Skip to content

ACS-6304 Implement SAST Pipeline Scan #1940

ACS-6304 Implement SAST Pipeline Scan

ACS-6304 Implement SAST Pipeline Scan #1940

Triggered via pull request November 30, 2023 13:12
Status Failure
Total duration 1h 7m 25s
Artifacts 7
This run and associated checks have been archived and are scheduled for deletion. Learn more about checks retention

ci.yml

on: pull_request
Source Clear Scan (SCA)
0s
Source Clear Scan (SCA)
Pipeline SAST Scan - ACS
20m 34s
Pipeline SAST Scan - ACS
Pipeline SAST Scan - Share
1h 7m
Pipeline SAST Scan - Share
PMD Scan
58s
PMD Scan
CMIS TAS tests - Open Search (CMIS API)
11m 44s
CMIS TAS tests - Open Search (CMIS API)
All AMPs tests
12m 43s
All AMPs tests
Distribution Zip content tests
7m 13s
Distribution Zip content tests
Single Pipeline image tests
0s
Single Pipeline image tests
Test Tomcat deployment
11m 27s
Test Tomcat deployment
Upload docker images needed for pipeline tests: <acs.version>-<PIPELINE_TAG_TEXT_INSERT>-<build>
0s
Upload docker images needed for pipeline tests: <acs.version>-<PIPELINE_TAG_TEXT_INSERT>-<build>
Matrix: cmis_tas_tests_elasticsearch
Matrix: tas_test_with_mtls
Matrix: tas_tests
Matrix: tas_tests_search_api
Matrix: tas_tests_with_aims
Matrix: upgrade_tas_tests
Fit to window
Zoom out
Zoom in

Annotations

6 errors and 5 warnings
Opensearch Upgrade TAS tests
Process completed with exit code 1.
Elasticsearch Upgrade TAS tests
Process completed with exit code 1.
Pipeline SAST Scan - ACS
[30 Nov 2023 13:20:29,0426] PIPELINE-SCAN INFO: Pipeline Scan Tool Version 23.11.0-0. [30 Nov 2023 13:20:29,0430] PIPELINE-SCAN INFO: Loading policy file Alfresco_Default.json [30 Nov 2023 13:20:29,0440] PIPELINE-SCAN INFO: Successfully retrieved the policy [30 Nov 2023 13:20:29,0440] PIPELINE-SCAN INFO: Policy name: Alfresco Default [30 Nov 2023 13:20:29,0440] PIPELINE-SCAN INFO: CWE filter: [30 Nov 2023 13:20:29,0441] PIPELINE-SCAN INFO: Severity filter: 3, 4, 5, [30 Nov 2023 13:20:29,0442] PIPELINE-SCAN INFO: Beginning scanning of 'distribution/target/alfresco.war'. [30 Nov 2023 13:20:29,0442] PIPELINE-SCAN INFO: Sending 187051326 bytes to the server for analysis. [30 Nov 2023 13:21:26,0181] PIPELINE-SCAN INFO: Upload complete. [30 Nov 2023 13:21:26,0182] PIPELINE-SCAN INFO: Scan ID: de5ea958-f5fd-43ca-a1be-ee357f3400a0 [30 Nov 2023 13:21:36,0982] PIPELINE-SCAN INFO: Analysis Started. =========================== Found 6 Scannable modules. =========================== alfresco.war JS files within alfresco.war JS files within alfresco.war JS files within alfresco.war JS files within alfresco.war JS files within alfresco.war [30 Nov 2023 13:33:43,0345] PIPELINE-SCAN INFO: Analysis Complete. [30 Nov 2023 13:33:43,0347] PIPELINE-SCAN INFO: Analysis Results: Received 83312 bytes in 793905ms. [30 Nov 2023 13:33:43,0354] PIPELINE-SCAN INFO: Writing Raw JSON Results to file '/home/runner/work/acs-packaging/acs-packaging/results.json'. [30 Nov 2023 13:33:43,0357] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0357] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0357] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0358] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0358] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0358] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0358] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0358] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0358] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0358] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0358] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0359] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0359] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0359] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0359] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0359] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0359] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0359] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0360] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0360] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0360] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0360] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0360] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0360] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0360] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 13:33:43,0360] PIPELINE-SCAN INFO: Applying custom severity 4 to cwe 80 [30 Nov 2023 13:33:43,0363] PIPELINE-SCAN INFO: Writing Filtered JSON Results to file '/home/runner/work/acs-packaging/acs-packaging/filtered_results.json'. Scan Summary: PIPELINE_SCAN_VERSION: 23.11.0-0 DEV-STAGE: DEVELOPMENT PROJECT-NAME: acs-packaging-acs SCAN_ID: de5ea958-f5fd-43ca-a1be-ee357f3400a0 SCAN_STATUS: SUCCESS SCAN_MESSAGE: Scan successful. Result
Elasticsearch postgreSQL | TAS tests (Search API)
Process completed with exit code 1.
Elasticsearch Maria DB 10.6 | TAS tests (Search API)
Process completed with exit code 1.
Pipeline SAST Scan - Share
Process completed with exit code 12.
Opensearch Upgrade TAS tests
The following actions uses node12 which is deprecated and will be forced to run on node16: aws-actions/configure-aws-credentials@v1. For more info: https://github.blog/changelog/2023-06-13-github-actions-all-actions-will-run-on-node16-instead-of-node12-by-default/
Opensearch Upgrade TAS tests
The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/
Elasticsearch Upgrade TAS tests
The following actions uses node12 which is deprecated and will be forced to run on node16: aws-actions/configure-aws-credentials@v1. For more info: https://github.blog/changelog/2023-06-13-github-actions-all-actions-will-run-on-node16-instead-of-node12-by-default/
Elasticsearch Upgrade TAS tests
The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/
Pipeline SAST Scan - Share
No files were found with the provided path: readable_output.zip. No artifacts will be uploaded.

Artifacts

Produced during runtime
Name Size
PMD Summary (Human Readable) Expired
249 Bytes
Veracode Pipeline-Scan Results Expired
105 KB
Veracode Pipeline-Scan Results - ACS (Human Readable) Expired
2.46 KB
containers-logs-tas_tests_search_api-1-20231130133726.tar.gz Expired
132 KB
containers-logs-tas_tests_search_api-1-20231130133745.tar.gz Expired
129 KB
containers-logs-upgrade_tas_tests-1-20231130132957.tar.gz Expired
165 Bytes
containers-logs-upgrade_tas_tests-1-20231130133055.tar.gz Expired
163 Bytes