When providing an image for example like this:
- pipe: sonarsource/sonarqube-scan:2.0.1@sha256:f559720fcbb3bc355b9599666525c3ad80d6b6ab25ecd53aabb029aa583139a
We get an error in the pipeline:
Configuration error
It looks like you tried to use a pipe in your bitbucket-pipelines.yml that doesn’t exist. Check the name of the pipe and try again.
(pulling this image locally works without any problems)
But using something like:
- pipe: sonarsource/sonarqube-scan:2.0.1
Does work without any problems. Is there any reason why not to allow to use these digests to improve security?