To exclude this rule add one or more of "tasks.required_tasks_found:prefetch-dependencies", "tasks.required_tasks_found:prefetch-dependencies-oci-ta", "tasks.required_tasks_found:prefetch-dependencies-oci-ta-min" to the `exclude` section of the policy configuration. Solution: Make sure all required tasks are in the build pipeline. The required task list is contained as https://conforma.dev/docs/cli/configuration.html#_data_sources under the key 'required-tasks'. ✕ [Violation] tasks.required_tasks_found ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: Required task "rpms-signature-scan" is missing Term: rpms-signature-scan Title: All required tasks were included in the pipeline Description: Ensure that the set of required tasks are included in the PipelineRun attestation. To exclude this rule add "tasks.required_tasks_found:rpms-signature-scan" to the `exclude` section of the policy configuration. Solution: Make sure all required tasks are in the build pipeline. The required task list is contained as https://conforma.dev/docs/cli/configuration.html#_data_sources under the key 'required-tasks'. ✕ [Violation] tasks.required_tasks_found ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: One of "sast-shell-check", "sast-shell-check-oci-ta", "sast-shell-check-oci-ta-min" tasks is missing Terms: sast-shell-check, sast-shell-check-oci-ta, sast-shell-check-oci-ta-min Title: All required tasks were included in the pipeline Description: Ensure that the set of required tasks are included in the PipelineRun attestation. To exclude this rule add one or more of "tasks.required_tasks_found:sast-shell-check", "tasks.required_tasks_found:sast-shell-check-oci-ta", "tasks.required_tasks_found:sast-shell-check-oci-ta-min" to the `exclude` section of the policy configuration. Solution: Make sure all required tasks are in the build pipeline. The required task list is contained as https://conforma.dev/docs/cli/configuration.html#_data_sources under the key 'required-tasks'. ✕ [Violation] tasks.required_tasks_found ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: One of "sast-unicode-check", "sast-unicode-check-oci-ta", "sast-unicode-check-oci-ta-min" tasks is missing Terms: sast-unicode-check, sast-unicode-check-oci-ta, sast-unicode-check-oci-ta-min Title: All required tasks were included in the pipeline Description: Ensure that the set of required tasks are included in the PipelineRun attestation. To exclude this rule add one or more of "tasks.required_tasks_found:sast-unicode-check", "tasks.required_tasks_found:sast-unicode-check-oci-ta", "tasks.required_tasks_found:sast-unicode-check-oci-ta-min" to the `exclude` section of the policy configuration. Solution: Make sure all required tasks are in the build pipeline. The required task list is contained as https://conforma.dev/docs/cli/configuration.html#_data_sources under the key 'required-tasks'. ✕ [Violation] tasks.required_tasks_found ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: Required task "tpa-scan" is missing Term: tpa-scan Title: All required tasks were included in the pipeline Description: Ensure that the set of required tasks are included in the PipelineRun attestation. To exclude this rule add "tasks.required_tasks_found:tpa-scan" to the `exclude` section of the policy configuration. Solution: Make sure all required tasks are in the build pipeline. The required task list is contained as https://conforma.dev/docs/cli/configuration.html#_data_sources under the key 'required-tasks'. ✕ [Violation] tasks.required_untrusted_task_found ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: Required task "buildah" is required and present but not from a trusted task Term: buildah Title: All required tasks are from trusted tasks Description: Ensure that the all required tasks are resolved from trusted tasks. To exclude this rule add "tasks.required_untrusted_task_found:buildah" to the `exclude` section of the policy configuration. Solution: Make sure all required tasks in the build pipeline are resolved from trusted tasks. ✕ [Violation] tasks.required_untrusted_task_found ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: Required task "init" is required and present but not from a trusted task Term: init Title: All required tasks are from trusted tasks Description: Ensure that the all required tasks are resolved from trusted tasks. To exclude this rule add "tasks.required_untrusted_task_found:init" to the `exclude` section of the policy configuration. Solution: Make sure all required tasks in the build pipeline are resolved from trusted tasks. ✕ [Violation] test.test_data_found ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: No test data found Title: Test data found in task results Description: Ensure that at least one of the tasks in the pipeline includes a TEST_OUTPUT task result, which is where Conforma expects to find test result data. To exclude this rule add "test.test_data_found" to the `exclude` section of the policy configuration. Solution: Confirm at least one task in the build pipeline contains a result named TEST_OUTPUT. ✕ [Violation] trusted_task.trusted ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: PipelineTask "apply-tags" uses an untrusted task reference: oci://quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.1@sha256:516875845f2988848ebde5f3e9c717d6077af7bf9b3cb2b34a3c3f86b2609a14. The