Skip to content

ACS-6304 Implement SAST Pipeline Scan #1942

ACS-6304 Implement SAST Pipeline Scan

ACS-6304 Implement SAST Pipeline Scan #1942

Triggered via pull request November 30, 2023 14:10
Status Failure
Total duration 1h 8m 40s
Artifacts 5
This run and associated checks have been archived and are scheduled for deletion. Learn more about checks retention

ci.yml

on: pull_request
Source Clear Scan (SCA)
0s
Source Clear Scan (SCA)
Pipeline SAST Scan - ACS
19m 5s
Pipeline SAST Scan - ACS
Pipeline SAST Scan - Share
1h 8m
Pipeline SAST Scan - Share
PMD Scan
55s
PMD Scan
CMIS TAS tests - Open Search (CMIS API)
12m 17s
CMIS TAS tests - Open Search (CMIS API)
All AMPs tests
10m 55s
All AMPs tests
Distribution Zip content tests
7m 33s
Distribution Zip content tests
Single Pipeline image tests
0s
Single Pipeline image tests
Test Tomcat deployment
9m 52s
Test Tomcat deployment
Upload docker images needed for pipeline tests: <acs.version>-<PIPELINE_TAG_TEXT_INSERT>-<build>
0s
Upload docker images needed for pipeline tests: <acs.version>-<PIPELINE_TAG_TEXT_INSERT>-<build>
Matrix: cmis_tas_tests_elasticsearch
Matrix: tas_test_with_mtls
Matrix: tas_tests
Matrix: tas_tests_search_api
Matrix: tas_tests_with_aims
Matrix: upgrade_tas_tests
Fit to window
Zoom out
Zoom in

Annotations

4 errors and 5 warnings
Elasticsearch Upgrade TAS tests
Process completed with exit code 1.
Pipeline SAST Scan - ACS
[30 Nov 2023 14:17:56,0905] PIPELINE-SCAN INFO: Pipeline Scan Tool Version 23.11.0-0. [30 Nov 2023 14:17:56,0909] PIPELINE-SCAN INFO: Loading policy file Alfresco_Default.json [30 Nov 2023 14:17:56,0918] PIPELINE-SCAN INFO: Successfully retrieved the policy [30 Nov 2023 14:17:56,0918] PIPELINE-SCAN INFO: Policy name: Alfresco Default [30 Nov 2023 14:17:56,0918] PIPELINE-SCAN INFO: CWE filter: [30 Nov 2023 14:17:56,0918] PIPELINE-SCAN INFO: Severity filter: 3, 4, 5, [30 Nov 2023 14:17:56,0919] PIPELINE-SCAN INFO: Beginning scanning of 'distribution/target/alfresco.war'. [30 Nov 2023 14:17:56,0919] PIPELINE-SCAN INFO: Sending 187058500 bytes to the server for analysis. [30 Nov 2023 14:18:58,0992] PIPELINE-SCAN INFO: Upload complete. [30 Nov 2023 14:18:58,0992] PIPELINE-SCAN INFO: Scan ID: c0d269ff-c9ad-40c5-b7f9-ea70d45e1974 [30 Nov 2023 14:19:10,0325] PIPELINE-SCAN INFO: Analysis Started. =========================== Found 6 Scannable modules. =========================== alfresco.war JS files within alfresco.war JS files within alfresco.war JS files within alfresco.war JS files within alfresco.war JS files within alfresco.war [30 Nov 2023 14:30:05,0859] PIPELINE-SCAN INFO: Analysis Complete. [30 Nov 2023 14:30:05,0861] PIPELINE-SCAN INFO: Analysis Results: Received 83312 bytes in 728942ms. [30 Nov 2023 14:30:05,0868] PIPELINE-SCAN INFO: Writing Raw JSON Results to file '/home/runner/work/acs-packaging/acs-packaging/results.json'. [30 Nov 2023 14:30:05,0870] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0870] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0871] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0871] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0871] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0871] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0871] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0871] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0871] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0871] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0871] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0872] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0872] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0872] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0872] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0872] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0872] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0872] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0872] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0872] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0873] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0873] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0873] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0873] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0873] PIPELINE-SCAN INFO: Applying custom severity 2 to cwe 117 [30 Nov 2023 14:30:05,0873] PIPELINE-SCAN INFO: Applying custom severity 4 to cwe 80 [30 Nov 2023 14:30:05,0876] PIPELINE-SCAN INFO: Writing Filtered JSON Results to file '/home/runner/work/acs-packaging/acs-packaging/filtered_results.json'. Scan Summary: PIPELINE_SCAN_VERSION: 23.11.0-0 DEV-STAGE: DEVELOPMENT PROJECT-NAME: acs-packaging-acs SCAN_ID: c0d269ff-c9ad-40c5-b7f9-ea70d45e1974 SCAN_STATUS: SUCCESS SCAN_MESSAGE: Scan successful. Result
Elasticsearch Maria DB 10.6 | TAS tests (Search API)
Process completed with exit code 1.
Pipeline SAST Scan - Share
Process completed with exit code 12.
Elasticsearch Upgrade TAS tests
The following actions uses node12 which is deprecated and will be forced to run on node16: aws-actions/configure-aws-credentials@v1. For more info: https://github.blog/changelog/2023-06-13-github-actions-all-actions-will-run-on-node16-instead-of-node12-by-default/
Elasticsearch Upgrade TAS tests
The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/
Opensearch Upgrade TAS tests
The following actions uses node12 which is deprecated and will be forced to run on node16: aws-actions/configure-aws-credentials@v1. For more info: https://github.blog/changelog/2023-06-13-github-actions-all-actions-will-run-on-node16-instead-of-node12-by-default/
Opensearch Upgrade TAS tests
The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/
Pipeline SAST Scan - Share
No files were found with the provided path: readable_output.zip. No artifacts will be uploaded.

Artifacts

Produced during runtime
Name Size
PMD Summary (Human Readable) Expired
249 Bytes
Veracode Pipeline-Scan Results Expired
105 KB
Veracode Pipeline-Scan Results - ACS (Human Readable) Expired
2.47 KB
containers-logs-tas_tests_search_api-1-20231130143638.tar.gz Expired
131 KB
containers-logs-upgrade_tas_tests-1-20231130142655.tar.gz Expired
165 Bytes