denial reason is: deny_rule - oci://quay.io/konflux-ci/tekton-catalog/task-apply-tags Term: apply-tags Title: Tasks are trusted Description: Check the trust of the Tekton Tasks used in the build Pipeline. There are two modes in which trust is verified. The first mode is used if Trusted Artifacts are enabled. In this case, a chain of trust is established for all the Tasks involved in creating an artifact. If the chain contains an untrusted Task, then a violation is emitted. The second mode is used as a fallback when Trusted Artifacts are not enabled. In this case, **all** Tasks in the build Pipeline must be trusted. To exclude this rule add "trusted_task.trusted:apply-tags" to the `exclude` section of the policy configuration. Solution: If using Trusted Artifacts, be sure every Task in the build Pipeline responsible for producing a Trusted Artifact is trusted. Otherwise, ensure **all** Tasks in the build Pipeline are trusted. Note that trust is eventually revoked from Tasks when newer versions are made available. ✕ [Violation] trusted_task.trusted ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: PipelineTask "build-container" uses an untrusted task reference: oci://quay.io/konflux-ci/tekton-catalog/task-buildah:0.1@sha256:72e4ddd9b543e2766830e3a513da5c2fec26ea7a72a50e8c85be642912caa603. The denial reason is: deny_rule - oci://quay.io/konflux-ci/tekton-catalog/task-buildah Term: buildah Title: Tasks are trusted Description: Check the trust of the Tekton Tasks used in the build Pipeline. There are two modes in which trust is verified. The first mode is used if Trusted Artifacts are enabled. In this case, a chain of trust is established for all the Tasks involved in creating an artifact. If the chain contains an untrusted Task, then a violation is emitted. The second mode is used as a fallback when Trusted Artifacts are not enabled. In this case, **all** Tasks in the build Pipeline must be trusted. To exclude this rule add "trusted_task.trusted:buildah" to the `exclude` section of the policy configuration. Solution: If using Trusted Artifacts, be sure every Task in the build Pipeline responsible for producing a Trusted Artifact is trusted. Otherwise, ensure **all** Tasks in the build Pipeline are trusted. Note that trust is eventually revoked from Tasks when newer versions are made available. ✕ [Violation] trusted_task.trusted ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: PipelineTask "init" uses an untrusted task reference: oci://quay.io/konflux-ci/tekton-catalog/task-init:0.2@sha256:99c98d3e5195e9920482f2187590d6f9150c4b8a2001b1ce5dcd5077abda9481. The denial reason is: deny_rule - oci://quay.io/konflux-ci/tekton-catalog/task-init Term: init Title: Tasks are trusted Description: Check the trust of the Tekton Tasks used in the build Pipeline. There are two modes in which trust is verified. The first mode is used if Trusted Artifacts are enabled. In this case, a chain of trust is established for all the Tasks involved in creating an artifact. If the chain contains an untrusted Task, then a violation is emitted. The second mode is used as a fallback when Trusted Artifacts are not enabled. In this case, **all** Tasks in the build Pipeline must be trusted. To exclude this rule add "trusted_task.trusted:init" to the `exclude` section of the policy configuration. Solution: If using Trusted Artifacts, be sure every Task in the build Pipeline responsible for producing a Trusted Artifact is trusted. Otherwise, ensure **all** Tasks in the build Pipeline are trusted. Note that trust is eventually revoked from Tasks when newer versions are made available. ✕ [Violation] trusted_task.trusted ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: PipelineTask "push-dockerfile" uses an untrusted task reference: oci://quay.io/konflux-ci/tekton-catalog/task-push-dockerfile:0.1@sha256:e2c8fa67da036cef81e407e28c14b6a2034c6564009e084c368005a4640c554c. The denial reason is: deny_rule - oci://quay.io/konflux-ci/tekton-catalog/task-push-dockerfile Term: push-dockerfile Title: Tasks are trusted Description: Check the trust of the Tekton Tasks used in the build Pipeline. There are two modes in which trust is verified. The first mode is used if Trusted Artifacts are enabled. In this case, a chain of trust is established for all the Tasks involved in creating an artifact. If the chain contains an untrusted Task, then a violation is emitted. The second mode is used as a fallback when Trusted Artifacts are not enabled. In this case, **all** Tasks in the build Pipeline must be trusted. To exclude this rule add "trusted_task.trusted:push-dockerfile" to the `exclude` section of the policy configuration. Solution: If using Trusted Artifacts, be sure every Task in the build Pipeline responsible for producing a Trusted Artifact is trusted. Otherwise, ensure **all** Tasks in the build Pipeline are trusted. Note that trust is eventually revoked from Tasks when newer versions are made available. ✕ [Violation] trusted_task.trusted ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: PipelineTask "show-sbom" uses an untrusted task reference: oci://quay.io/konflux-ci/tekton-catalog/task-show-sbom:0.1@sha256:7f8b5499a21de9aca718d0cf2e170949af6b30cacf882d64983471a2c673b1da. The denial reason is: deny_rule - oci://quay.io/konflux-ci/tekton-catalog/task-show-sbom Term: show-sbom Title: Tasks are trusted Description: Check the trust of the Tekton Tasks used in the build Pipeline. There are two modes in which trust is verified. The first mode is used if Trusted Artifacts are enabled. In this case, a chain of trust is established for all the Tasks involved in creating an artifact. If the chain contains an untrusted Task, then a violation is emitted. The second mode is used as a fallback when Trusted Artifacts are not enabled. In this case, **all** Tasks in the build Pipeline must be trusted. To exclude this rule add "trusted_task.trusted:show-sbom" to the `exclude` section of the policy configuration. Solution: If using Trusted Artifacts, be sure every Task in the build Pipeline responsible for producing a Trusted Artifact is trusted. Otherwise, ensure **all** Tasks in the build Pipeline are trusted. Note that trust is eventually revoked from Tasks when newer versions are made available. › [Warning] base_image_registries.allowed_registries_provided ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: allowed_registry_prefixes is configured without signing_identities. Migrate to signature-based verification by setting signing_identities in rule data. Title: Allowed base image registry prefixes list or signing identity was provided Description: Confirm that either the `allowed_registry_prefixes` or a `signing_identities` entry was provided, since at least one is required by the policy rules in this package. Solution: Make sure to configure either a signing identity under the `rh-release` key in the `signing_identities` https://conforma.dev/docs/cli/configuration.html#_data_sources or a list of trusted registry prefixes in `allowed_registry_prefixes`. › [Warning] trusted_task.future_deny_rule ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: Task "apply-tags" will be denied by rule pattern "oci://quay.io/konflux-ci/tekton-catalog/task-apply-tags" starting on 2026-09-05T00:00:00Z. Term: apply-tags Title: Future deny rule will apply Description: Warn when a task matches a deny rule that has an effective_on date in the future. This provides advance notice that a task will become untrusted when the deny rule takes effect. Solution: Update the Task to a version that will not match the future deny rule before its effective date. › [Warning] trusted_task.future_deny_rule ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: Task "build-container" will be denied by rule pattern "oci://quay.io/konflux-ci/tekton-catalog/task-buildah" starting on 2026-09-05T00:00:00Z. Term: buildah Title: Future deny rule will apply Description: Warn when a task matches a deny rule that has an effective_on date in the future. This provides advance notice that a task will become untrusted when the deny rule takes effect. Solution: Update the Task to a version that will not match the future deny rule before its effective date. › [Warning] trusted_task.future_deny_rule ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: Task "clone-repository" will be denied by rule pattern "oci://quay.io/konflux-ci/tekton-catalog/task-git-clone" starting on 2026-09-05T00:00:00Z. Term: git-clone Title: Future deny rule will apply Description: Warn when a task matches a deny rule that has an effective_on date in the future. This provides advance notice that a task will become untrusted when the deny rule takes effect. Solution: Update the Task to a version that will not match the future deny rule before its effective date. › [Warning] trusted_task.future_deny_rule ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: Task "init" will be denied by rule pattern "oci://quay.io/konflux-ci/tekton-catalog/task-init" starting on 2026-09-05T00:00:00Z. Term: init Title: Future deny rule will apply Description: Warn when a task matches a deny rule that has an effective_on date in the future. This provides advance notice that a task will become untrusted when the deny rule takes effect. Solution: Update the Task to a version that will not match the future deny rule before its effective date. › [Warning] trusted_task.future_deny_rule ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: Task "push-dockerfile" will be denied by rule pattern "oci://quay.io/konflux-ci/tekton-catalog/task-push-dockerfile" starting on 2026-09-05T00:00:00Z. Term: push-dockerfile Title: Future deny rule will apply Description: Warn when a task matches a deny rule that has an effective_on date in the future. This provides advance notice that a task will become untrusted when the deny rule takes effect. Solution: Update the Task to a version that will not match the future deny rule before its effective date. › [Warning] trusted_task.future_deny_rule ImageRef: quay.io/hacbs-release-tests/dcmetromap@sha256:544259be8bcd9e6a2066224b805d854d863064c9b64fa3a87bfcd03f5b0f28e6 Reason: Task "show-summary" will be denied by rule pattern "oci://quay.io/konflux-ci/tekton-catalog/task-summary" starting on 2026-09-05T00:00:00Z. Term: summary Title: Future deny rule will apply Description: Warn when a task matches a deny rule that has an effective_on date in the future. This provides advance notice that a task will become untrusted when the deny rule takes effect. Solution: Update the Task to a version that will not match the future deny rule before its effective date. For more information about policy issues, see the policy documentation: https://conforma.dev/docs/policy/